How it works
When you sign in on a new phone or computer, the website asks for your password and a second thing: usually a short code sent to your phone, or a prompt you approve on a device you already own. A thief who has your password still cannot get in without your phone.
You may see it called two-factor authentication, two-step verification, or a login code. They all mean the same thing.
Which accounts first
- Your email. Whoever controls your email can reset everything else.
- Your bank and credit card accounts.
- Your Apple Account or Google Account, which hold your photos, contacts, and saved passwords.
- Shopping sites that store your card, and social media.
Where to find the setting
- Apple Account: most accounts already have it on. To check, open Settings, tap your name, then Sign-In & Security.
- Google Account: open the Google app or Settings, tap Google, then Manage your Google Account, then Security, then 2-Step Verification.
- Banks and other sites: log in on the website or app and look in Security or Settings for two-step or login verification.
The golden rule about codes
A code sent to you is for typing into the website yourself, and nowhere else. Never read it out to someone on the phone, and never text it to anyone, even if they say they are from your bank, the company, or a friend who sent it by mistake. Anyone asking for your code is trying to get into your account.
Plan for a new phone
Before you replace or reset your phone, make sure you can still get your codes. Many accounts give you backup codes when you turn this on. Print them or write them down and keep them with your important papers.
Stuck on a step?
Text Uncle at +1 208 214 0093 and tell him what you see on your screen. He walks you through it in plain words, one step at a time.
Read next
Written by the Textuncle team. Last updated October 3, 2026.
Text Uncle