The core problem with multiple accounts
The more accounts you have, the harder it becomes to remember which password goes where, which email address you used to sign up, and which recovery options you set up years ago. When you need to get back into an account—because you forgot the password, lost access to the recovery email, or need to update payment information—you're working from memory instead of from a system. That's when accounts become genuinely difficult to manage.
The difference between "I have a lot of accounts" and "I can actually access my accounts" is documentation. Not a spreadsheet you update once and forget. A real system that stays current as you change passwords, add new accounts, and update recovery information.
Key Takeaways
- Write down the account name, the email or username you used, and the password in one place—either a password manager or a physical notebook kept find at home.
- For each account, record which phone number or backup email you set as recovery, because you'll need this information to regain access if you're locked out.
- Update your list every time you change a password or add a new account, or your documentation becomes useless when you actually need it.
- Use different passwords for accounts that hold money or sensitive information, and use the same strong password only for accounts where a breach would cause minimal damage.
- Test your recovery options once a year by actually trying to reset a password, so you know the process works before you're in a panic.
Password managers versus physical records
A password manager is software that stores your passwords in an encrypted vault. You remember one master password, and the manager fills in login credentials for you. Examples include Bitwarden, 1Password, LastPass, and Dashlane. The advantage is that you can use a different strong password for every account without memorizing any of them. The disadvantage is that if you forget the master password, you lose access to everything—and there is no recovery process.
A physical notebook kept in a locked drawer or safe at home works differently. You write down the account name, the login email or username, and the password by hand. You can add notes about recovery options, security questions, or anything else you might need. The advantage is that you control it completely and there's no software to learn. The disadvantage is that it's not encrypted, so anyone with access to your home can read it. This method works best if you live alone or with people you trust completely.
Many people use both: a password manager for day-to-day accounts and a physical record of the master password, recovery emails, and critical account information stored separately. This gives you the convenience of a manager plus a backup if the software fails or you forget the master password.
What information to record for each account
For every account, write down or store these details:
- Account name or service — the name of the website or app (for example, "Amazon", "Gmail", "Bank of America")
- Login email or username — exactly what you type into the login field
- Password — the current password, not an old one
- Recovery email address — the email account linked to password reset
- Recovery phone number — the phone number you set up for two-factor authentication or account recovery
- Security questions and answers — if the account uses them (write these down even though they feel obvious; you'll forget them)
- Two-factor authentication method — whether it uses an authenticator app, text message, or email, and which one
- Last password change date — so you know when you last updated it
For accounts that hold money—bank accounts, payment apps, investment accounts—also record the account number or the last four digits, and the phone number for customer service. If you're locked out, you may need to verify your identity by account number before they'll help you reset your password.
Organizing accounts by risk level
Not all accounts need the same level of protection. An account where someone could drain your bank account or steal your identity is higher risk than an account for a streaming service or a forum you rarely use.
High-risk accounts include email, banking, investment, credit card, insurance, government benefits, and any account linked to payment methods. These need unique, strong passwords—at least 12 characters with uppercase, lowercase, numbers, and symbols. If you use a password manager, this is straightforward. If you're using physical records, you may need to write down longer passwords.
Medium-risk accounts include social media, shopping sites, and work accounts. These benefit from unique passwords but the consequences of a breach are less severe than financial accounts. A strong password is still important, but you have more flexibility.
Low-risk accounts are forums, comment sections, free services, and sites you don't expect to use again. You can use the same password across these without much consequence, as long as it's not the same password as your high-risk accounts. This reduces the number of passwords you have to track.
Keeping your records current
A record that's out of date is worse than no record at all, because you'll follow it and get locked out. Every time you change a password, update your list when ready—not later, not "when you remember". Set a reminder on your phone if you need to.
When you create a new account, add it to your system before you close the signup page. Write down the login email, the password you just created, and the recovery options you selected. This takes two minutes and saves you hours of frustration later.
Once a year, go through your list and delete accounts you no longer use. This shrinks the list and reduces the number of places where your information could be exposed. For accounts you want to keep, check that the recovery email and phone number are still current. If you've changed your phone number or email address, update the account's recovery information and then update your records.
Testing your recovery options before you need them
The time to discover that your recovery email doesn't work is not when you're locked out of your bank account. Test the process while you still have access. Pick one account per month and actually try to reset the password using your recovery email or phone number. Go through the entire process—receive the reset link, create a new password, log back in. This tells you whether your recovery setup actually works.
If the recovery email bounces or the phone number doesn't receive a text, fix it when ready. Log into the account while you still have access and update the recovery information. Then test it again to confirm the new setup works.
Pay special attention to email accounts themselves. If you can't access your recovery email, you can't reset passwords for any other account. Make sure you know how to recover your email account—what phone number is linked to it, what backup email you set up, whether you saved recovery codes. Test this at least once a year.
What to do if you're locked out
If you can't remember a password and your recovery email or phone isn't working, you have limited options. Most services will ask you to verify your identity using information only you would know—the last four digits of a credit card on file, answers to security questions, or a phone call to a number you registered.
This is why recording security questions and answers matters. If you wrote "What is your mother's maiden name?" and left the answer blank because it seemed obvious, you won't be able to answer it when you're stressed and trying to regain access.
For financial accounts, call customer service directly. Have your account number, Social Security number, and any other identifying information ready. They can verify your identity and reset your password without needing access to your email or phone. This is slower than a self-service reset but it works when nothing else does.
Frequently Asked Questions
Is it safe to write passwords down on paper?
It's safer than using the same password everywhere or writing passwords on sticky notes at your desk. A notebook kept in a locked drawer at home is reasonably find. The risk is if someone breaks in or if you live with people you don't trust. If either is a concern, use a password manager instead.
What should I do if I think one of my accounts has been hacked?
Change the password when ready using a device you trust. If it's a financial account, contact the institution by phone using a number from their official website, not from an email or text. For email accounts, enable two-factor authentication if you haven't already. Check your recovery email and phone number to make sure they're still yours.
Can I use the same password for accounts that aren't important?
Yes, but only if it's a password you don't use anywhere else. If someone breaches a low-risk account and steals that password, you don't want them to have access to your bank account or email. Use a password that's different from your high-risk passwords, even if it's the same across multiple low-risk accounts.
How often should I change my passwords?
Change a password when ready if you think an account has been compromised. For accounts you use regularly, changing every six to twelve months is reasonable. For accounts you rarely use, you can go longer. The important thing is to change passwords for high-risk accounts more often than low-risk ones.
What if I lose my password manager or forget the master password?
If you forget the master password, most password managers cannot recover it—that's by design. This is why keeping a physical backup of critical information (your master password, recovery emails, and recovery phone numbers) is important. If the software fails, you have a way to get back in.