Skip to content

What to Do When Gmail Two-Step Verification Asks for a Recovery Number You No Longer Own

Google is texting a code to a line that now belongs to a stranger. There are six other routes in, one of them is a file already sitting on your laptop, and the worst thing you can do right now is keep hitting retry.

Add us as a preferred source on Google (opens in a new tab)

Table of Contents
  1. Stop hitting retry first
  2. Six routes to try before the recovery form
  3. The file you probably already have and forgot about
  4. If none of that works, the form and the wait
  5. Can you just get the old number back?
  6. The first ten minutes after you're back in

Google won’t offer to send that code somewhere else. Once a number is locked in as your second step, that’s where the text goes, and it keeps going there even if the line was reassigned to a stranger eighteen months ago.

What it does offer is a link reading Try another way, sitting under the code box where nearly everybody scrolls straight past it. When Gmail two-step verification asks for a recovery number you no longer own, that link is the entire answer for most people. Six other verification routes sit behind it, and the account recovery form that everyone jumps to should be the last thing you try rather than the first.

Stop hitting retry first

Before anything else, quit tapping the resend button. Google treats repeated failed attempts as suspicious behaviour and can lock the account down harder in response, which turns a bad afternoon into a much longer problem. One attempt, then move to a different method.

Six routes to try before the recovery form

Click Try another way and see which of these Google offers you. They’re worth checking in roughly this order because they get progressively harder.

  • A Google prompt on another device. If your account is still signed in on any phone or tablet, Google can push a Yes or No prompt straight to it. This is the fastest route by a mile and people forget they’ve got an old phone or a tablet sitting in a drawer still signed in.
  • A device you marked as trusted. If you ever ticked the box saying don’t ask again on this computer, that machine may let you straight through without a second step at all. Try the laptop you normally use before anything else.
  • A backup code. Ten single-use codes generated when you turned 2-Step Verification on. More on finding these below, because most people have them without knowing.
  • A second phone number. If you ever added a spare number in the 2-Step Verification settings, it’s still there and Google will offer it.
  • A passkey. If you set one up on a laptop or another phone, that device can verify you on its own with a fingerprint or face scan.
  • A hardware security key. Rare for home users, but if you own one it works.

Google won’t always show every option. What appears depends on what you’ve actually got set up on the account, so if the list looks short, that’s the account telling you what your past self did and didn’t do.

The file you probably already have and forgot about

This is the tip worth the whole article. When Google generates backup codes, most people click Download rather than Print, and the file lands in the downloads folder with a very specific name: Backup-codes-username.txt, with your own Gmail username in place of username.

Search for that exact filename on every computer and phone you own. Search your downloads folder, your documents, any external drive, an old laptop, a phone you’ve since replaced. People genuinely find it there years later, sitting untouched, having spent the whole afternoon convinced they never made backup codes at all.

If you use a password manager, check inside it too. Plenty of people paste the codes into a secure note when they set 2FA up and then never think about them again, which is exactly why keeping a proper password manager on your phone pays for itself the one time something like this happens.

Each code works once. Use one to get in, then go and generate a fresh set immediately, because using one doesn’t invalidate the others but you don’t want to be down to your last two.

If none of that works, the form and the wait

Google’s account recovery form is the fallback, and there’s a detail about it that almost no guide mentions. For accounts protected by 2-Step Verification, Google says it can take three to five business days to verify you’re the owner. That’s not a queue you can jump and no support agent can shorten it.

Knowing that up front matters, because people submit the form, hear nothing for two days, assume it failed, and submit again. Fresh submissions can reset your position and make things worse. Submit once and then leave it alone.

A few things that improve your odds. Fill the form from the device and the internet connection you normally used for that account, because Google weighs whether the request looks like it’s coming from somewhere familiar. Give old passwords you’ve used, even ones from years back, and be as accurate as you can about roughly when you created the account. Answer everything rather than skipping questions you’re unsure about, since a rough answer scores better than a blank.

Do also give a contact email address you can actually open, since that’s where Google’s response lands. A borrowed address from a family member is fine.

Can you just get the old number back?

Sometimes, and it’s worth twenty minutes at a service centre before you write it off.

Nigerian networks reclaim lines after a stretch of inactivity and eventually hand them to somebody new. The important question is which stage yours is at. If the line is dormant but hasn’t been reassigned, MTN, Airtel, Glo and 9mobile can often restore it to you, particularly when the NIN registered against that number is still yours. Walk into a service centre with your ID rather than trying to sort it over the phone.

If the number has already gone to somebody else, that door is closed. The network won’t take it back off a paying customer, and no amount of explaining that your Gmail is attached to it will change that.

This bites hardest for people who moved abroad and let a Nigerian line lapse, which is a very common version of this problem. If you’re setting up a fresh line here for verification purposes, an eSIM is worth considering since it’s harder to lose than a physical card and easier to keep active from a distance.

The first ten minutes after you’re back in

Go straight to your Google Account, then Security, then the 2-Step Verification section. Delete the dead number before you do anything else, because leaving it there means a stranger keeps getting codes tied to your account and that’s a genuine security hole, not just an inconvenience.

Then set up more than one way back in, because relying on a single phone number is what put you here. Download a fresh set of backup codes and put them somewhere that isn’t your phone. Add an authenticator app so codes are generated on the device rather than texted to a line that can be recycled. Set up a passkey on your laptop. Add a second phone number belonging to someone you’d trust with your email, a parent or a partner.

Check your recovery email address too, since plenty of people have an old work address or a defunct Yahoo account sitting in that field. And while you’re in there, look at the list of devices with access and sign out anything you don’t recognise or no longer own.

One last thought worth acting on today rather than after the next emergency. Every account tied to that dead number has the same problem waiting, your bank app, your social accounts, everything. Sorting them out one evening beats discovering it the hard way, and the process for clawing back a social account with no working email or phone attached is considerably slower and less forgiving than Google’s.

Avatar of Ebeh Christopher

A Computer Science graduate, web developer, and digital strategist with over 10 years of experience. On GuidesCafe, I create practical guides on education, technology, jobs, business opportunities, and digital skills to help readers make smarter decisions.