digital
SMS or Authenticator App: Which to Use
By Jason Su ·
Short answer first: an authenticator app is the better default. Its codes never travel through your phone number, and a phone number can be taken away from you without your phone ever leaving your pocket.
But the honest ranking puts both of them in second place, and the reason is worth five minutes of your time. Neither one stops a fake login page.
What the two choices actually are
An authenticator app generates a new six-digit code on your phone every thirty seconds. The code is calculated on the device itself, from a secret that was shared once when you set it up.
SMS codes are texted to your phone number by the service. The code is generated somewhere else and delivered over the mobile network.
Both count as “something you have.” The difference is what you have. With an app you have a secret on your device. With SMS you have a phone number — and a phone number is not really yours alone.
If you want the wider picture of what a second factor is and how the backup codes work, that is in how to back up two-factor codes.
The difference that matters: your number can move
A phone number can be moved from your SIM card to someone else’s by pretending to be you. It goes by several names — a SIM change, a number port, a SIM swap — and from your side it is nearly invisible until something breaks.
The point is what happens next. Every SMS code addressed to your number now arrives on the attacker’s phone. You still have your phone. Your phone still works. The codes simply stopped coming to you.
This is not a fringe worry. The federal standards for digital identity call out exactly this pattern. When a service is about to send a verification code over the phone network, it should weigh risk signals first — device changes, SIM changes, number porting, or anything else that looks unusual about the account. (NIST SP 800-63B)
The same document goes further. Of all the ways to prove who you are, the telephone network is the one method it labels restricted — the only one carrying that label. It is still allowed, but the rules now say a service offering it must also offer you a non-restricted alternative and tell you what the risks are.
An authenticator app does not have this weakness. There is no number to steal, no carrier to persuade, no transfer to make. The secret sits on your device.
Neither one stops a fake login page
This is the part that surprises people, and it comes straight from the same standard. The guidance is blunt about it:
Out-of-band authentication is not phishing-resistant.
And it explains why. Any method where you type a code by hand cannot be counted as phishing-resistant, because typing the code does not tie it to the site you are actually on.
Put plainly: a convincing fake login page collects your password, then asks for your six-digit code, then passes both to the real site within seconds. The code was correct. It just was not used by you.
That applies to SMS codes. It also applies to authenticator app codes. Your app is better protected against a stolen phone number, but it does not protect you against a good fake page.
What does? A method where your device proves something to the site directly, so a lookalike domain gets nothing usable. That is what security keys and passkeys do. CISA, the federal cybersecurity agency, calls this phishing-resistant MFA and says FIDO/WebAuthn is the only widely available form of it. (CISA — More than a Password)
So what should you actually turn on
Here is the ranking, honestly:
| Rank | Method | What it protects against |
|---|---|---|
| 1 | Security key or passkey | Both phishing and a stolen phone number |
| 2 | Authenticator app | A stolen phone number — but not a fake login page |
| 3 | SMS codes | Somebody who only has your password — nothing more |
| 4 | Nothing | Nothing at all |
Two things worth saying about that table.
First, third place still beats fourth. CISA’s own line is that any MFA is better than no MFA. If a service you depend on offers only text codes, turn them on today and move on. A text code stops the most common kind of account takeover, which is somebody using a password they bought.
Second, nothing here says to remove SMS. Keep it as a backup method if that is what the service allows. Just do not let it be your only method on an account that matters.
What about passkeys?
A passkey is the newer version of the same idea as a security key. Instead of a device you plug in, the key is held by your phone, your computer, or your password manager, and you unlock it with your face, your fingerprint, or a PIN.
For everyday purposes it behaves like the strongest option on that list. It is tied to the real site, so a lookalike domain gets nothing.
There is one nuance worth knowing if you like details. Passkeys are syncable — the key can be copied between your devices, which is exactly what makes them convenient. The highest assurance level in the federal standards requires a key that cannot be exported, so syncable keys are not allowed at that level. (NIST SP 800-63B)
For a household account, trading a little of that top-tier strictness for convenience across devices is usually the right call. It just means “strongest thing I can turn on today” and “top of the government’s own ladder” are not quite the same thing.
The part nobody plans for: getting back in
All three methods share one weakness, and it is not the attacker — it is the device.
If the phone is lost, replaced, or simply out of reach, every method above depends on something physical. That is why backup codes exist, and why printing them is the part that actually works.
The FTC’s consumer guidance on phones rests on the same idea, and it reads like a checklist: lock the phone with a PIN or your face, keep it updated, back up what is on it, and turn on the feature that finds it if it goes missing. (FTC — How To Protect Your Phone From Hackers)
SMS adds one more failure mode that families run into later: the phone number itself has to keep existing. Numbers get cancelled, plans get closed, and a number that was recycled can be reassigned to a stranger. An account whose only recovery path is a text message becomes unreachable the moment the plan ends. If you are organizing things for a family member, that is worth checking while the account is still open — see how to leave digital passwords to family.
The third place on that ranking table hides a fourth question: how does someone else get in? An authenticator app on a phone that nobody can unlock is a wall. A shared plan with a recovery path written down is not.
What to do this week
- Turn on an authenticator app for your email first. Email resets everything else, so it gets the strongest method it supports.
- Then the accounts that can move money, and the password manager itself.
- Keep SMS as a second method, not the only one. Some services still use it for setup or recovery, and that is fine.
- Generate and print the backup codes at the same time you turn the app on. Two minutes, and it is the step people skip.
- If you use a security key, register a second one and keep it somewhere else. A single key with no spare is a single point of failure.
- Ask your carrier what protection they offer for number transfers on your account. Ask it as a question — the answer varies by carrier and by country.
- Write down which method each account uses on your Digital Account Inventory, so the next person is not guessing.
What not to do
- Do not approve a login prompt you did not ask for. CISA points to “push bombardment” — repeated approval prompts sent until someone taps yes — as a real attack. If your phone lights up with a request you did not start, deny it and change that password.
- Do not make SMS your only second factor on email or banking. It is the one method with an extra way to fail.
- Do not assume the app makes you unphishable. It stops a stolen number. It does not stop a fake page.
- Do not store the codes in the same app that generates them. If the phone goes, both halves go with it.
- Do not cancel a phone number that a family account still depends on for logins, until you have moved that account to something else.
- Do not skip the backup codes because the app “just works.” It works right up until the phone does not.
Frequently asked
Is a text code still worth turning on?
Yes. It is the weakest form of MFA, and it is still far better than a password alone. Turn it on if it is what the service offers — then replace it when you can.
Is an authenticator app safe if someone steals my phone?
Most authenticator apps sit behind your screen lock, so a locked phone is not an open book. But a phone you no longer control is a real problem, which is why the backup codes matter more than the app.
Do I need a security key?
Not for everything. They are the strongest option and the only phishing-resistant one, so use one where a service supports it and where the account matters most. Register two.
Can I use both an app and SMS?
Yes, and on important accounts you probably should. Register the app as your main method and keep text as the fallback, so one lost thing does not lock you out.
What if the phone number belongs to a parent I help?
Check what the number is holding up before anything changes. Bank and email recovery, two-factor codes, and sometimes the password manager itself can all point at one number. Our guide to helping a parent organize their paperwork covers the conversation.
Next step
Open your email account’s security settings now and look for two words: two-factor or two-step. If an authenticator app is offered, set it up. If only text is offered, turn that on. Then print the backup codes and note where that account sits on your Master Checklist.
This is general information, not legal or financial advice. Account policies and the methods each service supports differ and change over time — please confirm the details in the service’s own help pages.
General information only. Rules vary by state and change over time. Confirm details with the official source before acting. Read the full disclaimer.