Account security
Securing your email account: the one that unlocks everything else
Your inbox is the master key to nearly every other account you own. Why attackers go for it first, the settings that actually make it hard to take, and the quiet forms of persistence people forget to check.
Most people rank their email account somewhere below their bank and their phone in order of importance. Attackers rank it first, and they are right to. Almost every other account you own has a button on its login page that says email me a reset link. Whoever controls the inbox controls the buttons.
This guide is about closing that door. It is deliberately practical, and none of it requires you to be technical.
Why the inbox is the master key
Think about what actually happens when you forget a password. The service does not verify who you are in any deep sense. It sends a link to an address on file and trusts that only you can read it. That is the entire security model, and it is a reasonable one — right up until someone else can read your mail.
An attacker who gets into your inbox does not need to break your other accounts. They can simply ask each one, politely, to let them in. Banking, shopping, social accounts, your domain registrar, your cloud storage: all of them, one reset at a time.
This is why a compromised inbox is not one problem. It is every problem you have, arriving at once.
The three settings that do most of the work
If you do nothing else in this guide, do these.
1. Use a unique password nowhere else in your life. Not a variation. Not the one with a different number on the end. Credential-stuffing attacks work by taking a password leaked from some forum you forgot about in 2015 and trying it against your mail provider. A password manager makes this painless; if you would rather not use one, a long passphrase of several unrelated words is far stronger than a short string of symbol substitutions.
2. Turn on the strongest second factor your provider offers. Ranked from best to worst: a passkey or hardware security key, then an authenticator app, then SMS codes. SMS is genuinely better than nothing — do not let anyone talk you out of it if it is all you can use — but it is vulnerable to SIM-swap attacks, where someone persuades your mobile carrier to move your number to their device. If your provider supports passkeys, prefer them. We cover the mechanics in Passkeys explained and the trade-offs between methods in Choosing a two-factor method.
3. Print your recovery codes and store them somewhere physical. Every provider gives you a set of one-time backup codes when you enable two-factor. People generate them, leave them in a downloads folder, and lose them. Put them on paper, in a drawer, with your passport. The single most common reason people avoid strong authentication is the fear of locking themselves out, and recovery codes are the answer to that fear.
The persistence tricks people miss
Here is the part that gets skipped, and it is the reason people get compromised twice.
When an attacker gets into a mailbox, changing the password does not necessarily evict them. Mail systems have a number of features that quietly keep access alive:
- Forwarding rules. A rule that silently copies every incoming message to an outside address. You change your password; they keep reading your mail.
- Filters that hide evidence. A rule that immediately archives or deletes anything containing the words security alert, password, or the name of your bank, so you never see the warnings.
- Alternate recovery addresses and phone numbers. Added quietly, so the attacker can reset your password later at their convenience.
- App passwords and connected third-party apps. Long-lived tokens that bypass your password entirely and often survive a password change.
- Active sessions on other devices. Still signed in, still reading.
Go and look at all five right now, on your main mail account. Every major provider exposes these in its security or settings screens. If you find something you do not recognise, remove it, then change your password, then sign out of all sessions — in that order.
Recognising the attack before it lands
Almost every real-world inbox compromise starts with you typing your password into a page that is not your mail provider. Not a clever exploit — a convincing replica reached through a link.
The reliable defence is a habit rather than a skill: never sign in through a link. If a message claims your account has a problem, do not tap the button. Open your browser or app and navigate to the service yourself. This costs you eight seconds and defeats the entire category.
Passkeys and security keys make this stronger still, because they are bound to the real site's identity and simply will not produce a credential for a lookalike domain. Human vigilance fails occasionally; that binding does not.
For the wider pattern of manipulation these messages rely on — urgency, authority, a plausible reason to hurry — see Recognising social engineering.
A quiet risk: the address you abandoned
Many people have an old address at a provider they stopped using, still listed as the recovery address on accounts they still care about. Some providers eventually release abandoned usernames. Others simply have weaker security than the account you have been carefully protecting.
Spend ten minutes auditing which address is on file as the recovery route for your important accounts. If it is one you no longer monitor, update it. An unmonitored inbox is not just a weak link — it is a weak link where nobody hears the alarm.
If you think it has already happened
Move in this order:
- Change the mail password from a device you trust, and sign out of all other sessions.
- Audit forwarding rules, filters, recovery addresses, app passwords, and connected apps. Remove anything unfamiliar.
- Re-enrol your second factor, and generate fresh recovery codes. Assume the old ones are burned.
- Work outward to accounts that use this address for resets, starting with anything financial.
- Warn your contacts. Compromised mailboxes are used to attack the people who trust you, and your address is the most convincing thing an attacker has.
The honest summary
Email security is unglamorous. There is no single setting that makes you safe, and the useful work is a handful of small, boring configuration choices plus one habit about links.
But the leverage is real. An hour spent on the account that can reset all your other accounts is worth more than the same hour spread thinly across everything else you own.
