Follow these core practices to minimize risk and keep your account safe from phishing and account takeover attempts.
Enable Two-Factor Authentication (2FA)
Use an authenticator app or hardware key. Avoid SMS-based 2FA where possible.
Verify the Domain
Check the TLS lock and exact hostname to avoid phishing pages that mimic the login UI.
Use Hardware Security Keys
FIDO2 / WebAuthn keys provide strong phishing-resistant protection for signing in.
Keep Recovery Details Offline
Store backup codes and account recovery information in a secure offline location.