A password can leak from anywhere - another site, a phone, a note. Two-factor means the leak alone is not enough, and it is the single highest-value setting on any account that controls a server.
Set it up
- Open the security section of the panel —
- Scan the code with an authenticator app — Any TOTP app works; the code is standard.
- Enter the six digits once to confirm — This proves the clock and the secret agree.
- SAVE THE RECOVERY CODES — This is the step that matters.
The recovery codes
Recovery codes are shown once. Saved in a screenshot on the same phone that holds the authenticator, they protect against nothing: lose the phone and you lose both. Print them, or put them in a password manager that syncs elsewhere.
Choose the method by what it protects against
- An authenticator app - works with no signal, cannot be intercepted. The default choice.
- A hardware key - the only method that also stops phishing, because the key checks the domain.
- SMS - better than nothing and the weakest: a SIM can be transferred to someone else's phone in a shop.
After the phone is replaced
Codes do not move with a new phone unless the app syncs them. Turn two-factor off with a recovery code on the old device, then on again on the new one - before the old phone is wiped.
Turn it on for the domain registrar too. Control of the domain is control of the mail, and control of the mail is control of every password reset you own.