ohgeeceee Remote — anywhere in the US

Security & Privacy / Security

Password Recovery and Setting Up a Password Manager with 2FA

Get back into a locked account, then set up a password manager and two-factor so it never happens again. Written for people who have never used one.

⚡ 30-second fix Difficulty Medium About 25 min Works on Any device · iPhone · Android · Windows · Mac Anywhere in the US

The 30-second fix

Before anything else, find the account's own Forgot password link and use the email or phone number you signed up with. Do not use a reset link from an email you did not ask for.

If that sorted it, you are done. If not, keep reading — the rest takes about 25 minutes.

Before you start

  • Access to the email address the account uses
  • Your phone, for verification codes
  • About 25 minutes, done calmly

You do not need to write passwords on paper, and you do not need to change every password today. Start with email, then bank, then everything else.

Two jobs, in order

There are two separate jobs here and it matters which you do first.

  1. Get back in. Recover the account you are locked out of.
  2. Make sure it never happens again. Set up a password manager and two-factor.

Do them in that order. Recovering an account is urgent; the setup is what stops it recurring.

Part 1 — Get back in

Step 1

Use the site's own Forgot password link

Screenshot to add

A sign-in page with the Forgot password link highlighted

Go to the site directly — type the address yourself rather than clicking a link in an email. Then use its Forgot password link.

Never use a password reset link from an email you did not ask for. That is the single most common phishing trick there is. If you did not request it, delete it.
Step 2

Check your email, including junk

Screenshot to add

An inbox showing a password reset email

The reset email should arrive within a minute or two. If it does not, check spam and junk, and search your inbox for the site's name. Reset links expire quickly, so use it the moment it arrives.

Step 3

Handle the verification code

Screenshot to add

A phone showing a six-digit verification code

Most sites now send a code to your phone or email as a second check. Enter it on the site. This is two-factor working as intended — it is what keeps someone else out even if they know your password.

Step 4

Set a new password you will actually keep

Screenshot to add

A password field showing a long passphrase

Long beats complicated. Three or four random words strung together — copper-tractor-lantern-nine — is both stronger and easier to remember than P@ssw0rd1.

Part 2 — Never do this again

Step 5

Install a password manager

Screenshot to add

A password manager app showing a list of saved logins

Install one on your phone and your computer. Bitwarden is free and open-source; 1Password and Dashlane are paid and very polished. Any of them is a huge improvement on a notebook.

The manager remembers every password so you only have to remember one — the master password. Make that one a long passphrase and never reuse it anywhere.

Step 6

Let it generate your passwords

Screenshot to add

A password manager generating a long random password

From now on, when you sign up somewhere, let the manager generate a long random password. You will never type it. That is the point.

Step 7

Turn on two-factor, starting with email

Screenshot to add

Security settings showing two-step verification enabled

Turn on two-factor for your email first, then your bank, then everything else. Email is the master key to every other account, because that is where password resets go.

Use an authenticator app when offered. Text messages are a decent fallback, not the best choice.

Step 8

Save your recovery codes offline

Screenshot to add

Recovery codes written on a card stored in a drawer

Every account gives you one-time recovery codes when you turn on two-factor. Print them or write them down and put them somewhere physical — a drawer, a safe, a wallet. If you lose your phone, these are the only way back in.

Do not store recovery codes in the same place as your password manager. If you lose access to one, you want the other to still work.

The order that matters

Email first, then bank, then the rest. If you only do one thing today, turn on two-factor for your email account — that single step protects everything else by making sure nobody can reset your other passwords.

Did it work?

  • You are signed in to the account you were locked out of
  • The password manager fills a login for you on a test site
  • Two-factor codes arrive and work
  • You have saved your recovery codes somewhere offline
Still not working?
  1. If the reset email never arrives, check the spam and junk folders, and search your inbox for the account name.
  2. If the account uses a phone number you no longer have, use the account's account-recovery form rather than the normal reset.
  3. If you are locked out of your email itself, call the provider's support line — email is the master key, so it is worth the phone call.
  4. If you believe the account was taken over, change the email password first, then everything else, then check the account's forwarding and recovery settings for anything you did not add.

If none of that helped, it is usually a hardware or account problem rather than a settings one — and that is exactly the kind of thing worth handing to someone for an hour. Book a session →

Still stuck? I can take it from here.

If the steps above did not do it, that is what I am here for — remote, flat rate, plain language. You watch everything I do.

Book a session →

REMOTE SESSIONS ONLY — ANYWHERE IN THE US — FLAT RATE, UP FRONT

Around the network

More from the maker of this network.

What two-factor authentication really is · Small tools that respect the person using them

By ohgeeceee Published 2026-10-04 Last verified 2026-10-04 Sources Bitwarden — free password managerCISA — use a password manager