Two-Factor Authentication Without a Phone Number
Contents
- The short answer, and what changes for you
- Where a number is still required anyway
- Why is SMS the weakest second factor?
- How do you migrate off SMS without locking yourself out?
- What do specific services and countries require at sign-up?
- What do you do when the code or the key fails?
- Common questions about two-factor authentication without a phone number
Yes. On most accounts you can turn off SMS codes entirely and use an authenticator app or a hardware key instead. Both are stronger than a text message, and neither one depends on a carrier, a SIM card or a number you have to keep alive forever.
What each second factor protects against
| Factor | Stops password reuse | Stops phishing | Stops SIM swap | Works offline |
|---|---|---|---|---|
| SMS code | Yes | No | No | No |
| Authenticator app (TOTP) | Yes | Partly | Yes | Yes |
| Push approval | Yes | Partly | Yes | No |
| Hardware key | Yes | Yes | Yes | Yes |
| Recovery codes | Yes | Yes | Yes | Yes |
The short answer, and what changes for you
An authenticator app generates a six-digit TOTP code from a shared secret stored on your device. It refreshes every 30 seconds and works with airplane mode on. A hardware key (a FIDO2 security key or a passkey stored in your phone or password manager) signs a challenge from the site itself, so a fake login page gets nothing usable.
What actually changes day to day:
| Factor | Needs signal | Phishing resistant | Recovery path |
|---|---|---|---|
| SMS code | Yes | No | Carrier and SIM |
| Authenticator app | No | No | Backup codes or encrypted export |
| Hardware key or passkey | No | Yes | Second key or backup codes |
The cost is that recovery moves onto you. With SMS, the carrier is your backup. With an app or a key, backup codes are the backup, and you have to save them before you need them.
Where a number is still required anyway
Three cases still ask for a number, and no app-based factor replaces them.
- Sign-up itself. Messaging and ride-hailing apps use the number as the account identifier, not as a second factor. WhatsApp, Telegram and Signal are built on the number.
- Account recovery floors. Some banks, brokers and government portals keep SMS as the only reset channel even after you add an app.
- Regional rules. Certain countries require a verified number for financial and telecom services, and the requirement sits in the sign-up flow rather than in the security settings.
For the second and third cases, and for second accounts you keep separate from your personal line, MarioSMS rents a real mobile number for one verification at a time, from $0.04, across 35+ countries. Use it for privacy hygiene and testing, never to evade a ban.
Why is SMS the weakest second factor?
SMS codes travel through systems you do not control: a carrier database, a support desk, an SS7 route, a lock screen preview. Every hop is a place the code can be read or redirected. The table below shows what each second factor actually stops, and where SMS leaves a gap.
[Table: What each second factor protects against]
A TOTP app generates codes on your device from a shared secret, with no network path to intercept. The screenshot shows a typical authenticator listing several accounts, each rotating a six-digit code every 30 seconds, offline, on a plane, with the SIM tray empty.
[Image: An authenticator app on a phone]
Hardware keys go further by tying the login to the site’s actual domain. The browser signs a challenge only for the origin it is talking to, so a lookalike page gets nothing usable. That single property is what separates a key from every code-based factor.
SIM swaps, port-outs and carrier support desks
An attacker calls your carrier, gives your name, address and last four digits, and claims a lost phone. The carrier moves your number to their SIM. Your phone drops to no service, and their phone starts receiving your codes. A port-out to a different carrier does the same thing with a PIN and an account number. Both take minutes, not days.
Phishing pages that relay your code in real time
A phishing kit sits between you and the real site. You type your password on the fake page, it forwards them, the real site texts you a code, you type the code, the kit forwards that too. The OTP is valid and correctly delivered. It just arrives at the wrong destination. TOTP codes fail here for the same reason, which is why phishing-resistant keys matter.
What a TOTP app and a hardware key each block
| Attack | SMS | TOTP app | Hardware key |
|---|---|---|---|
| Password reuse | Blocked | Blocked | Blocked |
| Real-time phishing relay | Open | Open | Blocked |
| SIM swap or port-out | Open | Blocked | Blocked |
| No signal or roaming | Fails | Works | Works |
Keeping your number out of security settings also keeps it out of breach dumps and data brokers, covered in why protect your phone number.
How do you migrate off SMS without locking yourself out?
Most lockouts happen when people delete the phone number first and enroll the new factor second. The safe order is the reverse. Add the new factor, confirm it produces a working code, save recovery codes offline, then remove SMS from the account. The table below sets the sequence.
The order that avoids a lockout
| Step | Do this before the next one |
|---|---|
| 1 | Add the authenticator app and confirm it works |
| 2 | Download and store the recovery codes offline |
| 3 | Add a recovery email you control |
| 4 | Only now remove SMS as a factor, where the service allows it |
| 5 | Re-check the active sessions list |
| Step | Do this before the next one |
|---|---|
| 1. Add TOTP app | Scan the QR code and enter one generated code to confirm enrollment |
| 2. Save recovery codes | Download or write down all 8 to 10 codes, store them offline |
| 3. Add a second factor | Enroll a hardware key or a second TOTP device |
| 4. Remove SMS | Delete the phone number from security settings, then sign in again to verify |
Some accounts were opened with a rented number because the signup form required one. The screenshot shows what that migration looks like after sign-up: the account exists, the TOTP app is enrolled, and the number is dropped from security settings once the new factor works.
Step 1 to 4: add the new factor before removing the old one
Between step 1 and step 4, keep both factors live. Sign out fully after step 3 and sign back in using the new factor only. If that fails, SMS is still attached and you can recover. Only delete the number after a clean sign-in.
Where to store recovery codes
Print them and keep them in a drawer or a safe, or store them in a password manager that is not protected by the same account you are securing. Two copies in two physical locations beats one perfect copy. Do not email them to yourself, that files them inside the account they are supposed to rescue.
Enrolling a second key before you trust the first
One hardware key is a single point of failure. Enroll two during the same session, keep one on your keychain and one at home. A second TOTP device works as a cheaper backup, install the app on a tablet or old phone and scan the same QR code before you close the enrollment screen.
If a service still demands SMS at signup, MarioSMS rents a real number for one verification at a time from $0.04, with the code arriving in the dashboard usually within a minute. If no SMS lands inside the activation window, the charge returns to your balance automatically.
What do specific services and countries require at sign-up?
Requirements fall into three patterns. Some accounts never ask for a number. Some ask once at sign-up and then let you delete it. Some tie the number to account recovery, so removing it weakens your ability to get back in. Knowing which pattern you are dealing with decides whether you need a number at all.
Accounts that never ask for a number
Password managers, most developer tools, self-hosted services and a large share of email clients accept a TOTP app or a security key at enrollment with no phone field. Sign up, open security settings, scan the QR code, save the recovery codes. You never enter digits, and there is nothing to remove later.
Accounts that ask once, then let you remove it
Large consumer platforms often gate sign-up behind an SMS verification step, then allow you to unlink the number after a stronger factor is active. The order matters. Add the authenticator app or key first, confirm it works on a fresh login, then remove the number. Remove it first and some accounts drop straight back to email-only recovery.
Why the requirement varies by country
Registration rules, SIM identity checks and local fraud rates change how strict a service is per market. The same app can accept an email sign-up in one country and demand a number in another, and it may reject number ranges from countries where abuse volumes are high. Services also filter by number type, with many rejecting VoIP numbers while accepting mobile ranges.
| Pattern | Number needed | Can you remove it later |
|---|---|---|
| App or key only | No | Nothing to remove |
| One-time check at sign-up | Yes, once | Usually, after a second factor is live |
| Number tied to recovery | Yes | Only if you add backup codes first |
Using a rented number for the one-time step
- Pick the service and country in the app or at app.mariosms.com.
- Rent a number from $0.04 and watch the activation timer.
- Enter the code when it appears, usually within a minute.
- Enroll your authenticator app, save recovery codes, then unlink the number.
What do you do when the code or the key fails?
TOTP codes rejected because of clock drift
A TOTP code is derived from a shared secret plus the current time in 30 second steps. If your phone’s clock is off by more than about a minute, every code reads as wrong even though the secret is fine.
- Open the date and time settings and switch to automatic network time.
- In Google Authenticator, use the time correction option for codes.
- Generate a fresh code and try again within its 30 second window.
Desktop authenticators drift too, especially on machines that sleep for days.
Lost phone, new phone, same accounts
Recovery codes are the answer here, which is why you save them before you need them. Sign in with a recovery code, remove the old authenticator entry, enroll the new device, then generate a new set of codes. Authenticator apps with encrypted cloud sync (Google Authenticator, Authy, 1Password, Bitwarden) restore the secrets directly, but the restore needs its own password or account access, so store that separately from the phone.
With security keys, the second key you registered is what saves you. One key in a drawer at home costs less than an account recovery ticket that takes days.
A one-time SMS that never arrives
Carriers drop messages, senders throttle, and some routes block short codes. With a rented number, the activation has a timer. If no SMS lands before it expires, the activation cancels and the price returns to your balance automatically, so you can try a different country or service entry at $0.04 and up. Check the app or app.mariosms.com rather than refreshing the signup page.
The account keeps asking for a number again
Some services re-prompt after a password reset, a new device login, or a flagged session. Fixes in order:
- Confirm your authenticator app is listed as the default second factor.
- Remove any stale SMS verification entry left in security settings.
- Add a second factor (key or passkey) so the number stops being the only fallback.
Common questions about two-factor authentication without a phone number
Is an authenticator app safer than SMS?
Yes. TOTP codes are generated on your device from a shared secret and never travel over a carrier network, so a SIM swap or a rerouted message gains nothing.
Can I use TOTP without a smartphone?
Yes. Desktop clients, browser extensions and password managers all generate the same 6-digit codes. Some hardware keys store TOTP secrets too.
Do I need two hardware keys?
Two is the practical minimum. One stays on your keychain, one stays in a drawer at home. If you only own one and lose it, recovery codes are the sole way back in.
Are passkeys the same as two-factor authentication?
No. A passkey usually replaces the password entirely and folds the second factor into the face scan, fingerprint or PIN that opens your device. Many services still let you keep a separate second factor alongside it.
What happens if I lose my recovery codes?
Regenerate them immediately from security settings while you still have a working factor. If you have no working factor and no codes, you are in account recovery, which can take days and often demands ID.
Can I remove my phone number after enabling an authenticator app?
Usually yes, but only after the app is confirmed as the default and a second backup factor exists. Some services keep the number for account recovery even when it is no longer a login factor.
Is email a better second factor than SMS?
Only slightly, and only if that mailbox has its own strong second factor. Email codes inherit the security of the inbox, so a compromised mailbox breaks both factors at once.
Is it acceptable to use a rented number for a one-time verification?
For privacy hygiene, a legitimate second account or QA and OTP testing, yes. MarioSMS rents a real mobile number for one verification, prices start at $0.04, the code shows in the app or dashboard usually within a minute, and if no SMS arrives inside the activation window the charge returns to your balance. Never use it to dodge a ban or impersonate someone (acceptable use).