
Creating a Twitter account (now X) without providing a phone number remains a recurring question for privacy-conscious users. The official sign-up flow on x.com offers a choice between email address and phone number. The answer is yes, but the platform may require a number depending on the technical context of the connection.
X Risk Score: What Triggers the Phone Number Request
The X platform does not systematically impose the phone number requirement. It assigns a risk score to each sign-up attempt, based on the detected technical environment. When this score exceeds a certain threshold, phone verification becomes mandatory, even if the user has chosen the email option.
Several signals increase this score and make the phone number request almost inevitable:
- The use of a disreputable VPN or a data center proxy, which X associates with automated behaviors
- A shared IP address used by many recently created accounts, a classic signal of mass creation
- The inconsistency between the declared location and the one detected by the IP address or browser
Understanding this mechanism changes the strategy. Rather than trying to bypass the phone request afterward, it is more effective to reduce the risk score upstream so that the platform never requires this number.
A detailed guide explains how to sign up for Twitter without a number using the standard web flow, which remains the most permissive in this regard.

X Registration via Email or through Google and Apple: Comparison Table
The sign-up flow on x.com/signup offers three distinct paths. Each has different characteristics regarding phone number requirements and privacy levels.
| Registration Method | Phone Number Required | Initial Verification | Privacy Level |
|---|---|---|---|
| Email Address (web flow) | No (unless high risk score) | Code sent by email | Medium to high |
| Sign in via Google | No (unless high risk score) | Google Authentication | Medium (data linked to Google account) |
| Sign in via Apple | No (unless high risk score) | Apple Authentication | High (option “Hide my email”) |
| Direct Phone Number | Yes | SMS Code | Low |
Signing in via Apple offers a specific advantage: the “Hide my email” feature generates a unique relay address, preventing X from collecting the real address. In contrast, signing in via Google transmits the Gmail address to the X account, which reduces privacy compared to a dedicated email.
The web flow with an email address remains the most controllable. The user chooses the address they provide and can opt for a privacy-focused email service.
Temporary or Dedicated Email Address: What Impact on the X Account
Several competitors suggest using disposable email addresses for registration. This approach sometimes works in the short term but poses real risks in the medium term.
A temporary email prevents any account recovery in case of loss of access. If the inbox expires after a few hours or days, the password reset code will go nowhere. The account becomes unrecoverable.
X also detects certain disposable email domains and blocks them during registration, or immediately triggers phone verification. The risk score increases with these domains.
More Reliable Alternative: A Permanent Dedicated Email Address
Creating an address on a classic free service, used exclusively for the X account, represents a stronger compromise. This address remains accessible for receiving verification codes and security notifications.
Some criteria for choosing this address:
- A provider that does not itself require a phone number at creation (some encrypted email services allow this)
- An inbox checked regularly, as X may request reconfirmation after a period of inactivity
- A password distinct from that of the X account, to prevent a single compromise from granting access to both accounts

Securing an X Account Created Without a Phone Number
The absence of a phone number on the account removes a recovery vector, but also an attack vector. SIM swap attacks, where a hacker transfers the victim’s number to another SIM card to intercept SMS codes, cannot target an account without an associated number.
Two-factor authentication via app (TOTP) largely compensates for the absence of SMS verification. The apps generate codes locally, without relying on the mobile network. This mode of two-factor authentication is available in X’s security settings.
A often overlooked point: the backup codes generated when enabling 2FA must be stored offline. Without a phone number and without these codes, losing access to the authentication app permanently locks the account. No standard support procedure allows account recovery in this situation.
Thus, the appropriate security setup for an account without a phone combines a permanent dedicated email address, app-based 2FA, and physical storage of backup codes. This configuration offers a higher level of protection than an account verified by SMS, while preserving the privacy of the personal number.