Step 4 of 5

Registering and confirming your email address safely

This step takes about fifteen minutes and you only do it once per account. Done properly, it removes most of the ways a game account is lost, and all of the ways it is lost embarrassingly.

Choosing the email address

The address you register with becomes the key to the account. If someone gets into that mailbox, they can usually reset the game password at will, which means the mailbox is more valuable than the game account and deserves at least as much protection.

A work or school address is a poor choice, because you will lose access to it when you leave, and the account will go with it. A shared family address is a poor choice for a different reason: password reset messages for one person's account land in everyone's inbox.

A personal address you control, which you expect to keep for years, with its own strong password and its own second factor, is the right choice. If you want to keep game mail separate from everything else, many mail services let you file messages automatically by sender, which gets you the separation without a second mailbox to maintain.

Whatever you choose, make sure you can open it on the computer you are registering from. Having to walk to another room to read a confirmation message is how people end up registering twice.

Passphrases, and why length beats punctuation

A passphrase is a password made of several unrelated words rather than one word with substitutions in it. Current public guidance from the Australian Cyber Security Centre favours long passphrases over short complicated passwords, and explains the reasoning in plain language at cyber.gov.au. It is a short read and worth doing once.

The two rules that matter in practice are simple. Make it long, and make it unique to this account. Length is what makes guessing impractical. Uniqueness is what stops a breach somewhere else from becoming a break-in here, and reused passwords are the single most common way ordinary accounts are taken over.

Remembering a different long passphrase for every account is not realistic, which is why a password manager exists. A password manager is an application that stores your passwords behind one passphrase you do remember, and fills them in for you. Your browser almost certainly includes one; there are also standalone ones, free and paid. Using any of them is better than reusing a password across sites.

Write the one passphrase that opens the manager on paper and keep it somewhere physically safe. That advice sounds old-fashioned and it is the right advice: paper in a drawer at home is not reachable by anybody on the internet.

The registration procedure, step by step

This procedure is written to apply across the category rather than to any one vendor's screens, because screens change and the order of operations does not.

  1. Open the vendor's own site directly. Type the address or use a bookmark you made earlier. Do not start a registration from a link in an email, a message or an advertisement, even if it looks right.
  2. Check the address bar before typing anything. Confirm the domain is the vendor's own and that the connection is secure. A near-miss spelling of a well-known name is the oldest trick there is.
  3. Enter the email address you chose in Step 1, and read it back character by character before you submit. This is the one field that is painful to fix later.
  4. Set the passphrase from your password manager, generated or chosen, and save it in the manager before you submit the form rather than after.
  5. Enter the display name you drafted in Step 1. Assume it is permanent and public.
  6. Submit, then go to your mailbox and confirm the address using the link in the message. Confirmation links usually expire; if yours has, request a new one rather than registering again.
  7. Open the account security settings and turn on two-factor authentication. Do this before you play, not after, because afterwards you will not.
  8. Store the recovery codes offline — printed, or in the password manager's secure notes, not in the mailbox the codes are meant to protect.
  9. Sign out and sign in again once. It takes thirty seconds and it proves the whole chain works while you still remember what you set.

Enlisted is the example this course uses because this exact sequence is what getting started with it involves: registration, confirmation of the email address, and then logging in to play. We describe the sequence in general terms rather than walking through the vendor's own screens, since those screens are theirs to change. You can visit the Enlisted website if you want to follow the procedure on a real sign-up form.

This is a paid affiliate link. IGOA s.r.o. is paid a commission if you register through it, at no extra cost to you, and the procedure above was not written to suit it.

Telling a genuine confirmation from a fake one

A genuine confirmation message arrives within a minute or two of you registering, because you caused it. That timing is the most reliable signal available to an ordinary reader, and it is free.

Four further checks take ten seconds each. Does the sender's domain match the vendor's own, exactly? Does the link, when you hover over it without clicking, point at that same domain? Does the message ask for anything beyond clicking a link — a password, a payment detail, a document? A genuine confirmation asks for none of those. And is it pressuring you, with a deadline measured in minutes or a threat about your account?

If a confirmation message arrives when you did not register, do not click anything in it, including an unsubscribe or "this wasn't me" link. Someone has typed your address into a form. The safe response is to delete it, and, if such messages keep coming, to change the mailbox password and check that mailbox's own second factor.

Scamwatch collects and publishes current information about scams in Australia, including the shapes that fraudulent messages take, at scamwatch.gov.au. It is a better source than any list we could write here, because the patterns change and theirs is kept current.

The rule that covers almost everything. Never start from a link when the destination is somewhere you log in. Open the site yourself, from your own bookmark, and then look for the thing the message mentioned. If the message was genuine, it will be there.

Two-factor sign-in and recovery codes

Two-factor authentication means proving who you are in two ways: something you know, which is the passphrase, and something you have, which is usually a phone running an authenticator app that generates a six-digit code. With it switched on, a stolen password on its own is not enough to get into your account.

Codes from an authenticator application are generally preferred to codes sent by text message, because text messages can be redirected in ways an app on your own device cannot. If a service only offers text messages, that is still much better than nothing.

Recovery codes are the part people skip and regret. They are one-time codes the service gives you when you turn on two-factor sign-in, so that you can still get in if the phone is lost, broken or replaced. Print them, or store them in your password manager's notes, and do not store them in the email account they protect.

If the account belongs to a teenager, agree who holds the recovery codes. Our hypothetical household puts them in an envelope in a kitchen drawer, which is unglamorous and works.

Where the software should come from

Install the client from the vendor's own site or from a storefront you already trust, and from nowhere else. Files offered by a third party have been modified, by definition, even if only by having an installer wrapped around them, and you have no way to tell what else was changed.

Be particularly wary of anything that offers a faster version, a free version of something that is not free, or a tool that promises to improve a game's performance. Those offers are consistently where trouble comes from, and the Australian Cyber Security Centre's guidance for individuals at cyber.gov.au covers safe software practice properly.

Nothing on this site installs or offers software. We describe what to do; the files come from the vendor.

The worked example: fifteen minutes, done once

Our hypothetical household sits down with the laptop chosen in Step 2 and the notes from Step 1. This is an illustration, not a report of anyone's actual session.

The teenager's personal mailbox gets its own long passphrase first, and its own second factor, before anything else is touched — on the reasoning from the top of this page, that the mailbox is the more valuable account. That takes about five minutes.

Then the game account is created: address typed and read back, passphrase generated in the browser's password manager and saved before the form is submitted, display name as drafted. The confirmation message arrives in under a minute, which they note as the expected behaviour.

Two-factor sign-in goes on immediately. The eight recovery codes are printed on one sheet and go into the kitchen drawer. Finally one adult signs out and signs back in to check the second factor actually challenges them, which it does. Nobody has installed the game yet, and that is fine — the account exists and is protected, which is what Step 4 is for.

Before you move on

You should have an account whose email address is confirmed, whose passphrase is long, unique and stored in a password manager, and which asks for a second factor when you sign in. You should also have recovery codes somewhere offline and know who in the household holds them.

Step 4 checklist

  • Secure the mailbox first: long passphrase, second factor, recovery details current.
  • Open the vendor's site by typing the address or using your own bookmark.
  • Check the domain in the address bar before typing anything into a form.
  • Enter the email address and read it back character by character.
  • Generate a long, unique passphrase and save it in a password manager before submitting.
  • Use the display name you drafted, and treat it as permanent and public.
  • Confirm the email address from the message in your own mailbox, within the stated time.
  • Check the confirmation message: expected timing, matching sender domain, matching link, no request for passwords or payment details.
  • Turn on two-factor authentication before playing, preferring an authenticator application.
  • Store recovery codes offline, not in the mailbox they protect, and agree who holds them.
  • Sign out and sign in once to prove the whole chain works.
  • Install the client only from the vendor's own site or a storefront you already use.