Key Takeaways
- Reused passwords are one of the most common reasons multiple accounts get compromised at once.
- A password manager makes it practical to use long, unique credentials for every account.
- Two-factor authentication adds a critical second layer of protection beyond your password alone.
- Outdated recovery options — old phone numbers or emails — can lock you out of your own accounts.
- Periodic audits, not just one-time fixes, are what keep your credentials genuinely secure over time.
Summary
18 items · 30–60 minutes
Why a Password Audit Matters
Most people accumulate dozens — sometimes hundreds — of online accounts over the years. Passwords get reused, forgotten, or left unchanged after breaches. The result is a patchwork of credentials with unknown vulnerabilities quietly waiting to be exploited.
A password health audit is a structured way to close those gaps. Rather than waiting for a breach notification to prompt action, you proactively review every account, update weak credentials, and put safeguards in place. This checklist walks you through that process in a logical order, from gathering your tools to verifying your recovery options.
For a broader view of protecting your accounts and devices together, the Device Protection hub covers practical steps that complement what you'll do here.
Your Email Password Is Your Master Key
If an attacker gains access to your primary email account, they can trigger password resets on nearly every other account you own. Make your email password the strongest, most unique credential you have — and ensure two-factor authentication is enabled on it before anything else.
Tools You'll Need Before You Start
Having the right tools in place before you begin makes the audit faster and more thorough. The items below range from essential to optional — but each one meaningfully improves what you can accomplish.
Password Manager
Stores all your credentials securely, generates strong unique passwords, and flags reused or weak entries.
Breach-Notification Service
Checks whether your email addresses appear in known data breaches so you know which accounts need urgent attention.
Authenticator App
Generates time-based one-time codes for two-factor authentication, which is more secure than SMS-based verification.
Secure Notes (within your password manager)
Stores backup codes and recovery information generated during 2FA setup in an encrypted, accessible location.
Spreadsheet or Notepad (temporary)
Helps you track which accounts you've reviewed during the audit session — delete it securely when finished.
Work Through the Checklist
Use the groups below in order. Start with preparation to get organized, then move through your accounts systematically. Don't try to do everything in one sitting if your account list is long — completing one group per session is a perfectly reasonable approach.
Preparation
Password Strength Review
Reuse and Duplication
Two-Factor Authentication (2FA)
Account Recovery Options
Once you've completed the checklist, pair these habits with the password hygiene practices that keep credentials secure between audits. If you store files or sensitive data in cloud services, securing those cloud accounts is a natural next step.
Don't Store Passwords in Plain Text
Avoid writing passwords in unencrypted documents, notes apps, or spreadsheets — even temporarily. If your device is compromised, those files are immediately accessible. Use your password manager's secure notes feature instead, which encrypts data at rest.
SMS-Based 2FA Has Known Weaknesses
While SMS verification is better than no 2FA at all, it is vulnerable to SIM-swapping attacks, where an attacker convinces a carrier to transfer your number to their device. Wherever possible, use an authenticator app instead of text-message codes.
Making Audit Results Stick
Completing the checklist once is a strong start, but password security is an ongoing habit, not a one-time event. Schedule a reminder to repeat this audit every six to twelve months, or immediately after any breach notification involving one of your accounts.
Consider pairing your next password review with a broader device security check — the two reinforce each other. If your home network is a concern as well, the home network security audit checklist covers router settings, connected devices, and more.
The goal isn't perfection — it's a consistent baseline that makes your accounts meaningfully harder to compromise.
