A Telegram login code can arrive by SMS or through an existing Telegram session. Two-Step Verification adds a separate password to a new login. Telegram recommends a recovery email so a forgotten password does not trap you outside the account, but that email becomes part of the security chain. The goal is to make a stolen number or one-time code insufficient while keeping a tested route back into your account.
Before you start
Start while you have a trusted signed-in phone and control of the phone number. Choose a password that is unique and store it in a reputable password manager or another secure offline method. Make sure your recovery email has its own strong password and MFA. Do not use an address you are about to close or one shared with someone else.Do it step by step
- Open Settings, Privacy and Security, Two-Step Verification. Confirm the feature belongs to the Telegram account and number you intend to protect, especially if you use multiple accounts.
- Create a strong unique password. Do not reuse the phone unlock PIN, email password or a code someone dictated in a support chat.
- Add a recovery email if offered. Open that mailbox independently, complete verification and ensure you can still receive messages there. Review forwarding rules and recovery methods for that email account.
- Inspect Settings, Devices and terminate any old or unfamiliar sessions. Enabling a new-login password does not force an intruder already signed in to disappear.
- On a second device you own, test the sign-in flow without logging out of the primary phone. Confirm you understand the code and additional password prompts, then terminate the test session if it is no longer needed.
- Record a recovery plan: where the password is stored, which email receives recovery and what to do if the SIM is lost. Recheck these details when you change phone number or email provider.