Two-Factor Authentication (2FA) Explained:Methods Compared
How two-factor authentication works, and how SMS codes, authenticator apps, push prompts, security keys and passkeys compare, plus how to store recovery codes safely.

Table of Contents
Two-factor authentication (2FA) requires two different kinds of proof to log in: usually something you know (a password) plus something you have (a phone app or a security key). If an attacker steals or guesses your password, they still cannot log in without the second factor. Turning on 2FA for your email, hosting, domain registrar and website admin is one of the most effective security steps you can take.
The methods are not equally strong, though. Here is how they compare.
The factors
- Something you know: a password or PIN.
- Something you have: a phone, an authenticator app, a security key.
- Something you are: a fingerprint or face, usually used to unlock a device or passkey.
"Multi-factor authentication" (MFA) is the general term; 2FA means exactly two factors.
Methods compared
| Method | How it works | Strengths | Weaknesses |
|---|---|---|---|
| SMS or voice code | A code sent to your phone number | Easy, no app needed | SIM-swap attacks, interception, phishable, depends on mobile signal |
| Email code | A code sent by email | Easy | Only as secure as the email account |
| Authenticator app (TOTP) | An app generates a 6-digit code every 30 seconds | Works offline, much stronger than SMS | Codes can still be phished in real time |
| Push approval | Approve a prompt in an app | Convenient | "Push fatigue" attacks; better with number matching |
| Security key (FIDO2/WebAuthn) | A physical key you tap or insert | Very strong, resists phishing | Cost; need a backup key |
| Passkey | A cryptographic credential on your device, unlocked by fingerprint, face or PIN | Strong and phishing-resistant, easy to use | Device and service support still growing |
Phishing-resistant methods (security keys and passkeys) check the website's real address cryptographically, so a fake login page cannot capture a usable credential.
Which should you use?
- For your most important accounts (email, registrar, hosting, admin): a security key or passkey where supported, otherwise an authenticator app.
- SMS is better than no 2FA, but use an app or key when available.
- For staff: require 2FA on admin and shop-manager accounts at minimum.
Setting up an authenticator app
- In the account's security settings, choose "authenticator app".
- Scan the QR code with your authenticator app.
- Enter the 6-digit code to confirm.
- Save the recovery codes shown (see below).
For WordPress, a 2FA plugin adds this to the login; see the WordPress security checklist. cPanel also supports two-factor authentication in its Security section.
Recovery codes: do not skip them
When you enable 2FA, most services give you one-time recovery codes. If you lose your phone, these are often the only way back into the account.
- Store them in your password manager or another secure place, not in a screenshot on the same phone.
- For critical accounts, register two second factors (for example two security keys, or an app plus a key).
- When you replace your phone, move your authenticator accounts before wiping the old device.
Common problems
- Codes not accepted: the phone's clock is wrong; set time automatically.
- Lost phone: use recovery codes or a backup factor, then reconfigure 2FA.
- Locked out with no recovery: contact the service's support, which will require identity verification and may take time.
A 2FA rollout plan for a small business
- List critical accounts: email (especially the admin mailbox), domain registrar, hosting control panel, website admin, payment providers, social media, accounting software, password manager.
- Choose methods: authenticator app as the standard; security keys or passkeys for the owner and administrators where supported.
- Enable 2FA account by account, starting with email and the registrar, because they can reset everything else.
- Store recovery codes in the business password manager, not in personal notes.
- Register a backup factor (a second key, or the app on a second device kept safely) for accounts that only one person controls.
- Write down the recovery process: who to contact if someone loses their phone.
- Check quarterly that new accounts and new staff have 2FA enabled.
Example: the attack 2FA stops
An employee reuses their email password on a forum that is later breached. Attackers try the leaked password on the company's webmail and it works, but the login asks for a code from an authenticator app the attackers do not have. The login fails, the employee receives an alert about a failed attempt, and changes the password. Without 2FA, the attackers would have read the mailbox, reset other passwords through it, and possibly sent fake invoices to customers.
For website owners: offering 2FA to your users
- Support authenticator apps and, ideally, passkeys.
- Make recovery codes part of setup.
- Require 2FA for administrator accounts.
- Rate-limit code attempts to prevent guessing.
Frequently Asked Questions
Does 2FA make accounts impossible to hack?
No, but it blocks the most common attacks based on stolen passwords. Phishing-resistant methods block real-time phishing too.
Is a fingerprint a second factor?
On its own it usually unlocks a device-held credential, such as a passkey. Combined with possession of the device, it provides strong authentication.
What are passkeys?
Passkeys replace passwords with a key pair stored on your device or in your password manager. The website stores only the public key, so there is no password to steal.
Related reading
2FA is step 2 of website security basics. Pair it with strong passwords and password managers. For help with your ServerNeed account security, contact support.
Sources
Featured image: “mandoingvideocallfromhomestockphotoauthenticf6b4e6ce-2cb0-4821-964a-03f96e5d0f6c” by digitalcreators.ch, licensed under CC BY 2.0.
Last updated 7 October 2026



