Keep access when your SIM changes.

Before travel or a phone change, find the accounts that still depend on SMS. Add a stronger method where possible, keep a separate recovery path, and test the whole setup before deleting anything.

1. Check the accounts that can lock you out

Start with your primary email. It is often the recovery channel for banking, cloud storage, work tools, social accounts, and the app store itself. If email access depends on an SMS sent to a SIM that is unavailable abroad, every downstream recovery path becomes more fragile.

Do not replace everything in one sitting. Make a short list of critical accounts, change one account at a time, and complete a real sign-in before moving to the next. Keep the old authenticator and old recovery method until the replacement has been tested.

  • List the primary email, password manager, Apple or Google account, banks, work identity, mobile carrier, and any service needed during the trip.
  • Mark the accounts whose only second factor is a text message or call to one phone number.
  • Add a passkey or hardware security key where the service and your recovery setup support it.
  • For accounts without a phishing-resistant option, add a standard authenticator code rather than relying only on SMS.
  • Generate fresh recovery codes and keep them somewhere separate from the password and the only phone.
  • Confirm that the account has a second, independent recovery method. More copies of the same SIM-dependent method do not add much resilience.
  • Turn on airplane mode and verify that the authenticator still produces current codes. Then reconnect and complete a real sign-in.

2. Use different methods for different failures

Authentication and recovery solve related but different problems. A passkey can provide strong, phishing-resistant sign-in. An authenticator can provide an offline code. A recovery code can regain access when the authenticator is lost. A second trusted device can help when the primary phone is unavailable. They should not all fail together.

The usual mistake is concentration: password, TOTP seed, recovery codes, and email session all live on one unlocked phone. That setup feels convenient until the phone is lost. Moving one copy into the cloud is not automatically enough if the same unavailable account protects that cloud backup.

Passkeys and security keys first

Where available, passkeys and hardware security keys reduce the risk of giving a credential to a phishing site. Set them up on more than one trusted device or key when the service allows it, and understand the provider's recovery process before relying on them overseas.

Offline authenticator codes next

Standard TOTP codes are calculated from a shared secret and the current time. The code generator normally does not need a mobile connection, but the device clock must be reasonably accurate and the service still needs a network connection to receive the sign-in. HOTP uses a counter instead of time and is less common in consumer setup flows.

Recovery codes somewhere else

A recovery code is valuable precisely because it works when the normal second factor does not. Print it, store it in a different protected system, or give a sealed copy to a trusted person where appropriate. Do not leave the only copy beside the password it is meant to recover.

3. Treat an exported QR code like the account secret

Authenticator portability matters. A tool should not become another place you are locked into. But an export QR code is not a harmless picture: a standard otpauth QR normally contains the underlying shared secret. Anyone who copies it may be able to generate the same codes.

Export only when you are ready to complete a migration. Keep the old authenticator until the new one works, then remove screenshots or exported images from Photos, Recently Deleted, shared folders, chat attachments, desktop downloads, and printer queues as appropriate. If an export was exposed to someone else, rotate the authenticator secret through the account's official security settings rather than merely deleting the image.

Check the exact export format before promising yourself an easy move. Some apps use a proprietary cloud backup. Some provide a standard QR for each account. Some support a batch migration format that other apps may not understand. A successful-looking import of one entry does not prove that every algorithm, digit count, period, or issuer label transferred correctly.

  • Prefer a standard format you can verify rather than an undocumented screenshot or opaque backup.
  • Move one important account first and complete a sign-in before migrating the rest.
  • Keep the device time set automatically unless a specific environment requires otherwise.
  • Delete temporary export copies only after the replacement authenticator has been tested.
  • Rotate the secret at the service if you believe an export QR or setup key was exposed.
  • Remember that export protects portability; it does not make TOTP phishing-resistant.

Primary sources worth reading

These references explain both the value and the limits of different authentication methods.

CISA

Require multifactor authentication

CISA's practical ordering of phishing-resistant methods, authenticator codes, and SMS or email factors.

Read the MFA guidance →
NIST

Authenticator requirements

The technical standard explains why manually entered OTP codes are not phishing-resistant and how authenticators are classified.

Read the standard →
GOOGLE

Set up two-step verification

Official steps for Google prompts, authenticator codes, security keys, passkeys, phone numbers, and backup codes.

Review Google 2SV →
GOOGLE

Create and use backup codes

Official guidance for generating, storing, replacing, and using one-time recovery codes for a Google Account.

Review backup codes →

Offline authenticator and export FAQ

The small details matter when the old phone is about to disappear.

Will authenticator codes work without a SIM or internet connection?

Standard TOTP codes are generated on the device and normally work without a SIM or data connection when the clock is correct. The website or app receiving the code still needs connectivity, and it may impose additional risk checks.

Is TOTP safer than SMS?

It avoids dependence on mobile delivery and several SIM-related failures, but it can still be phished. Passkeys and hardware security keys offer stronger phishing resistance when supported. Keep a separate recovery method whichever option you choose.

Can I keep an export QR in my photo library?

It is technically possible, but the QR normally exposes the shared secret to anyone or any service that can read the image. Use it briefly for migration, protect it like a password, delete unnecessary copies, and rotate the secret if exposure is suspected.

What if I forget the password to a local authenticator vault?

A local-first app may be unable to recover it. Keep independent recovery codes and test exports before relying on one vault as the only copy. A forgotten local vault password cannot be recovered by the developer.

Put the account plan into the rest of your travel setup.

The travel checklist covers offline documents, data minimization, lost-phone preparation, and the final airplane-mode test.

Open the travel checklist