First read how passkeys, security keys, SMS, and TOTP differ. Then work through this list one account at a time. Do not disable the current sign-in method before testing a fallback.
Critical accounts
- I list my primary email, password manager, Apple/Google/Microsoft account, bank, mobile carrier, and important social accounts
- I start with a less critical account so I can learn the process without risking access to my main email
- For each account, I record the available methods: passkey, security key, TOTP app, SMS, password, and support-assisted recovery
- I verify the official domain and open security settings there — I do not set up a passkey from a link in a message
A backup route in
- I add a passkey on the first device but keep the current working method
- I add an independent recovery route: a second physical key, recovery codes stored away from the phone, or a device that does not depend solely on the same syncing account
- I store the second key or device separately, not in the same bag as my phone and laptop
- I identify the provider account that syncs my passkeys and confirm I can recover that account
- The recovery phone number and backup email belong to me and are current
Recovery codes
- I generate fresh recovery codes after changing MFA if the service offers them
- I keep them away from the phone: a printout, sealed envelope, or encrypted store reachable from another device
- I do not keep the only photo of the codes on the phone those codes are meant to replace
- I label the account and date without writing the password on the same sheet
Emergency test
- I open a new private browser session and sign in with the passkey
- I sign out of the test session and try the second device or second key
- I locate the controls for revoking a lost passkey, key, and active sessions
- I read the provider’s recovery procedure; I do not start it merely as a test if it could lock the account
- Only after a successful test do I remove an old method I no longer want
Keep it working
- I repeat the test after changing my phone, number, primary email, or password manager
- Every few months I review devices, passkeys, and active sessions
- A household member or emergency contact knows where the backup is — they do not need my password
A fallback stored on the lost laptop is not independent. Protect device data with full-disk encryption. For an organisation, dependencies and recovery paths can be reviewed as part of cybersecurity.