The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To protect an X account, use a unique password for X and its associated email, turn on an available second sign-in method, keep a recovery option such as a backup code, and enter credentials only on the genuine x.com domain or in the official app. If you suspect someone has taken over the account, change the password, secure the linked email, revoke unfamiliar app access, and contact X support if you cannot regain access.
How do I know if an X login page is fake?
Phishing pages imitate X to capture a username, email address or phone number, and password. The page may look convincing, so check the address bar rather than relying on its appearance or the text shown for a link. X advises checking that the base domain is x.com; if you are unsure, open a new browser tab and go to x.com directly.
- Do not enter your password after following an unexpected link in a Direct Message, email, text, or reply—even if it came from someone you know.
- X Help says, “X will never ask you to provide your password via email, Direct Message, or reply.” X also says it will not ask you to download something or sign in on a non-X website. See X’s account-security tips.
- Treat requests to complete an X liveness check through a link with suspicion. X says liveness checks appear only inside the official app or, for QR checks, the X App Clip on iOS; it will not send a link to complete one by email, text, or Direct Message. Details are in X’s liveness-check guidance.
How should I strengthen X sign-in and account recovery?
Use unique passwords for X and its recovery email
X recommends a strong, unreused password and gives a minimum length recommendation of 10 characters. Use a different strong password for the email account linked to X: someone who controls that mailbox may be able to reset access to X. A password manager can help you create and keep distinct passwords without reusing them.
Turn on a second sign-in method
X offers two-factor authentication (2FA), which adds a check after the password, and also documents passkeys as a sign-in option. Available choices and setup can depend on the account, device, region, and current X settings.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Method | What to consider |
|---|---|
| Passkey | X describes passkeys as using the WebAuthn standard: the device creates a public/private key pair, X stores the public key, and the private key stays on the device. X says passkeys are available on iOS and Android and are encouraged, not required. Consider how you will recover access if you lose the device. |
| Authentication app | Generates sign-in codes through an app. You need access to the app or its recovery method when signing in. |
| Security key | A physical security key is an optional 2FA method listed by X. Check compatibility with your devices and keep a recovery route in case the key is lost. |
| SMS text message | X stopped supporting SMS 2FA for non-Premium subscribers effective March 20, 2023. For Premium subscribers, availability may vary by country and carrier; check the current account settings. |
X’s help pages describe 2FA under Settings and privacy > Security and account access > Security; passkey setup is described under Security and account access > Security > Passkey. Labels and paths can change, so use the current in-app settings if they differ. See X’s 2FA instructions and passkey instructions.
Make password resets harder to redirect
X recommends requiring both the email address and phone number to initiate a password reset link or code. Look for this option in the account’s security settings. It is an added safeguard, not a guarantee against takeover.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Save a backup code before you need it
X says a backup code can be generated when 2FA is enabled in its iOS or Android app, and can also be generated on x.com. Keep it somewhere private and accessible if your phone is lost or your number changes; X suggests writing it down, printing it, or taking a screenshot. Do not send the code to anyone claiming to be support. A backup code is different from a temporary password, which is used to sign in to some third-party apps that require an X password. If you are logged out and have no active backup code, X directs you to contact support. See X’s 2FA login help.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhat should I do if my X account was hacked?
Take action if you see posts or Direct Messages you did not send, unfamiliar follows, unfollows or blocks, account-change notices you did not initiate, or a password that no longer works. X says unexpected activity can sometimes come from an application bug, so investigate app access as well as possible unauthorized sign-ins. A new-device or suspicious-login alert you cannot recognize is a reason to act promptly.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- If you can still sign in, change your X password. Choose a strong password you do not use elsewhere. Changing it does not automatically log out every X mobile app session, so continue with the app-access review.
- Secure the email account associated with X. Change its password if needed and check that only you can access it. If X notifies you that the account email was changed, its message may contain a link to reverse an unauthorized change. Confirm the message is genuine before using any link; if unsure, go to X directly.
- Revoke unfamiliar third-party app access. Review connected applications in X account settings and remove access you do not recognize. If a trusted external app stored your X password, update the saved password there too; otherwise, repeated failed sign-ins could cause further lockouts.
- Remove unauthorized activity and check your devices. Delete posts you did not publish. If suspicious behavior continues after the password change, scan computers for viruses or malware and install operating-system and application security updates.
- If you cannot sign in after trying a password reset, submit an X support request. Use the account-access form at X’s hacked-or-compromised account form, using the email associated with the account. X asks for your username and the date you last had access; the process may require a password reset.
X identifies possible compromise routes including giving credentials or tokens to a malicious app or website, using a weak or reused password, password-stealing malware, and signing in over a compromised network. X’s guidance is available in Help with my compromised account and its authenticity guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Does a temporary X lockout mean someone got in?
No. X says an account may be temporarily locked after too many failed login attempts. That lockout by itself does not show that another person successfully accessed the account. Follow X’s temporary-lockout guidance, and separately check for unfamiliar activity or security notifications.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

