Page 8 / 11
WhatsApp two-step verification is a secret 6-digit PIN on top of the SMS registration code, protecting your account from SIM swaps. Learn how to set it up and why the PIN can't be intercepted.
Carriers filter SMS to block spam and fraud - and legitimate codes sometimes get caught, usually silently. Learn what triggers filters and how registration and clean templates get through.
Lost access to your number? Recover accounts with a backup email, saved backup codes, an authenticator app, or a hardware key - but most must be set up first. Here's how.
Adversary-in-the-middle phishing relays your password and one-time code to the real site live, stealing your session. Learn why it defeats SMS OTP and why passkeys stop it.
Credential stuffing tries passwords leaked from one breach across many sites, succeeding wherever you reused one. Learn how it works and why unique passwords plus 2FA stop it.
Yes - services restrict supported countries, flag country-vs-location mismatches, and deliver unevenly by region. Learn why matching your number's country to the service decides if the code arrives.
MFA fatigue floods you with push-approval prompts hoping you tap 'approve' to make them stop. Learn how push bombing works, why codes are immune, and how to defend against it.
2FA uses exactly two factors; MFA uses two or more. Learn why 2FA is just the common form of MFA, when a third factor is worth it, and why both usually mean an SMS code.
QR login uses your already-trusted phone to vouch for a new device by scanning a one-time token. Learn how it works, why it's convenient, and the 'quishing' risk to avoid.
"Too many attempts" is rate limiting - a security block after repeated code requests or wrong tries. Learn why it triggers, why resending makes it worse, and how to get back in.
10DLC lets US businesses send verification texts over registered 10-digit numbers. Learn how registration works and why a sender's 10DLC compliance decides if your code arrives.
Six digits give a million combinations - hard to brute-force in a short expiry, easy to read and type. Learn why 6 became the standard OTP length and why more digits rarely help.
Biometric 2FA proves you're physically at your device; SMS proves you control a number. Learn how they differ, why they usually work together, and which an online number can receive.
A traditional landline can't display a text, but it can often get the code by automated voice call. Learn why SMS needs a mobile channel, the 'call me instead' workaround, and where VoIP blurs the line.
Google Voice is a free VoIP number that receives codes fine for everyday sign-ups but gets rejected by banks and strict services that block VoIP. Learn why, and when it works.
A port-out scam transfers your phone number to an attacker's carrier so your codes go to them — the SIM swap's twin. Learn how it works and how a transfer PIN stops it.
Carriers reassign old phone numbers to new people — and if the previous owner didn't unlink accounts, the new holder can receive their reset and 2FA codes. Learn the risk and how to avoid it.
A grey route is a cheap, unofficial path a text takes to your phone — until a carrier blocks it. Learn how grey routes cause late and missing verification codes and why routing quality matters.