Authenticator app vs SMS codes: which is safer?
By the Novaz team · Updated October 9, 2026 · Novaz steps checked against version 1.0.3
Short answer: codes from an authenticator app are safer than codes sent by SMS. Nothing is sent over the phone network, so someone who takes over your phone number doesn't get your codes. Both kinds are still one-time codes you type in, though, and a convincing fake sign-in page can steal either one. Where a website offers a passkey or a security key, that's stronger than both.
Why SMS codes are the weaker option
A text message goes to your phone number, not to your phone. Whoever controls the number gets the code.
- SIM swapping and port-out fraud. A scammer persuades your mobile carrier to move your number to their SIM, or to another carrier. The FCC explains that the scammer then controls "the victim's private texts and calls" (FCC). The FBI warns that after a swap, "calls, texts, and other data are diverted to the criminal's device" (FBI IC3).
- US government guidelines restrict it. NIST's digital identity guidelines (SP 800-63B-4, July 2025) list one-time codes sent over the phone network as a restricted authenticator. Services using them should watch for SIM changes and number porting, and must offer every user another option (NIST).
- Big providers are moving away from it. Microsoft says it will "start phasing out SMS" for signing in to, and recovering, personal Microsoft accounts (Microsoft).
Why authenticator app codes are better
An authenticator app makes each code on your phone from two things: a setup key you scanned once, and the current time. The code is never sent to you, so:
- taking over your phone number gets an attacker nothing,
- there's no text message to intercept or to read on a lock screen, and
- codes work with no signal at all. As Google puts it, "you can still generate codes without an internet connection or mobile service" (Google).
The FBI recommends "strong multi-factor authentication methods", including "standalone authentication applications" (FBI IC3).
What neither one protects you from: phishing
Both kinds of code are typed in by you, and that's the weak spot. A fake sign-in page can ask for your password and your current code, and pass both to the real website within seconds. NIST is direct about it: "OTP authentication is not phishing-resistant" (NIST, section 3.1.4).
What helps:
- Check the address bar before you type a code, every time.
- Never read a code out to anyone who calls, texts or emails you, however official they sound.
- Where it's offered, use a passkey or a hardware security key. They're tied to the real website's address, so they don't work on a fake site. NIST counts this kind of cryptographic sign-in as phishing-resistant.
Side by side
| SMS code | Authenticator app | Passkey or security key | |
|---|---|---|---|
| Someone takes over your phone number | Gets your codes | Gets nothing | Gets nothing |
| Works with no signal | No | Yes | Yes |
| Fake sign-in page | Can steal the code | Can steal the code | Doesn't work there |
| You lose your phone | Get a new SIM from your carrier | Depends on the app's backup, so keep backup codes | Synced passkeys come back on a new device; for a hardware key, keep a spare |
Turn off the SMS fallback where you can
Some websites keep SMS as a backup even after you set up an authenticator app. If the SMS route stays open, someone who takes over your number may be able to use it instead. Once your app and backup codes are set up, remove the phone number from the 2FA options if the website lets you.
In Authenticator App - Novaz
Novaz makes standard time-based codes on your iPhone. The setup keys stay in the iPhone Keychain on that device: they're never sent to Novaz or synced to iCloud. You can lock the app with Face ID or a passcode. Like every authenticator app, its codes aren't phishing-resistant. Novaz also has no backup, so the backup codes each website gives you are what get you back in if you lose the phone. More detail is in Is Novaz Authenticator safe?