Skip to main content
FixMyTech

Where to Store Your Recovery Codes Safely

By

Published

7 min read

Share

Short answer

Keep two copies in different places: one printed on paper somewhere secure at home, and one in a password manager that is not protected by the same device the codes would rescue. Never store them in the account they unlock, in your email, or only on the phone running the authenticator — those all fail in exactly the scenario the codes exist for.

On this page

Recovery codes get skipped because they appear at the end of a setup flow you have already decided is finished. The screen says “save these somewhere safe” and most people click Done, which is the single most expensive click in consumer security.

Those codes are not a convenience feature. For a large number of accounts they are the only route back in when the second factor is gone, because the provider has no other way to establish that you are you.

What makes storage good or bad

Every bad storage location fails the same test, so it is worth stating the test rather than listing the places.

The codes must be reachable in the exact scenario they exist for: your phone is gone, you cannot pass 2FA, and you may not be at home. A location that depends on any of those three is not storage, it is decoration.

Three properties, in priority order:

  1. Independent. It must not depend on the account, the device or the second factor in question.
  2. Durable. Still readable in three years, surviving a dead phone, a wiped laptop and a house move.
  3. Secured. Anyone who finds the codes can bypass your 2FA, so they are as sensitive as the password.

Most people optimise for the third and fail the first, which is how you end up with codes stored inside the account they were meant to rescue.

The places that fail, and why

Where Why it fails
Screenshot in your photo library Syncs to the cloud account the codes unlock
An email to yourself Needs the email account, often the locked one
A note in the account’s own notes app Circular; needs the account
Only on the phone with the authenticator Gone with the same phone
A plain text file on one laptop Unencrypted, and a single disk failure
A photo in your messaging app Sits in two people’s chat backups

The first three share one fault: a dependency loop. Recovery codes for a Google account stored in Google Drive, or Apple codes in Notes, are retrievable only by someone who can already sign in. The codes exist precisely for the person who cannot.

The fourth is the most common and the most quietly fatal. Codes saved into the same phone that runs the authenticator cover you for forgetting a password and for nothing else. One dropped handset takes both.

The places that work

Printed on paper, at home

Unfashionable and the best single answer. Paper does not sync, cannot be remotely compromised, survives every device failure, and is readable by whoever needs it in an emergency.

Print the sheet, write the account name and the date on it, and put it somewhere you would keep a passport or a birth certificate. A locked drawer, a document box, a safe. Not a desk drawer labelled “passwords”, and not in a wallet where it travels with you.

If you want the extra margin, a second copy at a relative’s house or in a bank box covers fire and theft. That is proportionate for the two or three accounts that genuinely matter and excessive for anything else.

A password manager

Good, with one condition: the manager must not be locked behind the thing you are trying to recover.

So — codes for your email, your bank and your social accounts go in the manager happily. Codes for the manager itself go on paper, because a vault that contains its own recovery key is not a backup.

The practical advantage is that you will actually find them. A password manager is searchable, syncs across devices, and is somewhere you already look. Paper in a drawer is more secure and considerably easier to forget about, which is why two copies in different forms is the recommendation rather than a choice between them. Choosing a password manager covers the options.

An encrypted file on a USB drive

Reasonable for anyone comfortable with it. An encrypted archive or a small encrypted volume on a USB stick kept with your important documents is durable and independent.

The caveat is honest: encryption you cannot open is the same as data loss. If the password for that archive lives only in your head and you use it once every four years, the odds are not in your favour. Write that password on the paper copy.

A fireproof document box or safe

If you already have one for passports and deeds, the codes belong there. It is the storage problem solved, and it makes the annual check easy because everything is in one place.

Doing it properly, once

Fifteen minutes, and it covers the accounts where this actually matters.

  1. List the accounts that need it. Main email, password manager, phone carrier, banking, anything holding your identity documents. Usually four to six.
  2. Generate fresh codes for each, from the account’s security settings. This invalidates any old set you might have lost, which is a benefit rather than a cost.
  3. Print them on one sheet, labelled by account, with the date.
  4. Store the sheet with your important documents.
  5. Add the same codes to your password manager, in a clearly named entry — except the manager’s own codes, which stay on paper only.
  6. Cross one off as used and generate a new set when you are down to two or three remaining.

Point six is the step people miss. Codes are single-use, and a sheet quietly exhausted over three years is a sheet that will fail at the worst moment.

While you are there

Recovery codes are one of three things a locked-out account needs, and the other two take another five minutes.

A verified recovery email and phone on each important account, pointed at somewhere you can still reach if your primary phone is gone. Check they are current; stale recovery details are nearly as useless as none.

A second device able to produce the second factor. Another phone, a tablet, or a password manager that stores TOTP codes. Setting up an authenticator so this is covered explains the order.

Together those three mean a lost phone costs you an afternoon rather than an account. Without them, you are relying on provider recovery processes that take days and sometimes say no.

Realistic expectations

Done for your five most important accounts, this is a one-off fifteen minutes and an annual five-minute check that the sheet is still valid and the recovery addresses still work.

The honest limitation is that recovery codes only help with accounts that issue them, and plenty of smaller services do not. For those, a verified backup email address is the whole of your safety net, which is a reason to keep that address reachable and protected rather than letting it quietly lapse.

Frequently asked questions

What are recovery codes actually for?
They are single-use strings that substitute for your second factor when you cannot produce one. Each works once, so a sheet of ten gives you ten chances to get back in without the authenticator, the phone or the hardware key.
What if I have already lost the codes?
Generate a fresh set immediately from the account's security settings, which invalidates the old ones. You can only do this while signed in, so do it now rather than when you need it.
Is it safe to photograph my recovery codes?
It is better than having no copy, but worse than it looks. The photo lands in a library that probably syncs to a cloud account, which may itself be protected by the 2FA those codes unlock. If you do it, move the image into an encrypted store and delete the original.
Do recovery codes expire?
Generally not by date, but they are invalidated whenever you generate a new set, and some services replace them automatically when you change your second-factor method. If you have reconfigured 2FA since printing them, check the old sheet is still valid.
How many accounts actually need this?
Fewer than you think. Your main email, your password manager, your phone carrier account and anything financial are the ones where losing access is genuinely serious. For a forum login, a lost account is an inconvenience rather than a problem.

All Accounts guides