All guides

Not losing your account — 2FA and recovery methods

Recovery rules got stricter in 2026. Set this up now or you may never get back in. It takes five minutes.

Updated 2026-07-25

What changed

There used to be room for a support ticket to sort things out. Now you must pass both an email challenge and a phone challenge. Asking nicely does not open the door.

So turning on 2FA is not enough by itself. You also need a way back in if you lose your device. Skip this and a new phone is all it takes to lose the account permanently.

Step 1 — turn on 2-Step Verification

Find it under security in your account settings. Several methods exist, but one is clearly the practical choice.

  • Authenticator app — a six-digit code that changes every 30 seconds. Works on web, mobile, and Studio. This is the one to use.
  • Security key — a physical key or your device's fingerprint/face unlock. The most secure, but you must also enable the authenticator app as a backup for it.
  • Email — the weakest. If your email is compromised, so is this. Use something else if you can.

Step 2 — add at least two recovery methods

This is the part almost everyone skips. Register at least two of these.

  • Phone number — 13 and over only. Used together with the email challenge during recovery.
  • Passkey — sign in with your device's fingerprint or face. No age limit, cannot be phished, and it skips the 2FA prompt entirely.
  • Backup codes — a set of one-time codes. No age limit. These are how you get in when the authenticator is gone.

Under 13 and unable to add a phone number? Use a passkey and backup codes.

Where to keep backup codes

Screenshotting them into your photo roll is a bad idea. Other apps can read your photos, and if you lose the device the codes go with it.

  1. Write them on paper and keep it somewhere only you know. This is the most reliable option.
  2. If you have a parent or guardian, leave a copy with them too.
  3. If you use a password manager, store them there as a note.
  4. Each code works once, so check occasionally how many are left.

If your account is already taken

  1. If you can still log in, change your password first. That signs out every other device.
  2. Check whether the email address was changed. If they changed it, recovery gets much harder.
  3. If you cannot log in, contact Roblox support with everything only you would know: when the account was created, past usernames, purchase history.
  4. If you have ever paid for anything, that receipt is your strongest evidence.
  5. Once you are back in, set up 2FA and recovery methods. An account that got taken once gets targeted again.

You can look up past usernames using the profile lookup on this site and include them in your support request.

How accounts actually get taken

Guessed passwords are rare. It is almost always one of these three.

  • Entering your login on a site promising free Robux. Nobody gives Robux away.
  • Reusing a password from another site. When that site leaks, your Roblox account goes with it.
  • Lending your account to someone who offered to "trade for you" or "put an item in". Roblox staff never ask for passwords.

Related reading