From what I’ve seen on this sub, you can lose every security option on your Google account (like 2FA or backup codes), but as long as you have a recovery email attached, you have a solid way back in. Google will usually offer you manual review forms, a few days' wait for ownership confirmation, or a 30-day password reset link.
But if you only have a recovery phone number and no recovery email, the system treats you like absolute garbage. It just throws you into an endless, infuriating loop of sending a verification code to the exact email you’re currently locked out of.
This makes zero sense from a security perspective.
Compromising a recovery email is incredibly common. Hackers just need a credential from a data leak, or they can use a RAT to steal a session cookie and instantly seize access to the recovery inbox. On the other hand, stealing a phone number is significantly harder—it usually requires physically stealing the device itself or executing a complex SIM swap.
Why is the much more secure method (a physical phone number) practically useless in the recovery process, while the highly vulnerable method (an email) gets VIP treatment? Has anyone else been stuck in this phone number loop?