discord3 min read

Curated summary

How Multi-Factor Authentication Helps Keep Your Discord Account Safe

Read original(opens in new tab)

Discord recommends strengthening accounts with multi-factor authentication (MFA), especially passkeys or authenticator apps. MFA adds protection beyond a password, which can be stolen, guessed, or leaked. The post explains Discord’s available login protections and emphasizes using unique passwords and securely storing recovery credentials.

Login Verification Emails

  • Accounts with verified email addresses receive a verification email when signing in from a new device or location.
  • Users must select “Verify Login” before Discord allows access.
  • This protection is ineffective if the email account is compromised, particularly when the same password is reused.
  • Discord strongly recommends using a different password for every online account.

How Multi-Factor Authentication Works

  • MFA adds one or more authentication factors beyond a password:
    • Something you know: A password or secret phrase.
    • Something you have: A phone, computer, security key, or other device.
    • Something you are: A fingerprint or facial biometric.
  • Using multiple factors makes account takeover more difficult.
  • Enabling any MFA option disables login verification emails.

Passkeys

  • Passkeys are presented as Discord’s fastest and most secure option because they are practically phishing-resistant.
  • They use a cryptographic exchange between Discord and a device, unlocked with a fingerprint, face scan, or device PIN.
  • Biometric data stays on the user’s device; Discord receives only the cryptographic credential needed to approve the login.
  • Discord supports up to 16 passkeys per account, including passkeys stored in password managers, browsers, mobile devices, or hardware security keys.
  • Users are encouraged to keep a backup passkey in a credential manager such as 1Password or Bitwarden.

Authenticator Apps

  • Authenticator apps generate time-based one-time passwords.
  • Discord and the app share a secret starter value, allowing them to generate matching codes.
  • A new code is created every 30 seconds, while Discord also accepts the previous code to provide roughly a one-minute login window.
  • Supported apps include Authy, Microsoft Authenticator, and Google Authenticator.
  • Backup codes should be saved in a password manager or another secure, reliable location.
  • Backup codes can be regenerated through My Account > View Backup Codes > Generate New Backup Codes.

Recommended Account Protection

  • Enable MFA on every Discord account.
  • Prefer one or more passkeys.
  • Use an authenticator app if passkeys are unavailable.
  • Use unique passwords across all services.
  • Store passkeys and backup codes securely, with a backup recovery method available.

Overall, Discord recommends passkeys as the strongest option, with authenticator apps as the next-best choice. Login verification emails provide basic protection, but MFA offers substantially stronger defense against stolen or reused passwords.

Continue with another curated summary.