Your email account is more powerful than it looks. It is not just where letters and photos from family land. It is also the account that resets almost every other password you have.

That makes it the first place a scammer wants to break into, and the first place worth locking down. The good news is that the lock itself takes about 10 minutes to set up, and you only have to do it once.

This guide walks you through turning on two-step verification for Gmail, Outlook (including Hotmail), and Yahoo Mail. It also covers backup codes, so you never get shut out of your own account.

How Do I Turn On Two-Step Verification for My Email?

You turn it on inside your email account’s security settings, choose a second way to prove it’s you, then save your backup codes. Every major provider works the same general way, even though the screens look a little different.

Plain talk: two-step verification

Two-step verification means you need two things to sign in: your password, and a short code from your phone or an app. Some people call it two-factor authentication or “2FA.” It is the same idea.

Here is the general pattern, no matter which email provider you use:

  1. Go to your account’s security settings while signed in.
  2. Find “two-step verification” or “two-factor authentication.”
  3. Choose how you want to get your second code (text message, phone call, or an app).
  4. Confirm the code you receive to finish setup.
  5. Save the backup codes you’re given, and write down or print a second recovery option.

The sections below give you the exact steps for Gmail, Outlook, and Yahoo.

Why Your Email Account Is the One to Protect First

Think of your email as a master key. If a scammer gets into it, they can often click “forgot password” on your bank, your social media, and your shopping accounts, and have a new password sent straight to the inbox they now control.

According to the FTC’s Consumer Sentinel Network Data Book, the agency received over 5.4 million consumer reports in 2023, a large share involving stolen personal information and hijacked accounts. Locking down email first cuts off one of the easiest paths a scammer has into the rest of your digital life.

Safety tip

Never read a verification code out loud to someone who calls or texts you, even if they say they work for Google, Microsoft, Yahoo, or your bank. A real company never needs you to read your own code back to them.

Turn On Two-Step Verification for Gmail

Gmail’s two-step verification lives inside your Google Account settings.

  1. On your phone or computer, sign in to your Google Account and go to the Security section (you can also type myaccount.google.com into the address bar).
  2. Under “How you sign in to Google,” select 2-Step Verification.
  3. Select “Get started” and enter your password again to confirm it’s you.
  4. Choose your second step. Most people pick a Google prompt (a tap-to-approve notification on your phone) or a text message code.
  5. Follow the on-screen instructions to confirm your phone.
  6. Once it’s turned on, scroll down on the same page to “Backup codes” and select “Set up” to generate and save a set of codes.

Try this

If you have a smartphone, an authenticator app such as Google Authenticator makes codes even when you have no phone signal or Wi-Fi. It’s a good backup to a text message code, not a replacement for it.

Turn On Two-Step Verification for Outlook or Hotmail

Outlook, Hotmail, and Live email addresses all use the same Microsoft account security settings.

  1. Sign in to your Microsoft account and go to the Advanced security options page.
  2. Under “Additional security,” find “Two-step verification” and select “Turn on.”
  3. Microsoft will ask you to confirm your identity with your current sign-in method first.
  4. Choose how you want to receive your second code: the Microsoft Authenticator app, a text message, a phone call, or a second email address.
  5. Follow the steps to confirm your chosen method.
  6. When setup finishes, add at least one backup method, such as a second email address or phone number, so you have three pieces of security information on file in total.

Microsoft recommends keeping a second email address and a phone number on file in addition to your main sign-in method, so a lost phone never locks you out completely.

Turn On Two-Step Verification for Yahoo Mail

Yahoo calls its version “two-step verification,” and it’s a separate setting from Yahoo’s older “Account Key” sign-in option.

  1. Sign in to Yahoo and go to your Account Security page.
  2. If Account Key is currently turned on, turn it off first. Yahoo asks you to choose one or the other, not both.
  3. Under “Ways of signing in,” select “2-step verification” and turn it on.
  4. Choose your method: a text message, a phone call, or an authenticator app.
  5. Enter the code you receive to confirm setup.
  6. If you choose an authenticator app, Yahoo gives you a one-time recovery code on screen. Write it down or print it immediately, since it’s shown only once.

Yahoo asks for at least two recovery methods on file (for example, a phone number and a recovery email address) before you can rely on an authenticator app alone.

Comparing Gmail, Outlook, and Yahoo

Provider Second step options Where backup codes live
Gmail Google prompt, text, call, authenticator app, security key Security settings, under “Backup codes”
Outlook Microsoft Authenticator app, text, call, second email Advanced security options, “Additional security”
Yahoo Text, call, authenticator app, security key Shown once on screen during authenticator setup

Save Your Backup Codes

Backup codes are your safety net. They let you sign in even if your phone is lost, broken, or simply out of battery.

  1. Print the backup codes if you have a printer at home, or write them by hand on paper.
  2. Store them somewhere safe and separate from your phone, such as a drawer or a folder with other important documents.
  3. Do not save them as a photo on the same phone you use for your second step. If that phone is lost, the codes go with it.
  4. Cross off each code as you use it. Most providers only let each one work once.

Say this

If a family member is helping you set this up, you can say: “Can you sit with me while I turn on two-step verification for my email, and help me find a safe spot to keep my backup codes?”

What to Do If You Think Your Email Was Already Compromised

If you notice sign-ins you don’t recognize, or you can no longer get into your own account, act quickly. Change your password from a device you trust, turn on two-step verification right away, and check your account’s recent activity or sign-in history for anything unfamiliar.

Our guide on what to do if you clicked a scam link walks through the same calm, step-by-step approach if you’re worried you’ve already been targeted. If money or a financial account was involved, our guide on freezing your credit after a scam covers the next steps. And if you want to report what happened, see where to report a scam for the right agency in your country.

If you’d like a refresher on the basic idea behind two-step verification before you dive in, our earlier article on what two-factor authentication is covers the concept in simple terms.

Plain talk: backup codes

Backup codes are a short list of one-time passwords your email provider gives you when you turn on two-step verification. Each code works only once, and they’re meant to be used only if you can’t get your usual code another way.

A Few Extra Habits Worth Building

Once two-step verification is on, a few small habits keep it working well for you:

  • Keep your phone number up to date in your account settings, especially if you get a new phone or new SIM card.
  • Review your backup codes once a year and generate a fresh set if you’re running low.
  • Add a second, separate email address as a recovery option wherever the provider allows it.
  • Tell one trusted family member where your backup codes are stored, in case you ever need help.

None of this needs to happen all at once. Setting it up for one email account today, and coming back to your other accounts another day, is a perfectly good plan.

Where to go from here

Two-step verification is one of the strongest, simplest habits for keeping scammers out of your accounts, and it pairs well with the everyday scam-spotting skills covered throughout our Scam-Proof book.