Authenticator App vs SMS Codes: Which to Use
Short answer
Use an authenticator app wherever it is offered. SMS codes depend on your phone number, which can be moved to someone else's SIM by convincing your carrier — an app's codes are generated on the handset and cannot be redirected that way. SMS is still far better than no second factor, so keep it where it is the only option.
On this page
The advice to “switch from SMS to an authenticator app” gets repeated without the reason, so it reads like generic hardening and most people ignore it. The reason is specific and worth understanding, because it also tells you when SMS is perfectly acceptable.
SMS is the only second factor that depends on something you do not control: a record at your mobile carrier, maintained by staff who can be persuaded to change it.
What each one is actually tied to
An authenticator app stores a secret on the handset at setup time. From then on the app and the service independently compute the same six digits from that secret and the clock. Nothing travels over a network, there is no message to intercept, and the code exists only on that device.
An SMS code is generated by the service and sent to your phone number. A number is a routing entry at your carrier, not a property of your phone. Change the entry and the messages follow: a new SIM, an eSIM, or a different handset entirely.
That is the whole difference, and everything below follows from it.
The comparison that matters
| Authenticator app | SMS code | |
|---|---|---|
| Tied to | The device’s stored secret | Your phone number |
| Works with no signal | Yes | No |
| Can be redirected by a third party | No | Yes, via the carrier |
| Survives changing carrier or country | Yes | No |
| Phishable by a fake login page | Yes | Yes |
| Recovery if the phone is lost | Codes or sync, or nothing | Replacement SIM |
| Setup effort | Scan a QR code, save codes | None |
Two rows deserve attention because they cut in opposite directions.
“Can be redirected” is the security case for the app, and it is decisive. The attack is a number takeover: someone contacts your carrier with enough personal detail to pass their checks and has your number moved to a SIM they hold. Every SMS code for every account then arrives on their phone. This is a known, repeatedly documented attack pattern, and no setting on your phone prevents it, because the vulnerability is at the carrier.
“Recovery if the phone is lost” is the honest case for SMS, and it is why so many people quietly prefer it. Lose your phone with SMS 2FA and you walk into a shop, get a replacement SIM, and every account works again within a day. Lose it with an authenticator app and no recovery codes, and some of those accounts are gone permanently. What happens when the 2FA phone disappears sets out exactly which ones.
So the app is more secure and less forgiving. Switching without saving recovery codes trades one risk for a larger one.
What neither of them fixes
Both are six-digit codes you type into a page, which means both are phishable in the same way. A convincing fake login page asks for your password and your code together, and relays both to the real service inside the code’s 30-second window. The app’s secret is never exposed, but the attacker gets a session anyway.
Only passkeys and hardware keys close that gap, because they verify the site’s domain before responding and a lookalike domain gets nothing. What passkeys are and what they replace covers whether that is a switch worth making yet.
Push prompts sit between the two. They cannot be phished by a text field, but they can be approved by reflex, which is why the better implementations now show a number on screen that you must match.
When SMS is still the right answer
Not a reluctant concession. There are cases where SMS is correct:
- The service offers nothing else. Many banks, utilities, government portals and older retailers only do SMS. SMS 2FA beats password-only by a wide margin.
- Shared or low-stakes accounts. A streaming service or a loyalty scheme does not warrant a recovery-code regime.
- The person using it will not manage an app. A parent who will lose the recovery codes and panic at a QR screen is genuinely safer on SMS. The best second factor is the one that stays switched on.
- As a temporary bridge while you set up something stronger, then removed.
What makes SMS dangerous is not SMS itself. It is SMS on the account that controls everything else: your main email, your password manager, your carrier account. That is where a number takeover converts into total access.
How to switch without breaking anything
Work through this per account, and do not batch it.
- Install an authenticator and turn on its cloud backup before adding anything. Setting up Google Authenticator properly covers the order.
- Add the account by scanning the QR code in the service’s security settings, then confirm with a code so the pairing is actually active.
- Save the recovery codes. Before closing the page. This is the step that makes the switch safe rather than reckless.
- Sign out and back in once to confirm the app genuinely works for that account.
- Then remove SMS, if the service allows it. Some require a phone number on file regardless; where that is forced, the number stays as a recovery route and you accept it.
Step five is the one people skip, and skipping it means you have added effort without removing risk. An attacker chooses the weakest enabled method, not the one you prefer.
Lock down the number itself
Whatever you decide, protect the number, because it underpins far more than you think: password resets, bank verification calls, delivery confirmations.
Most carriers offer a port-out PIN, a number lock, or an account password separate from your online login. The names differ and the setting is usually buried, so ask them directly rather than hunting the app. It is the only control that addresses SIM swapping at the layer where it happens.
Realistic expectations
For most people the realistic outcome is a mix: authenticator apps on email, password manager and anything financial that supports it, SMS on the dozen services that offer nothing better, and a port-out lock on the carrier account. That is a reasonable place to land and does not require a weekend.
The failure worth avoiding is the half-switch — an app configured on your main email, recovery codes never saved, SMS left on as a fallback. That version is less secure than where you started and considerably easier to lock yourself out of.