Email is the account that guards the others
Work out the order by asking what a compromise spreads to. Your mail account is at the top of that list by a wide margin: nearly every service on earth will send a password reset link there, so control of the mailbox is functionally control of the accounts it can reset. Banking is a close second in consequence but a distant second in reach, because a bank account does not reset your other accounts.
This has a practical implication people get backwards. If several accounts look compromised at once, do not start with the one that has money in it. Start with the mailbox, because until it is secure every fix you make elsewhere can be undone by a reset link the attacker receives. Secure the mail account, then work outward.
The same logic applies in reverse when you are setting things up. The mail account should have the unique passphrase, the strongest available second factor, and recovery details that are actually current. And a mail account used for account recovery is a poor choice for a public contact address on a resume, a classified listing or a forum profile, because the address itself is the first half of every credential-stuffing attempt against you.
Why legitimate owners fail recovery
The recovery process is a security control, and like any security control it is calibrated to keep the wrong person out — which means it sometimes keeps the right person out. Nearly all of that comes from a small number of avoidable situations.
| Reason | What actually happened | Prevented by |
|---|---|---|
| Stale recovery phone number | You changed carriers or numbers years ago and the account still lists the old one. This is the single most common cause. | Checking it whenever your number changes, and again at any annual review |
| Stale recovery email | The backup address was a work account you no longer have, or a provider that shut down | Using an address you control independently and will keep |
| Lost the authenticator app with the phone | Codes were only ever on one device, and the device is gone | Enrolling a second device, or saving the setup codes at enrollment |
| Backup codes never saved | They were shown once at setup and clicked past | Printing them at the moment they are offered |
| Recovery attempt from an unfamiliar device and location | Providers weigh signals. A first-ever sign-in attempt from a new machine in a new country looks exactly like a takeover. | Running recovery from your usual home network and a device you have used before, where possible |
| Answers that no longer match | Old security questions answered years ago with something you have since forgotten, or details that changed | Treating security answers as passwords — random text stored in your manager, not true facts |
| Account created with details you cannot evidence | A name that does not match your documents, or an account made for you by someone else | Nothing after the fact. Worth knowing before you build a life on an account. |
Note the row about security questions. Answering them truthfully is the weak option, because a mother's maiden name and a first school are frequently public. Storing random answers in your password manager is stronger and, as a side effect, means the answers are still there in five years when your memory of the truthful version has drifted.
What to set up before anything goes wrong
All of this takes about half an hour once, per important account, and it converts a lost phone from a crisis into a nuisance.
| Set up | Detail that matters |
|---|---|
| Backup codes, printed | Most services offer a set of single-use codes when you enable two-factor. Print them or write them out and store them physically, with your other documents. A screenshot in the phone's photo library is not a backup, because the phone is what you have lost. |
| Two enrolled second factors | Two security keys, or an authenticator on two devices, or a key plus an app. One is a single point of failure and the failure mode is total. |
| A current recovery email you actually control | Not a work address. Ideally at a different provider than the account itself, so one provider's outage or suspension does not take both. |
| A current recovery phone number | Update it the same day you change numbers. Put it on the moving checklist next to the mailing address. |
| Authenticator setup codes saved at enrollment | When a service shows the secret alongside the setup image, save it in your password manager. That is what lets you re-add the account on a replacement phone without the old one. |
| A written note of where all of this lives | One page. Where the paper is, which email is the recovery address, which manager holds the vault. Someone else in your household should be able to find it. |
| Provider account-recovery options, whatever they are called | Some services offer a trusted contact, an inheritance or legacy setting, or a delayed self-recovery. These exist and almost nobody enables them. |
Test one thing before you trust it: sign in to your main mail account on a device you have not used for it, using only what you have written down. If that works, the rest of this page is theoretical for you. If it does not, you have found the gap while it is still cheap.
You are locked out right now
Work down this list in order rather than repeating the same failed attempt, because repeated failures from the same device can trigger a temporary lock that makes everything harder.
Start with the obvious mechanical causes. Caps lock, a keyboard layout that changed, an autofilled old password from a browser that saved one two years ago, or a password manager entry you updated on one device and not another. Then check whether the account is locked rather than the password wrong — the wording differs and it matters, because a lock usually clears on its own after a period.
Next, use the recovery route the service offers, from a device and network you have used with that account before. Providers weigh familiar signals heavily, and running recovery from your home computer on your home connection materially improves the outcome versus a hotel laptop.
If a recovery form asks questions, fill in everything you can, even approximately. Account creation date, previous passwords you remember, addresses on file, contacts you correspond with, the device you normally use. Partial and honest beats blank. Do not submit the form five times with different guesses; multiple contradictory submissions look like someone probing.
Two things not to do. Do not pay anyone who advertises account recovery services — the search results for a locked account are dense with people who cannot do what they claim, and paying them ends with less money and the same locked account. And do not create a new account and then try to use it to recover the old one, because that new account has no history and no signal value.
If it was taken rather than lost
Takeover has a different order of operations, and speed matters more than tidiness.
| Step | Why this order |
|---|---|
| 1. Regain access, mail account first | Everything else can be undone by whoever receives the reset links |
| 2. Change the password to something new and unique | Not a variation of the old one, and not something reused elsewhere |
| 3. Sign out all active sessions | This is the step people skip. A session opened with the old password stays valid after a password change until it is explicitly revoked. |
| 4. Check for mail forwarding rules and filters | A standard move is to add a rule that quietly copies or deletes incoming mail, so the attacker keeps seeing your reset messages after you lock them out. Look for filters that delete or archive on keywords like security, invoice, or the name of your bank. |
| 5. Check recovery email, recovery phone, and enrolled second factors | Anything added that you do not recognize gets removed. An added recovery address hands the account straight back. |
| 6. Review connected apps and authorized devices | Third-party access granted during the takeover survives a password change |
| 7. Then work outward to accounts that used the same password | Or that used this mailbox for recovery, which is most of them |
| 8. Warn your contacts | The most profitable use of a taken account is messaging the owner's friends. Say it plainly and from a channel they will trust. |
If money or documents were involved, or if the account held identity information, treat it as more than an account problem: identity theft response covers freezing credit and the reporting steps, and data breach response covers the cleanup when the source was a company rather than you.
After you are back in
Do the setup section above for this account before you close the tab, because the moment you are back in is the only moment you reliably have both access and motivation. Unique passphrase in a manager, the strongest second factor offered, two enrolled devices, backup codes printed, recovery address and phone confirmed current. Then look at how it happened: a reused password from an old breach, a phishing page, or a session left signed in on a device you no longer have. Each of those has a different follow-up, and using a password manager addresses the first two directly.
Recovery is one of the few things in computing where the work has to happen before the problem. A locked account is not a puzzle to solve on the day; it is a set of arrangements you either made or did not, and the arrangements take half an hour.
Questions people ask
Which account should I secure first?
Your primary email, without much argument. Nearly every other service will send a password reset link there, so whoever controls the mailbox controls everything it can reset — which is why fixing a bank login before the mailbox is the wrong order. Give the mail account a unique passphrase, the strongest second factor it supports, a recovery address at a different provider, and a phone number that is actually current. It is also worth keeping that address off public listings, since the address itself is the first half of any credential-stuffing attempt aimed at you.
I lost the phone with my authenticator app. What now?
Use your backup codes, which is exactly what they exist for — a set of single-use codes issued when you enabled two-factor. If you saved them on paper you are a few minutes from being back in. If you did not, try a second enrolled device, then the provider's account recovery form, submitted from a computer and network you have used with that account before. Going forward, enroll two second factors rather than one, and save the authenticator setup codes into your password manager at the moment you enroll, since those are what let you re-add accounts on a replacement phone.
Why did the recovery form reject me when it is genuinely my account?
Recovery decisions weigh signals rather than a single proof, and an attempt from an unfamiliar device, a new network or a different country looks statistically like a takeover. The two most common fixable causes are a recovery phone number or email address that has not been updated since you changed carriers or jobs, and security question answers that no longer match what you typed years ago. Retry from your usual home device and connection, fill in every field you can even approximately, and avoid submitting repeatedly with different guesses — inconsistent submissions read as probing.
Someone got into my account and I changed the password. Is that enough?
No. A session that was already open stays valid after a password change until you explicitly revoke it, so the first extra step is signing out all active sessions from the account's security settings. Then look for what was added rather than what was changed: a mail forwarding rule or filter that quietly copies or deletes incoming messages, a new recovery email or phone number, an extra enrolled second factor, or a third-party app with account access. Any one of those hands the account straight back regardless of your new password.
Are paid account recovery services worth trying?
No. Search results for locked accounts are full of people offering to restore access, and they have no channel the account owner does not have — the provider decides recovery, not a third party. Paying typically ends with the money gone and the account still locked, and handing over your personal details to prove ownership to a stranger creates a second problem. The one legitimate exception is a business account where your organization has a support contract with the provider. Otherwise, work the official recovery route from a device and network the account recognizes.