SECURE YOUR PROTON PASS ACCOUNT

Protect the vault that protects your identity.

Proton Pass can store passwords, passkeys, payment information and other sensitive data. It can also help protect your real email address with hide-my-email aliases. Secure the vault before trusting it with the keys to your digital life.

Protect the Proton account first.

Proton Pass uses end-to-end encryption for sensitive vault data, meaning the security of your account credentials, authentication methods and recovery arrangements matters enormously.

What is Proton Pass?
Proton Pass is a password manager that can store logins, passwords, passkeys, notes and other sensitive information. It also provides hide-my-email aliases that can keep your real email address private.
What is a hide-my-email alias?
It is a randomly generated email address that can forward messages to your real mailbox without exposing your real address to the website or service you signed up for.
What is two-factor authentication?
Two-factor authentication requires another verification method in addition to your password, such as an authenticator app or security key.
What is a passkey?
A passkey is a modern authentication credential that can use your device's security features instead of requiring you to type a traditional password.
Does an email alias replace 2FA?
No. An alias protects your email identity. You should still use a strong unique password and two-factor authentication when the service supports it.
What if I lose my phone?
Use another trusted device to secure your Proton account, review active sessions and replace or reconfigure authentication methods that depended on the lost phone.
PROTON PASS SECURITY

Secure the password manager before trusting it with everything else.

Work through these checks one at a time. You do not need to understand every technical term first.

Protect your Proton account password

Your Proton account protects Proton Pass and potentially other Proton services. Start with a strong, unique password.

Click to see protection steps

Step-by-step

  1. Use a long and unique password for your Proton account.
  2. Never reuse your Proton password on another website.
  3. Do not share your password with anyone.
  4. Avoid saving the password in ordinary notes, messages or email.
  5. Consider using Proton Pass itself to generate and store strong passwords for other accounts.

VERIFY: Confirm that your Proton password is unique and that nobody else knows it.

Turn on two-factor authentication

Two-factor authentication adds another verification step so that a stolen password alone is not enough to sign in.

Click to see protection steps

Step-by-step

  1. Sign in to your Proton Account.
  2. Open Settings → Account and password.
  3. Find Two-factor authentication.
  4. Choose an available method such as an authenticator app or security key.
  5. Complete the verification process.
  6. Store your recovery information somewhere safe.

VERIFY: Sign out and test your second factor so you know it actually works.

Protect your 2FA recovery method

A second factor protects your account, but losing it without a recovery method can create another problem.

Click to see protection steps

Step-by-step

  1. Review the recovery methods available on your Proton account.
  2. Make sure your recovery email or phone number is still accessible.
  3. If Proton provides a recovery phrase or code for your configured method, store it securely.
  4. Never send your recovery code to another person.
  5. Do not keep your only recovery method on the same phone you use for authentication.

VERIFY: Ask yourself: if I lost my phone today, could I still recover my Proton account?

Use a security key or passkey

Passkeys and hardware security keys can provide strong phishing-resistant authentication on supported devices.

Click to see protection steps

Step-by-step

  1. Use a compatible passkey or security key.
  2. Open your Proton account security settings.
  3. Add the passkey or security key as an authentication method.
  4. Give registered keys recognizable names where available.
  5. Keep a backup authentication method if practical.

VERIFY: Test the new authentication method before depending on it as your only way to sign in.

Use a unique password for every account

The purpose of a password manager is not simply to store passwords. It should help you stop reusing the same password everywhere.

Click to see protection steps

Step-by-step

  1. Open a saved login in Proton Pass.
  2. Replace weak or reused passwords with strong unique passwords.
  3. Use the built-in password generator where appropriate.
  4. Never use your Proton account password for another service.
  5. Prioritize email, banking, cryptocurrency and social-media accounts.

VERIFY: Confirm that a breach at one website would not give an attacker the password for another important account.

Turn on password health checks

Proton Pass can identify weak and reused passwords so you can work through the accounts that need attention.

Click to see protection steps

Step-by-step

  1. Open your Proton Pass vault.
  2. Review available password health or security alerts.
  3. Identify passwords that are weak or reused.
  4. Change the highest-risk passwords first.
  5. Generate unique replacements instead of creating another similar password.

VERIFY: Your important accounts should not depend on weak or repeated passwords.

Use hide-my-email aliases

A Proton Pass hide-my-email alias lets you sign up for a service without exposing your real email address.

Click to see protection steps

Step-by-step

  1. When creating a new online account, consider using a hide-my-email alias.
  2. Generate the alias through Proton Pass.
  3. Use the alias instead of your primary email address.
  4. Save the login and alias together in Proton Pass.
  5. If the service starts sending unwanted messages or the alias becomes compromised, disable or delete it when appropriate.

VERIFY: Confirm that your real email address is not unnecessarily exposed to every website you use.

Do not confuse aliases with passwords

An email alias protects your email identity. It does not replace a strong password or two-factor authentication.

Click to see protection steps

Step-by-step

  1. Use a unique alias where it provides a privacy benefit.
  2. Generate a unique password for the account.
  3. Enable two-factor authentication on the service whenever available.
  4. Store the login, alias and recovery information securely.

VERIFY: Remember: an alias hides your real email address, but it does not by itself secure the account.

Secure the Proton Pass browser extension

The browser extension can autofill passwords and other sensitive information, so browser security is part of password-manager security.

Click to see protection steps

Step-by-step

  1. Install Proton Pass only from an official Proton sourceor supported browser store.
  2. Keep your browser updated.
  3. Keep the Proton Pass extension updated.
  4. Be cautious when allowing autofill on unfamiliar websites.
  5. Lock Proton Pass when using a shared or public computer.

VERIFY: Confirm that the Proton Pass extension is installed only on devices and browsers you trust.

Protect autofill

Autofill is convenient, but entering credentials into the wrong website can expose them to a phishing attack.

Click to see protection steps

Step-by-step

  1. Check the website address before accepting autofill.
  2. Be especially careful with banking, cryptocurrency and email logins.
  3. Do not blindly accept autofill on a website reached through an unexpected message.
  4. If a login page looks unusual, stop and verify the website first.

VERIFY: Verify the actual domain before allowing Proton Pass to fill sensitive credentials.

Protect your vault on shared devices

A password manager can expose many accounts at once if its vault is left unlocked on a device other people can access.

Click to see protection steps

Step-by-step

  1. Avoid using your full password vault on public computers.
  2. Lock Proton Pass when you step away.
  3. Use device-level PIN, password or biometric protection.
  4. Sign out of shared devices when finished.
  5. Never save your master credentials in a browser or device you do not control.

VERIFY: An unattended computer should not provide unrestricted access to your password vault.

Protect saved credit-card information

Proton Pass can store sensitive information beyond passwords. Treat saved payment information as highly sensitive.

Click to see protection steps

Step-by-step

  1. Store payment information only when there is a genuine reason to do so.
  2. Keep the Proton account itself strongly protected.
  3. Do not share vault contents casually.
  4. Review saved payment information periodically.
  5. Remove information you no longer need to keep.

VERIFY: Confirm that sensitive payment information is protected by the same strong security controls as your passwords.

Review shared vault access

If you share credentials with family, colleagues or another trusted person, make sure the sharing arrangement is intentional.

Click to see protection steps

Step-by-step

  1. Review who can access shared vaults or items.
  2. Remove people who no longer need access.
  3. Avoid sharing credentials through ordinary chat messages.
  4. Use Proton's supported secure-sharing features when available.
  5. Review shared access after a person leaves a team or organization.

VERIFY: Every person who can access a shared credential should still have a legitimate reason to have it.

Review your Proton account security

Proton Pass depends on the security of the wider Proton account. Review the account itself rather than protecting only the vault.

Click to see protection steps

Step-by-step

  1. Review your Proton account security settings.
  2. Check your two-factor authentication configuration.
  3. Review recovery information.
  4. Review active sessions or security activity where available.
  5. Remove or secure anything you do not recognize.

VERIFY: Do not ignore the Proton account simply because your passwords are stored inside Proton Pass.

If your Proton account may be compromised

Because Proton Pass may contain credentials for many other services, a suspected compromise should trigger a wider security response.

Click to see protection steps

Step-by-step

  1. Move to a trusted device if the original device may be compromised.
  2. Change your Proton account password.
  3. Secure or reconfigure your two-factor authentication.
  4. Review account sessions and security activity.
  5. Review your Proton Pass vault for suspicious changes.
  6. Change passwords for your highest-value accounts, starting with email, banking and financial accounts.
  7. Disable compromised email aliases where appropriate.

VERIFY: Do not stop after changing the Proton password. Review the accounts whose credentials were stored in Proton Pass.

If you lose your phone

A lost phone can affect your authenticator, Proton Pass access and email aliases. Treat the loss as a security event.

Click to see protection steps

Step-by-step

  1. Use another trusted device to secure your Proton account.
  2. Review your active sessions.
  3. Remove access from the lost device where appropriate.
  4. Replace or reconfigure your lost authentication method.
  5. Confirm that your recovery methods still work.
  6. If the phone contained other sensitive apps, secure those accounts too.

VERIFY: Confirm that losing the phone has not left an attacker with an active authenticated session.

Review your email aliases regularly

Aliases can reduce exposure of your real email address, but old aliases can accumulate over time.

Click to see protection steps

Step-by-step

  1. Review your existing aliases periodically.
  2. Identify aliases connected to services you no longer use.
  3. Disable unnecessary aliases.
  4. Delete aliases only when you are certain you no longer need them.
  5. Keep important aliases documented inside your secure vault.

VERIFY: Your alias list should contain only addresses you intentionally maintain.

Do not trust fake Proton support

Attackers may impersonate Proton support and ask for passwords, recovery codes or authentication codes.

Click to see protection steps

Step-by-step

  1. Never give your password to someone claiming to be support.
  2. Never send a 2FA code or recovery code to another person.
  3. Be suspicious of unexpected requests to install remote-access software.
  4. Navigate to Proton's official website yourself rather than using a suspicious support link.
  5. If someone pressures you to act immediately, stop and verify first.

VERIFY: Remember: an urgent request for your password or authentication code is a reason to stop, not a reason to comply.

Something does not look right?

If you find an unfamiliar login, changed recovery information, unexpected security alerts or another sign that someone may have accessed your account, stop the normal security check and move to the recovery process.

I think my account is compromised →
Still need help?

If you have worked through the relevant settings and something still looks wrong, do not give your security secrets to someone promising to fix the account. Use the service's official support and recovery resources for service-specific account problems.

For broader cybersecurity problems, you can also use the professional assistance pathway on this platform.

Need Professional Help? →
Proton Pass security is not a one-time task.

Review important account settings periodically, especially after a password change, device change, suspicious message or unexpected login alert.

VERIFY BEFORE YOU TRUST.

← Back to Secure Your Accounts