You have probably seen it. You log into your email or your bank account, and instead of getting in right away, the screen asks for a code. That extra step has a name: two-factor authentication, or 2FA for short.
It can feel like one more hurdle when all you want to do is check your balance. But that small hurdle is one of the most useful things you can do online. It keeps scammers out even when they somehow get hold of your password.
In this guide, we will explain what 2FA actually is, why it matters so much, and how to turn it on for your email and your bank in about five minutes each.
What Is Two-Factor Authentication?
Two-factor authentication is a login step that asks you to prove who you are in two different ways instead of just one. The first way is something you know, your password. The second way is something you have, usually your phone.
Plain talk: two-factor authentication
Two-factor authentication (2FA) means using two different proofs to log in: your password, plus a one-time code or an approval from your phone. You may also see it called multi-factor authentication, or MFA. They mean the same thing.
When you type your password on an account that has 2FA turned on, the site does not let you straight in. It sends a short numeric code to your phone, or asks you to approve the login inside an app on your phone. Only after you finish that second step does the account open.
Think of it like a safety deposit box at a bank. You need your own key, but the bank also needs to check your ID before the box opens. One proof alone is not enough. Two proofs together keep the box safe even if someone copies your key.
Why Do You Need 2FA?
Passwords leak far more often than most people realize. A company you have an account with can be hacked, and your password can end up posted online without you ever knowing it happened. Scammers also send fake login pages by text or email, hoping you will type your password into them by mistake.
If a scammer gets your password and your account has no 2FA, they are in. They can read your email, reset your other passwords, or move money out of your bank account. With 2FA turned on, a stolen password alone is not enough. The scammer also needs your phone, and they usually do not have it.
The FTC’s “Use Two-Factor Authentication To Protect Your Accounts” article calls it one of the single best steps you can take to protect an account, because it stops most break-in attempts even after a password is already out in the open.
If you are worried a scammer may already have one of your passwords, our guide on what to do after you click a scam link walks through the exact steps to take right now.
SMS Codes vs. Authenticator Apps
There are a few common ways to receive your second proof. Here is how the main ones compare.
| Method | How it works | How safe it is |
|---|---|---|
| Text message code | A code is sent by SMS to your phone number | Good, but can be intercepted through a SIM swap |
| Authenticator app | An app on your phone generates a changing code, or sends an approval request | Safer, tied to your device, not your phone number |
| Security key | A small physical device you plug in or tap | Very safe, but less common for everyday accounts |
Plain talk: authenticator app
An authenticator app is a free app, such as Google Authenticator or Microsoft Authenticator, that sits on your phone and creates a new six-digit code every 30 seconds. You open the app, read the current code, and type it in.
Safety tip
Scammers can sometimes trick a phone company into moving your number onto a new SIM card, something called a SIM swap. Once that happens, your text message codes go to the scammer’s phone instead of yours. According to the FTC’s SIM Swap Scams alert, an authenticator app is safer than text codes because it does not depend on your phone number at all. If you only ever use text codes, that is still far better than having no 2FA, but an app is the stronger choice when you are ready to try it.
The National Institute of Standards and Technology, the US government’s technology standards agency, also recommends apps or security keys over text codes when you have the choice, in its Digital Identity Guidelines. Start with whichever option feels manageable. Any 2FA is better than none.
How to Turn On 2FA for Your Email
Email deserves 2FA first, because it is usually the account a scammer can use to reset everything else. Here is how to turn it on for a Google account, using steps from Google’s own Account Help pages.
- Open a web browser and go to your Google Account settings.
- Select Security from the menu on the left.
- Under “How you sign in to Google,” select 2-Step Verification.
- Sign in again with your password if asked.
- Choose your second step. A text message code is the simplest to start with, or select Authenticator app if you would like to try that instead.
- Follow the on-screen prompts, then select Turn On.
If you use Outlook, Yahoo, or another email provider, look in Settings, then Security or Sign-in options, for the same kind of “2-Step” or “Two-Factor” setting. The wording differs slightly by company, but the idea is the same everywhere.
How to Turn On 2FA for Your Bank
Most banks already offer 2FA, and some turn part of it on automatically. To check or turn it on yourself:
- Log into your bank’s website or app as you normally would.
- Look for Security Settings, Login Settings, or Profile.
- Look for wording like “Two-Factor Authentication,” “Two-Step Verification,” or “Extra Security.”
- Turn it on and choose text message or an authenticator app as your second step.
- Save any backup codes the bank offers you.
If you cannot find the setting, call the number printed on the back of your bank card and ask.
Say this
“Hi, I would like to turn on two-factor authentication, or extra login security, on my account. Can you tell me where to find that setting, or turn it on for me?”
What About Backup Codes?
When you turn on 2FA, most services offer a set of backup codes, one-time codes you can use if your phone is ever lost, broken, or out of battery.
Try this
When you set up 2FA, look for an option to view, print, or save backup codes. Write them down and keep them somewhere safe at home, like a drawer or a folder with your important papers, not saved on the phone itself.
Without a backup code, losing your phone can mean a stressful call to customer support to prove it is really you. A few minutes now saves that headache later.
What 2FA Will Not Protect You From
2FA is powerful, but it is not magic. It protects against a scammer who has stolen or guessed your password. It cannot protect you if a scammer convinces you, on the phone or by text, to read your code out loud or type it into a fake page yourself. That is a different kind of trick entirely.
A real bank, a real government agency, or a real tech company will never call you and ask for your 2FA code. If anyone asks for it, hang up. Our guide to the bank “safe account” scam explains one common version of this trick, where a caller pretends to be your bank to get you to move money or share codes yourself.
If you ever do get locked out of an account, or you suspect someone got in despite your 2FA, our guide on where to report a scam lists exactly who to contact in the US, UK, Australia, and Canada. It is also worth reviewing whether to freeze your credit after a scam if you think any financial account was touched.
Where to Go From Here
Two-factor authentication is one small setting that closes off most of the ways scammers try to break into an account. Start with your email today, then move on to your bank and any account that holds money or personal details. For more ways to spot and stop scams before they reach you, our Scam-Stopper Kit (free when you join our email letter) is a good next step, and our book Scam-Proof goes further into building habits that keep your accounts and your money safe.

