How to Secure Your Email, Social Media, and Mobile Accounts

Account takeovers rarely start with a sophisticated hack, they start with a reused password from an old breach. The single most effective fix is still layering extra proof of identity on top of your password. In 2026, that layer increasingly means passkeys, not just the text-message codes many people think of as “two-factor authentication.”

 

Below is an updated walkthrough of what to turn on, in what order, and how to avoid getting locked out.

 

Understanding Your Options: Passkeys, Authenticator Apps, and SMS

Not all “extra security” is equally strong. From strongest to weakest:

  1. Passkeys — A device-based credential tied to your fingerprint, face, or PIN. There’s no code to type and no shared secret that can be phished or stolen in a breach. Google, Apple, Microsoft, PayPal, LinkedIn, X, and most major platforms now support them.
  2. Authenticator apps (TOTP) — Apps like Google Authenticator, Microsoft Authenticator, Authy, or a password manager (1Password, Bitwarden) generate a rotating six-digit code on your device. Codes never touch the phone network, so they can’t be intercepted via SIM-swap attacks.
  3. Hardware security keys — Physical devices (e.g., YubiKey) that plug in or tap via NFC/Bluetooth. Extremely phishing-resistant, best reserved for your highest-value accounts.
  4. SMS text codes — Better than nothing, but the weakest option. Codes can be intercepted through SIM-swapping or carrier-level attacks, and several major platforms have started restricting free SMS-based verification to paid tiers.


2026 recommendation:
turn on a passkey wherever it’s offered, keep an authenticator app as backup for services that don’t support passkeys yet, and save your printed backup codes somewhere safe (not a cloud notes app) as a last resort.

 

Securing Your Email Accounts

Enable a passkey or two-step verification. For Gmail, Outlook, and Yahoo Mail, go to your account’s security settings and look for “2-Step Verification,” “Two-Factor Authentication,” or “Passkeys.”

  • Gmail: Google now pushes passkeys as the primary sign-in method. If you’d rather stick with a code, Google Authenticator or an SMS/voice backup is still available, but a passkey is the fastest and most phishing-resistant option.
  • Outlook: Microsoft Authenticator supports both push-approval sign-in and passkeys tied to Windows Hello or your phone’s biometrics.


Logging in from a new device:
With 2FA or a passkey enabled, a new device will prompt for the second factor — a passkey confirmation, an app-generated code, or (least preferable) a text/email code.

 

Securing Your Social Media Accounts

Enable stronger verification on Facebook, Instagram, X, LinkedIn, TikTok, and YouTube.

  • Facebook / Instagram: Meta supports authenticator-app codes, SMS, and is expanding passkey support. Facebook Messenger now has end-to-end encryption turned on by default for personal chats, which wasn’t the case a few years ago.
  • X (formerly Twitter): This is the platform where the rules changed the most. Since 2023, free X accounts can no longer use SMS as a second factor — SMS 2FA is now restricted to paying X Premium subscribers. Free accounts must use an authenticator app or a FIDO2/WebAuthn hardware security key instead, both of which are actually stronger than SMS. X has also rolled out passkey sign-in and an encrypted “Chat” feature as a successor to its older encrypted DMs.
  • LinkedIn: Supports authenticator-app codes and SMS, with passkey support now available in account security settings.
  • TikTok: Supports 2-step verification via SMS, email, or an authenticator app (found under Settings and privacy → Security → 2-step verification). TikTok has also rolled out passkey support on iOS and Android — on iPhone/iPad it requires two-factor authentication to already be enabled on your Apple ID and iCloud Keychain turned on; on Android it requires Android 9.0+ with screen lock enabled.
  • YouTube: YouTube doesn’t have its own separate login — it runs on your Google Account, so securing YouTube means securing that Google Account (the same steps as the Gmail section above). Google now defaults new and existing accounts toward passkey-first, passwordless sign-in where possible; 2-Step Verification with an authenticator app or security key remains available as an alternative, and SMS/voice codes are the fallback of last resort. This matters especially for creators, since a compromised Google Account means a compromised channel.


Account recovery:
Set up backup codes and a secondary recovery email or phone before you need them. If you lose your authenticator device, most platforms require identity verification that can take anywhere from a few minutes to several days — printed backup codes are the fastest way around this.

 

Updated Security Feature Comparison (2026)

Platform Strongest 2FA Option SMS Backup Encrypted Messaging Account Recovery
Gmail Passkey Yes No (Gmail); Google Messages RCS has E2EE Recovery email/phone, backup codes
Outlook Passkey / Authenticator push Yes No Recovery email/phone, backup codes
Facebook Authenticator app, expanding passkey support Yes Yes (Messenger, default E2EE) Backup codes, trusted contacts
X (Twitter) Authenticator app / hardware security key / passkey Premium subscribers only Yes (X Chat) Backup codes, account recovery form
Instagram Authenticator app Yes No Backup codes, email recovery
LinkedIn Authenticator app, passkey available Yes No Backup codes, email recovery
TikTok Passkey (iOS/Android), authenticator app Yes No Backup codes, email/SMS recovery
YouTube (Google Account) Passkey (passwordless sign-in by default) Yes No Recovery email/phone, backup codes
PayPal Passkey (increasingly used as full single-step login) Yes No Security questions, backup codes

Note: Feature availability can vary by account type, region, and whether a platform is mid-rollout on a feature — always check the platform’s own security settings page for what’s currently offered on your account.

 

Bottom Line

Two-factor authentication is no longer the newest thing you can do to protect your accounts — passkeys are. The safest 2026 setup for most people is: enable a passkey everywhere it’s offered (Gmail/YouTube, TikTok, X, PayPal, and more all support them now), fall back to an authenticator app (not SMS) where passkeys aren’t available yet, and save backup codes somewhere secure and offline in case you ever lose access to your device.