Account recovery is strongest when losing one device or service does not lock you out of everything. The goal is controlled redundancy, not a large collection of weak recovery routes.
Start with your primary email
Use a unique password and an authenticator app or security key where supported. Check that the recovery email is itself protected and not dependent on the first inbox.
Keep two independent authentication methods
For an important account, consider a primary authenticator and a separately stored backup method. A second security key can help if the first is lost. Avoid relying only on text messages when stronger methods are available.
Store recovery codes separately
Treat recovery codes as passwords. Keep them encrypted in a reputable password manager or as a protected offline copy. Do not store the account password and its recovery codes together in an unprotected note.
Review your phone-number risk
Protect the mobile account with a carrier PIN or equivalent control where available. Remove old numbers from online accounts and check what happens if your phone is lost or replaced.
Document the plan
Record which accounts are most important, where their official recovery pages are, what backup method exists, and when you last reviewed it. Do not record live passwords in the plan.
Review every six months
Remove old devices, expired work addresses, unused application passwords, and recovery methods you no longer control. Regenerate codes after exposure and update the plan after changing a phone, email address, or authenticator.