Add Recovery Phrase Verification Tool (Without Resetting 2FA)
Description
Currently, ProtonMail users cannot verify whether their stored recovery phrase is correct without initiating an actual 2FA reset process. This creates uncertainty about whether users have properly saved their recovery credentials and could lead to account lockouts if the saved phrase is incorrect.
Feature Request:
Implement a dedicated "Verify Recovery Phrase" option in the security settings that allows users to:
- Input their recovery phrase to confirm it matches the one on file
- Receive immediate confirmation of whether the phrase is correct
- Do this without triggering any actual account recovery or 2FA reset
Benefits:
- Peace of mind: Users can periodically verify they have the correct recovery phrase stored
- Proactive security: Identifies issues with stored recovery phrases before an emergency occurs
- Reduced support burden: Fewer users locked out due to incorrect recovery phrases
- Better user experience: No need to go through a disruptive reset process just to test credentials
Implementation suggestion:
Add a "Verify Recovery Phrase" button in Account Settings → Security → Two-Factor Authentication section. When clicked, it opens a dialog where users can enter their phrase and receive a simple "✓ Verified - This recovery phrase is correct" or "✗ This recovery phrase does not match" message.
This feature would align with security best practices by encouraging users to regularly verify their backup access methods without compromising the integrity of their current security setup.
-
Privacy101 commented
Proton's done this for passwords already. Right idea, now it needs to expand.
-
Mick
commented
That sounds like an excellent idea since I've had to use it twice today myself for various reasons (mainly tinkering with stuff in the bowels of sleep deprivation).
-
Erik Blomgren commented
This would be a very good thing but it would also be a very easy way to brute force in to an account to a limit like once a week or once a month would be needed
-
Anonymous
commented
Only allow one recovery phrase to be verified per week, don't open another way to brute force access. Yes this is a good feature!
DO NOT ALLOW OFFLINE VERIFICATION this means you have leaked key data by allowing a brute force attack! @Privacy101 October 30, 2025
-
Martin commented
+1, very important and essential feature for this type of recovery scheme.
-
Tim
commented
This is a good idea. I worked for many years supporting database backup and recovery software, and we always encouraged our customers to do periodic "dry run recoveries" to help make sure everything they needed was in place if they had to perform an actual recovery.