Inbox
Email security

Protect the account that resets other accounts

How to Secure Your Email Account Without Relying on One Setting

A secure email account combines strong authentication, unique credentials, clean recovery settings, session review and careful treatment of forwarding rules because the mailbox often controls recovery for other accounts.

9 min read

Email security advice often collapses into one instruction: use a strong password. That is necessary when passwords are still part of the account, but it is not a complete model. A mailbox can also be weakened by an old recovery address, an attacker session that was never revoked, a malicious forwarding rule or a second factor that is easier to bypass than the primary login.

The security baseline

Treat these as layers. One strong control should not be asked to compensate for every weak control around it.

  • Use a passkey where your provider supports it, or use a strong unique password that is not reused anywhere else.
  • Turn on 2-step verification or multi-factor authentication and prefer stronger methods supported by your provider.
  • Keep recovery email addresses and phone numbers current and under your control.
  • Review signed-in devices and active sessions, especially after a suspicious login or password change.
  • Check forwarding rules, filters and delegated access for changes you did not create.
  • Protect the devices and browsers that stay signed in to the mailbox.

Passkeys reduce password exposure, but the surrounding account still matters

The UK National Cyber Security Centre now recommends passkeys for email where supported. Passkeys are phishing-resistant because the credential is bound to the legitimate service rather than typed into any page that asks for it.

If the account still has a password as a fallback, the NCSC also recommends keeping that password strong and unique and supporting it with 2-step verification. A secure primary path does not justify leaving a weak recovery path behind.

Recovery settings deserve the same attention as the login screen

A recovery email or phone number exists so you can prove control when the normal sign-in path fails. If those details belong to an old account, an old phone or someone else, the fallback can become the weakest part of the system.

The FTC specifically recommends checking recovery information after regaining a hacked account. That review matters because an attacker who had account access may try to change recovery details or leave behind another path into the mailbox.

What to review after suspicious activity

AreaWhat to look forWhy it matters
Sessions/devicesUnknown browsers, phones or locationsA password change is less useful if an attacker session remains valid
ForwardingRules that send copies of mail elsewhereAttackers can quietly siphon reset messages or sensitive correspondence
RecoveryUnfamiliar email addresses or phone numbersRecovery is another authentication route
Sent/deleted mailMessages you did not send or messages that vanishedThese can reveal how the account was used while compromised

A secure mailbox is a system, not a checkbox. Strong authentication, clean recovery settings, controlled sessions and honest review of forwarding rules work together because email often sits at the center of your wider account-recovery chain.

Put this threat in context

Sources and further reading

Need a separate inbox for a short-lived interaction?

Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.

Create temporary email

Related security guides