Online Security

Account Security Audit: A Practical Password Health Checklist

Laptop with a lock icon on screen next to a handwritten security checklist on a desk.

Key Takeaways

  • Reused passwords are one of the most common reasons multiple accounts get compromised at once.
  • A password manager makes it practical to use long, unique credentials for every account.
  • Two-factor authentication adds a critical second layer of protection beyond your password alone.
  • Outdated recovery options — old phone numbers or emails — can lock you out of your own accounts.
  • Periodic audits, not just one-time fixes, are what keep your credentials genuinely secure over time.
30–60 min

Summary

18 items · 30–60 minutes

Why a Password Audit Matters

Most people accumulate dozens — sometimes hundreds — of online accounts over the years. Passwords get reused, forgotten, or left unchanged after breaches. The result is a patchwork of credentials with unknown vulnerabilities quietly waiting to be exploited.

A password health audit is a structured way to close those gaps. Rather than waiting for a breach notification to prompt action, you proactively review every account, update weak credentials, and put safeguards in place. This checklist walks you through that process in a logical order, from gathering your tools to verifying your recovery options.

For a broader view of protecting your accounts and devices together, the Device Protection hub covers practical steps that complement what you'll do here.

Your Email Password Is Your Master Key

If an attacker gains access to your primary email account, they can trigger password resets on nearly every other account you own. Make your email password the strongest, most unique credential you have — and ensure two-factor authentication is enabled on it before anything else.

Tools You'll Need Before You Start

Having the right tools in place before you begin makes the audit faster and more thorough. The items below range from essential to optional — but each one meaningfully improves what you can accomplish.

Required

Password Manager

Stores all your credentials securely, generates strong unique passwords, and flags reused or weak entries.

Required

Breach-Notification Service

Checks whether your email addresses appear in known data breaches so you know which accounts need urgent attention.

Required

Authenticator App

Generates time-based one-time codes for two-factor authentication, which is more secure than SMS-based verification.

Optional

Secure Notes (within your password manager)

Stores backup codes and recovery information generated during 2FA setup in an encrypted, accessible location.

Optional

Spreadsheet or Notepad (temporary)

Helps you track which accounts you've reviewed during the audit session — delete it securely when finished.

Work Through the Checklist

Use the groups below in order. Start with preparation to get organized, then move through your accounts systematically. Don't try to do everything in one sitting if your account list is long — completing one group per session is a perfectly reasonable approach.

Preparation

Install or open a reputable password manager so you have a secure place to store new credentials as you create them. Must
Export or review your existing saved passwords from your browser or password manager to build a full picture of what you have. Must
Check whether any of your email addresses appear in known data breaches using a breach-notification service such as Have I Been Pwned. Must
Create a prioritized list of your most sensitive accounts — email, banking, healthcare, and primary social accounts — to tackle first. Must

Password Strength Review

Identify and replace any password shorter than 12 characters with a longer alternative — ideally 16 characters or more. Must
Replace any password that contains personal information such as your name, birth year, or pet's name. Must
Flag passwords that consist of simple dictionary words or common patterns (e.g., 'password123', 'qwerty') and update them immediately. Must
Use your password manager's built-in password generator to create new credentials — avoid constructing them manually. Should

Reuse and Duplication

Identify every account that shares a password with another account and assign each a unique credential. Must
Pay particular attention to your primary email password — it must be unique, since email is typically used to reset all other accounts. Must
Remove any saved passwords from your web browser and migrate them into your password manager for better security and portability. Should

Two-Factor Authentication (2FA)

Enable two-factor authentication on every account that supports it, starting with email, banking, and account recovery services. Must
Prefer an authenticator app (which generates time-based codes) over SMS-based 2FA where the option is available. Should
Save backup codes provided during 2FA setup in a secure location such as your password manager's secure notes. Must

Account Recovery Options

Verify that the recovery email address and phone number on each account are current and accessible. Must
Update any recovery options that point to old email addresses or phone numbers you no longer control. Must
Review and remove any third-party apps or services that have unnecessary access to your primary accounts (e.g., via OAuth connections). Should
Set a calendar reminder to repeat this full audit in six to twelve months. Nice to have

Once you've completed the checklist, pair these habits with the password hygiene practices that keep credentials secure between audits. If you store files or sensitive data in cloud services, securing those cloud accounts is a natural next step.

Don't Store Passwords in Plain Text

Avoid writing passwords in unencrypted documents, notes apps, or spreadsheets — even temporarily. If your device is compromised, those files are immediately accessible. Use your password manager's secure notes feature instead, which encrypts data at rest.

SMS-Based 2FA Has Known Weaknesses

While SMS verification is better than no 2FA at all, it is vulnerable to SIM-swapping attacks, where an attacker convinces a carrier to transfer your number to their device. Wherever possible, use an authenticator app instead of text-message codes.

Making Audit Results Stick

Completing the checklist once is a strong start, but password security is an ongoing habit, not a one-time event. Schedule a reminder to repeat this audit every six to twelve months, or immediately after any breach notification involving one of your accounts.

Consider pairing your next password review with a broader device security check — the two reinforce each other. If your home network is a concern as well, the home network security audit checklist covers router settings, connected devices, and more.

The goal isn't perfection — it's a consistent baseline that makes your accounts meaningfully harder to compromise.

Online Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Online Security Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.