Back to Blog

Remove a Former Housemate From Account Recovery Emails and Phone Numbers

A focused audit for removing old household recovery routes without locking the current account owner out.

Remove a former housemate's recovery email or phone number from every household account they no longer manage, but add and verify a current recovery route first. Then review sessions, two-factor methods, passkeys, trusted devices, forwarding rules, and delegated access. Changing the visible recovery contact is only one part of offboarding.

Build a recovery-route inventory

List household services that can reset access: primary email, utilities, internet, rent portal, insurance, security system, smart-home platform, shared storage, and subscriptions. For each service, record the account owner and the last few characters of the recovery address or number. Do not put full recovery codes or passwords in the inventory.

Search shared email for phrases such as “recovery email changed,” “new sign-in method,” and “backup code,” but respect personal mailboxes. Ask each person to check their own accounts. Some services hide recovery details or route changes through customer support, so note where identity documents or billing records may be required.

Recovery information can help regain access after a forgotten password or suspected takeover. Google's recovery options guidance also notes that after recovery information changes, codes may still be sent to previous information for a period. Read each provider's current warning and do not promise an instant cutoff that the provider does not offer.

Replace first, remove second

Add a current email address or phone number controlled by the proper account owner. Verify it using the provider's code or confirmation link. Confirm that the owner can sign in from a trusted device before removing the old route. For a genuinely shared account, choose an accountable custodian and a backup that does not depend on someone leaving the home.

Remove the former resident's email, number, trusted device, passkey, app password, and security key where they are no longer authorized. Sign out old sessions. Check whether third-party apps still have access. In email, review automatic forwarding, filters, delegates, and connected mail clients because those can preserve access after a password change.

Do not replace a former housemate with a new housemate's personal number by default. That merely restarts the same dependency. Prefer a service's member invitations or role-based access. If one shared login is unavoidable, document who owns it and how the household will recover it.

Test the new path without creating a lockout

Use the provider's security-checkup page to confirm the new recovery details appear. A normal sign-in and two-factor check are safer than deliberately triggering repeated account-recovery attempts, which can cause delays or fraud controls. Generate fresh backup codes if the service provides them and invalidate the old set.

Tell the former housemate when removal is complete, without sending screenshots of private security settings. Ask them to delete saved credentials from their password manager and devices. The household should also complete the wider digital move-out checklist for smart devices, subscriptions, and shared data.

Keep a dated record of the services checked. If an alert goes to an old contact after the change, read the provider's explanation and contact official support if needed. Never ask the former resident to forward a one-time security code unless a pre-agreed, legitimate transition is underway and the service permits it.

How HomeCo helps

Create one HomeCo offboarding project with a task for each service and fields for owner, new route verified, old route removed, sessions reviewed, and date completed. Mask contact details and keep secrets outside HomeCo.

Assign personal-account checks privately and shared-account checks to the current custodian. Link the recovery audit to move-out day, but start it early enough to resolve support delays. A final review task a few days later catches forgotten services without keeping informal access open indefinitely.

FAQ

Is changing the password enough?

No. Recovery contacts, active sessions, passkeys, forwarding, and connected apps may remain. Review each category in the provider's security settings.

What if the old number now belongs to someone unknown?

Replace it promptly through official settings or support. Treat any account using it as exposed to unintended recovery attempts.

Should a shared household email recover every account?

Only if access to that mailbox is tightly managed and appropriate for each service. Personal accounts should use personal recovery routes.