Se connecter à un compte Google : passer la vérification, puis rester connecté
La première connexion à une boîte Gmail neuve ou récupérée se heurte généralement à un mur de vérification. Ce que Google dit vraiment pour vous aider à le franchir, comment configurer la validation en deux étapes et une clé d'accès par la suite, et les deux horloges de sept jours qui déterminent si la récupération fonctionne quand vous en avez besoin.
Avery BennettYou type the password on a new inbox and instead of mail you get a full-screen prompt asking Google to confirm it is really you. No explanation, no obvious way round it.
This happens to nearly every account the first time it is used from an unfamiliar device, browser or location. It is not a sign that anything is wrong. It is the standard check, and once you clear it properly sign-in gets fast again.
What triggers the check, and what Google says gets you through it
Google compares the combination of device, browser and network against what it has seen for that account before. A new fingerprint, an address in a different country, or a sign-in arriving right after the password was used somewhere else will each raise the bar.
Google publishes its own tips for completing a recovery or verification flow, and they are more specific than most advice on the subject:
- Answer as many of the questions as you can, even the ones you are unsure about. A partial answer is worth more than a skipped one.
- Use a familiar device and location. Google names this explicitly: a computer, phone or tablet you sign in from often, in a place you usually sign in from.
- Be exact with passwords, including the last one you remember using.
- Enter an email address that is genuinely connected to the account.
- Check your spam folder for the message.
The one thing that reliably makes it worse is repeating the attempt from different networks while you troubleshoot. That pattern is what the system is built to catch, and it can extend the block instead of clearing it. Pick one verification path, do it once, from one place.
Turning on 2-Step Verification
Once you are in, open your Google Account and go to Security, or Security and sign-in depending on which layout you get, and find the section headed How you sign in to Google. Turn on 2-Step Verification there.
Google offers more second steps than most guides mention: passkeys and hardware security keys, Google prompts, a code app such as Google Authenticator, codes by text or voice call, a QR code, and backup codes. Its own recommendation is one people rarely follow, so it is worth quoting the reasoning: Google suggests Google prompts as the second step, on the grounds that tapping a prompt is easier than typing a code.
If you prefer a code app, set it up before you need it rather than during a login attempt. Scan the code, confirm the first generated value matches, and save the backup codes it offers you. Codes rotate on a short timer, so have the app open and ready rather than hunting for it while the clock runs.
Adding a passkey, and the toggle that confuses people
A passkey lets you confirm who you are with a fingerprint, a face scan or a device PIN instead of typing a password. You create one from the passkeys page in your account's sign-in options, using the current device's built-in biometrics, a phone that is already signed in, or a physical security key.
The part that catches people out is what happens next. Creating a passkey opts you into a passkey-first, password-less sign-in, but it does not delete your password: Google says you still have the option to sign in with it. The behaviour is governed by a setting called Skip password when possible. Turn that off and your password goes back to being the default, with the passkey as an alternative. Most reports of a passkey "not working" are actually this toggle being in the state the person did not expect.
Requirements are specific. On a computer you need at least Windows 10, macOS Ventura or ChromeOS 109, and on a phone Android 9 or iOS 16, or alternatively a hardware key supporting FIDO2. Name each passkey after the device it lives on, because you will be removing them later and a list of unnamed entries is useless.
Set them up on devices only you use. A passkey on a shared or work machine hands your account to whoever else can unlock that machine.
Recovery: four methods, and two clocks worth knowing about
An account with no recovery method attached is one bad login away from being genuinely hard to get back. Google now offers four, and most guides still describe two.
| Method | What Google uses it for | Worth knowing |
|---|---|---|
| Recovery phone | Sending a code when you are locked out, blocking unauthorised use, flagging suspicious activity | Adding or changing it may take up to seven days to take effect |
| Recovery email | Getting back in when you cannot sign in, storage and suspicious-activity notices | Use an inbox you actually read, not another account you may also lose |
| Recovery contact | A person you trust helping you prove the account is yours | Unusable for seven days after they accept the invitation |
| Selfie video | Matching a short video of your face against one you stored earlier | Not available on Workspace accounts, child accounts, or accounts in the Advanced Protection Program |
Both seven-day figures point the same way: add recovery methods before you need them, because a method added during an emergency is not yet usable. This is the opposite of a piece of advice that circulates widely, including in an earlier version of this article, that you should leave a new account alone for a week before touching its recovery settings. Google documents no such waiting period. What it documents is a delay on the methods themselves, which is a reason to move sooner rather than later.
Pick a recovery email you check regularly, such as an Outlook inbox you already manage, so a future recovery request does not land somewhere you have also lost track of.
Habits that keep the checks quiet
Google's own guidance is the summary: familiar device, familiar location. Consistency over time does more than any single setting. Sign in from the same general environment rather than bouncing between them, keep one browser profile per account, and let the pattern establish itself.
An earlier version of this article suggested buying a residential proxy to achieve that stability, and that deserves a correction. The site's proxy shelf is 83 live listings and by title text more than a third of them are consumer VPN subscriptions, which is close to the opposite of a stable per-account address: a VPN puts you on a shared exit alongside everyone else on that server, which is exactly the kind of environment a verification check is looking for. The residential subcategory is small, twenty listings, and even within it a couple describe server or datacenter ranges. If address stability is genuinely what you need, read the listing text rather than the shelf name. For most people managing one or two inboxes, doing nothing and signing in from home is the better answer.
What the inbox listings actually declare
If you are picking up an inbox rather than creating one, the listing text is the only place the security state is declared before you buy. Across the live Gmail listings on HstockPlus, a little over half mention two-factor authentication or 2-step verification, and a few hundred mention an app password, which is the usual way a seller makes an inbox reachable by a mail client while a second factor is in place.
One absence is worth naming. Not a single Gmail listing on the shelf mentions a passkey. Across the entire live catalogue, all of it, only a handful of listings do at all, and those are on the Facebook shelf rather than any email shelf. So on a Gmail inbox you take over, assume no passkey exists and create your own. On a Facebook account, that assumption is no longer safe.
Gmail and other inboxes for secondary projects, verification and team workflows are listed by many independent suppliers, and terms differ enough that comparing a few is worth the time. The same applies to Outlook mailboxes if you would rather split providers.
Google's Account Help centre is the source for everything above and stays current as the screens move. The two articles worth bookmarking specifically are Turn on 2-Step Verification and Set up recovery options.


