How to set up two-factor authentication
Step-by-step instructions for enabling two-factor authentication on your most important accounts — email, your website, and more.
- Time
- 5 minutes per account
- Difficulty
- Beginner
- You’ll need
- Your phone · An authenticator app
Setting up two-factor authentication (2FA) takes about five minutes per account. You only do it once — and it dramatically reduces the risk of someone breaking into your account even if they have your password.
Quick summary
Two-factor authentication adds a second login check: after your password, you enter a one-time code from your phone. Set it up on your email first — it is the most important account to protect. Then your website, hosting, domain registrar, and financial accounts. The process is similar for every service.
What you'll need
- Your phone (to receive or generate codes)
- An authenticator app (recommended) — see Using an authenticator app
- Access to the account you want to secure
The general process for any account
Most services follow the same steps:
Open your account settings. Look for "Security," "Privacy," or "Account." The exact label varies by service.
Find the two-factor or multi-factor authentication option. It may be called "2-Step Verification," "MFA," or "Two-Factor Authentication."
Choose your method. Select "Authenticator app" if available — it is more secure than SMS.
Scan the QR code. Open your authenticator app, tap the "+" or "Add account" button, and point your phone's camera at the QR code on screen.
Enter the first code. Your app will show a 6-digit code. Type it in to confirm the connection is working.
Save your backup codes. The service will give you a set of one-time recovery codes. Save these somewhere safe — in your password manager's secure notes, printed and in a locked drawer, or both.
You're done
2FA is now active. The next time you log in on a new device, you'll be asked for a code from your authenticator app.
Setting up 2FA on specific services
Google 2-Step Verification:
- Go to your Google Account at myaccount.google.com.
- Open Security & sign-in.
- Under "How you sign in to Google," select Turn on 2-Step Verification.
- Follow the on-screen steps.
- To use an authenticator app, open your 2-Step Verification settings and choose Set up authenticator, then scan the QR code with your app.
- Save the backup codes Google provides. Google's are 8-digit codes you can print or download.
Google also offers passkeys, hardware security keys, Google prompts, and codes by text or call. Google says passkeys and hardware security keys are the ones that protect you from phishing, and it recommends Google prompts over codes if you are not using a passkey. Google also warns that codes sent by text or call can be undermined by attacks on your phone number.
Setting up 2FA on your domain registrar
Your domain registrar is critically important. If someone gains access to your domain registrar, they can redirect your website and email to a server they control. Protect it with 2FA.
Look for security settings in your registrar's account dashboard:
- GoDaddy: your account's Security page → under Enhanced Security, switch on the 2-Step Verification toggle. You have to set up at least one verification method first.
- Namecheap: Profile → Security, then in the Access section click Manage next to Two-Factor Authentication. Namecheap offers an authentication app (TOTP) or a device/security key, but only one method at a time.
- Cloudflare: under the My Profile dropdown select My Profile, then Authentication, then Add next to Mobile App Authentication (or Security Key Authentication).
The steps vary by registrar, but follow the general process above.
What to do if something goes wrong during setup
Don't lock yourself out
Before finishing 2FA setup, always save your backup codes. If your phone is lost, stolen, or replaced, backup codes are how you get back in.
If you get locked out of an account after enabling 2FA:
- Look for a "Use a backup code" link on the login page.
- Check your saved backup codes.
- Use the account's account recovery process (usually involves verifying your identity by email or phone).
Common questions
What if my team uses shared accounts?
For shared accounts, the authenticator app needs to be on a shared device, or you can use a password manager that can also store the one-time code (1Password can act as an authenticator this way). Keep that login in a vault the team shares, so everyone who needs the code can get it.
Do I need to enter a code every time I log in?
Usually no. Most services let you mark a device as trusted and then only ask for a code when you log in from a device they don't recognize. How long that trust lasts is up to each service, so expect to be asked again from time to time.
What happens if I get a new phone?
Set up your authenticator app on the new phone before you reset or sell the old one. Authy can restore your accounts from its encrypted cloud backup, as long as you turned its backup feature on and set a backup password — Authy never receives that password, so it cannot recover your accounts without it. Google Authenticator syncs your codes to your Google Account, so signing in to the app on the new phone brings them across; if you use it without a Google Account, export them from the old phone instead (Menu → Transfer accounts → Export accounts). If you've already lost access, use backup codes or the service's account recovery process.
Related guides
- Two-factor authentication, explained
- Using an authenticator app
- Passkeys, explained
- Securing your WordPress site
- Securing your domain name
- I can't log in to my site
Need a hand?
Learn more
Last updated