Secure your email account: the key to everything else
Your email can reset almost every other account. Check password, 2FA, recovery options, forwarding rules and connected apps in about 20 minutes, step by step.
Login securityPublished
Your email account is the key to everything else, because almost every service sends password resets to it. If someone controls your inbox, they can take over your shops, social media and often more. Securing it takes about twenty minutes and is the best single investment in your online safety.
Why email deserves special care
A password reset is just an email with a link. An attacker who reads your mail can request resets for any account tied to that address, intercept the link and change the password before you notice. That is why your email needs a stronger setup than most of your other accounts.
Step by step: lock down your email
1. Use a unique, long password or a passkey
Give your email a password that you use nowhere else, long and random, following our guide to strong passwords. If your provider supports passkeys, use one, because they cannot be phished.
2. Turn on two-factor authentication
Enable 2FA and prefer an authenticator app or a security key. SMS is better than nothing, but it has known weaknesses.
3. Update recovery options
Check the recovery phone number and recovery address. Remove old ones, since an outdated recovery address that someone else now owns is a back door. Generate backup codes and store them offline. The guide to account recovery explains what to set up.
4. Look for forwarding rules and filters
Attackers who briefly gain access often add a rule that copies your incoming mail to their address, or hides security notices. In your mail settings, open “Forwarding” and “Filters and rules” and delete any that you did not create.
5. Review connected apps and devices
In your account’s security settings, look at third-party apps with mail access and the list of signed-in devices. Remove what you do not recognise or no longer use, and sign out of all other sessions.
6. Check recent activity
Most providers show recent sign-ins, locations and devices. A login from a country you have never visited is a reason to change your password immediately.
Use more than one address
| Address | Use for | Why |
|---|---|---|
| Private main address | Banking, government, health, key accounts | Never published, rarely guessed |
| Everyday address | Friends, work contacts | Normal use |
| Alias or separate address | Shops, newsletters, trials, sign-ups | Contains the damage and spam if it leaks |
Some providers let you create aliases that forward to your main inbox, and Apple’s Hide My Email does the same for sign-ups, as covered in Sign in with Google, Apple or Facebook.
Watch for phishing
Most email takeovers start with a convincing message that asks you to sign in. Check the sender and the address of the page before you type anything, or open the provider’s site yourself. Never share a code that was sent to you. For more on phishing-proof sign-in, see phishing-resistant MFA.
If you think your email is already compromised
- From a clean device, change the password now.
- Sign out of all sessions and remove unknown devices and apps.
- Remove forwarding rules and filters.
- Turn on 2FA and refresh your recovery details.
- Tell contacts to ignore odd messages from you.
- Review other accounts, starting with banking and social media, and follow the steps in what to do after a data breach.
What a secure setup looks like
A well-protected inbox needs very little maintenance once the basics are in place. A quick picture of the goal:
- The password is unique and stored in a password manager, or replaced by a passkey.
- Sign-in requires a second factor that cannot be read out over the phone, such as a security key or an authenticator app.
- Recovery details point to things you control today, and a printed set of backup codes sits in a safe place.
- The list of connected apps and devices contains only things you recognise.
- Nothing is silently forwarded, filtered or deleted.
Webmail, apps and old devices
Mail clients and old phones often keep long-lived access. If you retire a device, sign it out in your account’s security page, not only on the device itself. If an app asks for full access to your mailbox, ask yourself whether it needs it. Removing access is easy, and you can always grant it again.
Free, paid and custom domains
The security options you get depend on the provider. Large free services usually offer passkeys and 2FA. If you use your own domain for email, apply the same rules to the account that controls the domain, because whoever can change its settings can redirect your mail. Treat the domain registrar login like another critical account.
Annual check-up
Once a year, set aside ten minutes: review recent activity, devices and apps, confirm recovery options, and make sure your backup codes are still where you think they are.
Typical warning signs
- You receive password reset emails you did not request.
- Contacts say they got strange messages from you.
- Sent mail or deleted items contain messages you did not write.
- A security notification about a new device or a changed recovery address appears.
- You are suddenly signed out and your password no longer works.
Any one of these is a reason to follow the compromise steps above immediately.
Bottom line
Treat your email like the master key it is: unique password or passkey, a strong second factor, current recovery details, a tidy list of rules, apps and devices, and a separate address for the accounts that matter most.
Frequently asked questions
Why is my email account so important?
Because 'forgot password' links go to your inbox. An attacker who can read your email can request resets for your shops, social media and sometimes your bank, and then lock you out.
Should I use a separate email address for banking?
It helps. An address that you never publish and never use for newsletters is harder to guess and less likely to appear in marketing breaches. Use aliases or separate addresses for shops and sign-ups.
How do I know if someone is secretly reading my email?
Look for forwarding rules or filters you did not create, unfamiliar devices or sign-in locations, and apps with mail access that you do not recognise. Remove them, then change your password and sign out everywhere.
Is SMS 2FA enough for my email account?
It is better than nothing, but an authenticator app, a security key or a passkey is stronger because SMS can be redirected through SIM swapping.
More in Login security
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.
How password managers work and why they are safe
A password manager keeps your logins in an encrypted vault that only your master password opens. How it works, the real risks and how to start in an afternoon.