Built from reviewed service data

Account security checklist — built for your services

Choose the services you use and turn login.com's reviewed security information into a printable, copyable action plan.

Everything you enter or generate here stays in your browser — the tools make no network requests. The only other activity on this page is standard page-view analytics; see Privacy for exactly what's measured.

Your checklist

No services selected. Selections disappear when this page is refreshed.

What the checklist gives you for a real service

Pick GitHub and the checklist starts with github.com/login, then shows the recorded path through Settings to Password and authentication. It lists the methods supported by the reviewed GitHub material, marks passkeys as confirmed, and links to GitHub’s authentication help. The output is not a score. It is a short work order you can keep beside the real account while you check the domain, replace a reused password, configure a stronger method, prepare recovery, and review sessions.

Now add Spotify. The shape changes because the evidence is different. You still get accounts.spotify.com and the official help route, but the 2FA path and passkey status remain unverified in our review. The checklist says so plainly instead of turning an absent source into “unsupported.” That contrast is the point: each selected service carries its own reviewed facts, not a generic set of green check marks.

Choose an order that prevents lockouts

Start with the account that can reset the others. For many people that is email; for a team it may be an identity provider or administrator-controlled workspace. Keep a trusted session open. Before removing an old factor, confirm the recovery address, save fresh backup codes somewhere away from the daily device, and add the replacement method. Then use a private browser window to prove that a clean sign-in works.

Move through a few accounts at a time. A Saturday spent changing twenty logins is how recovery details get mixed up and untested methods become the only method. The copied checklist is more useful as a queue: email and password manager first, then developer or workplace accounts, followed by stores, media, and lower-impact services. If a page does not match the recorded menu, stop and consult the linked official help rather than guessing where a security control moved.

Read “confirmed” and “unknown” carefully

A confirmed passkey entry means current official material supported that claim on the review date. It is not a promise that every plan, device, country, or managed tenant exposes the button. Unknown is even narrower: the project did not find evidence strong enough to publish a current claim. Unknown does not mean no. Open the live account from the listed official domain and check the provider’s own help before making a decision.

The same rule applies to menu paths. Providers rename settings, test interfaces, and split personal from enterprise accounts. The path in the checklist is a reviewed starting point, while the linked guide shows the evidence date and source trail. If an organization uses single sign-on, learn which identity provider actually owns authentication. Changing a setting in the downstream app may do nothing—or may remove the only local fallback the administrator intended you to keep.

What is saved, copied, and worth revisiting

Selections live only in this page. Refresh and they disappear. Copying or printing creates the only lasting version, and that version can reveal which accounts matter to you, so treat it like private operational information. Store it with the same care you would give an account inventory. The checklist never needs a password, a one-time code, a recovery code, or a screenshot of the security page.

Run another pass after replacing a phone, losing a hardware key, changing jobs, updating recovery contact information, or seeing an unexplained sign-in. Review active sessions and connected applications while you are there. Remove what you do not recognize, but preserve one tested route until its replacement works. A useful account-security checklist is not proof that setup happened once. It is a record of which recovery assumptions you have actually tested.

Practical sequence

How to use this tool safely

  1. 01

    Search the local service index and add the accounts you want to review.

  2. 02

    Open each verified destination independently and follow the recorded security path.

  3. 03

    Prepare recovery, test a fresh sign-in, and then mark each action complete.

  4. 04

    Print or copy the plan only to a protected location, then clear the page selection.

Common questions

Account security checklist FAQ

Are my selected services saved?

No. The selection exists only in the current page memory. It is not written to local storage, cookies, analytics, or a login.com server, and refreshing the page clears it.

What does an unknown 2FA path mean?

It means the project did not verify a current official step-by-step source strong enough to publish the menu. It does not mean the service lacks 2FA; inspect the live official account and provider help.

Which accounts should I secure first?

Start with accounts that can reset or influence others, especially email, password managers, developer platforms, and workplace collaboration. Then cover services with payments, purchases, files, audiences, or valuable history.

Can I share the generated checklist?

You can copy or print it, but the service list may reveal sensitive information about your accounts. Store or share the output only through a channel appropriate for that privacy risk.

References

Primary guidance