Protect the account that resets other accounts
How to Secure Your Email Account Without Relying on One Setting
A secure email account combines strong authentication, unique credentials, clean recovery settings, session review and careful treatment of forwarding rules because the mailbox often controls recovery for other accounts.
Email security advice often collapses into one instruction: use a strong password. That is necessary when passwords are still part of the account, but it is not a complete model. A mailbox can also be weakened by an old recovery address, an attacker session that was never revoked, a malicious forwarding rule or a second factor that is easier to bypass than the primary login.
The security baseline
Treat these as layers. One strong control should not be asked to compensate for every weak control around it.
- Use a passkey where your provider supports it, or use a strong unique password that is not reused anywhere else.
- Turn on 2-step verification or multi-factor authentication and prefer stronger methods supported by your provider.
- Keep recovery email addresses and phone numbers current and under your control.
- Review signed-in devices and active sessions, especially after a suspicious login or password change.
- Check forwarding rules, filters and delegated access for changes you did not create.
- Protect the devices and browsers that stay signed in to the mailbox.
Passkeys reduce password exposure, but the surrounding account still matters
The UK National Cyber Security Centre now recommends passkeys for email where supported. Passkeys are phishing-resistant because the credential is bound to the legitimate service rather than typed into any page that asks for it.
If the account still has a password as a fallback, the NCSC also recommends keeping that password strong and unique and supporting it with 2-step verification. A secure primary path does not justify leaving a weak recovery path behind.
Recovery settings deserve the same attention as the login screen
A recovery email or phone number exists so you can prove control when the normal sign-in path fails. If those details belong to an old account, an old phone or someone else, the fallback can become the weakest part of the system.
The FTC specifically recommends checking recovery information after regaining a hacked account. That review matters because an attacker who had account access may try to change recovery details or leave behind another path into the mailbox.
What to review after suspicious activity
| Area | What to look for | Why it matters |
|---|---|---|
| Sessions/devices | Unknown browsers, phones or locations | A password change is less useful if an attacker session remains valid |
| Forwarding | Rules that send copies of mail elsewhere | Attackers can quietly siphon reset messages or sensitive correspondence |
| Recovery | Unfamiliar email addresses or phone numbers | Recovery is another authentication route |
| Sent/deleted mail | Messages you did not send or messages that vanished | These can reveal how the account was used while compromised |
A secure mailbox is a system, not a checkbox. Strong authentication, clean recovery settings, controlled sessions and honest review of forwarding rules work together because email often sits at the center of your wider account-recovery chain.
Put this threat in context
Sources and further reading
Need a separate inbox for a short-lived interaction?
Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.
Create temporary email