Your recovery options are the real password
Account takeovers rarely start with a guessed password. They start with a recovery email or phone number nobody had checked in years — and the change is designed not to be noticed.

Short answer
Every account's true security is the weakest path back into it. Check the recovery email and phone on your important accounts today: an address you no longer control, or one an attacker quietly added, defeats any password and most second factors. Then check the sessions and app permissions, which is where an intruder stays after being removed.
On this page
- The three things to check right now
- Then check where you are still signed in
- And the permissions you granted years ago
- Where the mail rules hide
- Order matters
- Make the recovery path strong, not just present
- What is account recovery?
- What should you check, and in what order?
- Which account first?
- Make the recovery options strong, not just present
- The 10-minute version
- Recovery options on the accounts that matter most
People harden the front door and leave account recovery untouched for a decade. Attackers know this, which is why the recovery flow is where they work.
The three things to check right now
Take ten minutes on your email, your bank, and whichever social account matters to you.
1. The recovery email address. Is it one you still control? An address at an old employer, an old provider, or a domain that has since expired is a way in that does not need your password at all. Expired domains are bought precisely for this.
2. The recovery phone number. Is it your current number? Recycled numbers are reassigned to new customers, and the new owner receives your reset codes.
3. Whether anything was added that you did not add. This is the one people never check. An attacker with brief access does not change your password — that alerts you. They add a recovery address of their own and leave, then use it weeks later, after you have stopped paying attention.
Then check where you are still signed in
Every major service has an active sessions or devices list. Look for:
- Locations and devices you do not recognise. Approximate locations are unreliable, but an unfamiliar device type is worth pursuing.
- Sessions older than your last password change. A password change should invalidate them; a session that survived is either a bug or a token an attacker holds.
Sign out everything you cannot account for.
And the permissions you granted years ago
Third-party apps connected to your account keep working long after you have forgotten them, with whatever access you agreed to then.
Look for anything that can read your email, post as you, or manage your files. Revoke anything you cannot name and use today. Reconnecting a tool you actually use takes seconds; discovering in a year that a defunct service still had read access to your mail does not.
Where the mail rules hide
An attacker who reaches an inbox often creates a filter — forward everything to an address, or move messages containing "password", "invoice" or "bank" straight to archive.
The account then looks normal. You do not see the reset emails because a rule filed them before you could.
Open your mail rules and filters and confirm you wrote each one. This is the single most commonly missed step after an incident, and it is how people get compromised a second time having "fixed" the first.
The password is the part everyone looks at. The recovery address, the sessions, the app permissions and the mail rules are the parts that actually decide who holds the account.
Order matters
Do email first. It is the recovery path for nearly everything else, so an attacker holding it can reset the rest at leisure regardless of how well those are protected.
Then: password manager, mobile operator account, bank, then everything else.
Make the recovery path strong, not just present
- Prefer passkeys or a hardware key where offered, on the email account above all.
- Store printed recovery codes somewhere physical. They work when your phone does not, which is the scenario people plan for least.
- Register a second passkey, not a phone number, as your backup. A weaker backup factor becomes the way in.
- Lock your mobile account with a PIN or port-out protection, because SIM swapping targets the recovery path rather than the account.
None of this is difficult. It is simply never urgent — until the day it is the only thing that mattered.
What is account recovery?
Account recovery is the set of paths back into an account when the password is unavailable — a recovery email, a phone number, printed codes, a trusted contact. It is the real security boundary, because any of them can replace the password without knowing it.
What should you check, and in what order?
| Check | Where | What you are looking for |
|---|---|---|
| Recovery email | Security settings | An address you no longer control, or never added |
| Recovery phone | Security settings | A recycled or unfamiliar number |
| Active sessions | Devices or sessions list | Anything older than your last password change |
| App permissions | Connected apps | Anything that can read mail or post as you |
| Mail rules and filters | Mail settings | Forwarding or auto-archiving you did not write |
| Backup factor | Two-factor settings | SMS left enabled behind a passkey |
Row 5 is the one almost everyone misses. An attacker who reaches an inbox often creates a filter that archives messages containing "password" or "bank", so the account looks normal while reset emails are hidden.
Which account first?
Email, then your password manager, then your mobile operator account, then banking. That is the order in which a compromise cascades, so it is the order in which to spend the 10 minutes. Google's guidance on securing a compromised account covers the same ground for its own products. See digital safety, phishing and impersonation.
Make the recovery options strong, not just present
- Prefer passkeys or a hardware key, on email above all.
- Store printed recovery codes somewhere physical — they work when your phone does not.
- Register a second passkey rather than leaving a phone number as the fallback.
- Lock your mobile account with a PIN or port-out protection, since SIM swapping targets the recovery path rather than the account.
None of this is difficult. It is simply never urgent, right up until it is the only thing that mattered — and by then the recovery options are whatever someone else set them to.
The 10-minute version
If you do nothing else, do this on your email account today:
- Open security settings and read the recovery email and phone aloud. Confirm you control both.
- Sign out every session you cannot account for.
- Open mail filters and confirm you wrote each rule.
- Revoke any connected app you cannot name and use.
Those 4 steps cover the routes that bypass a password entirely, and they are the ones nobody checks until after something has happened.
Recovery options on the accounts that matter most
Work through them in the order a compromise spreads, checking the same 4 recovery options each time:
- Email — the recovery path for everything else, so it gets the strongest factor and the most attention.
- Password manager — everything inside it depends on this one door.
- Mobile operator account — a SIM swap targets the recovery options, not the account.
- Banking — where the loss lands, but rarely where the compromise starts.
Reviewing recovery options takes about 10 minutes per account and holds for a year. It is the highest-value security task available to most people, and it is invisible, which is exactly why it goes undone. And when you next set up a new service, set the recovery options during signup rather than promising yourself you will return to them. That promise is the reason most accounts have a recovery email nobody has verified in six years.
Frequently asked questions
- Why is the recovery email more important than the password?
- Because it can replace the password without knowing it. An address you no longer control, or one an attacker added, bypasses the password and most second factors entirely.
- How would an attacker add a recovery address without me noticing?
- With brief access they add their own address and change nothing else, because a password change would alert you. The addition is used weeks later, after attention has moved on.
- What should I look for in my mail filters?
- Any rule you did not write — particularly forwarding to an unfamiliar address, or rules that archive messages containing words like password, invoice or bank. This is the most commonly missed step after an incident.
- Should I keep a phone number as backup after adding a passkey?
- On high-value accounts, prefer a second passkey or printed recovery codes. A weaker backup factor left in place becomes the path an attacker uses.
Sources
- Secure a hacked or compromised Google Account — Google Account Help
- Passkeys — FIDO Alliance
- Multi-Factor Authentication — CISA
Published by
Scamiro
Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.
About the publication