In this guide
- Why email is the account that matters
- Step one: a unique, strong password
- Step two: two-factor authentication
- Step three: audit the settings attackers change
- Step four: reduce what the account is worth
- Step five: know the warning signs
- If it has already happened
- The short version
Why email is the account that matters
Think about what happens when you forget a password anywhere. You click "forgot password", a link arrives in your email, and you set a new one. That mechanism is the foundation of how nearly every online service handles identity.
It also means that whoever controls your email controls almost everything you own online. Your bank, your shopping accounts, your cloud storage, your social media, in many cases your phone account. An attacker with your email does not need to break into those individually. They can simply reset them, one by one, at their leisure.
This is why email deserves more protection than any other single account, including your bank. Most people have it backwards, treating banking as the sensitive one and email as a utility.
Step one: a unique, strong password
Your email password must not be used anywhere else. Not a variation of it, not a version with a different number on the end. If it appears anywhere in your life besides this account, change it.
Make it long. A passphrase of four or five random words is easier to remember than a mangled word and far harder to crack — our passphrase generator creates one in your browser. If you have a password manager, use a long random string instead, since you will rarely need to type it.
Check whether your current password has already appeared in a breach using our breach checker. If it has, it is in every attacker's first-guess list and needs to change today.
Step two: two-factor authentication
This is the step that turns a leaked password from a disaster into an inconvenience. With it enabled, knowing your password is not enough to get in.
The options, in order of strength:
- Passkeys — the strongest. A cryptographic key on your phone or computer, unlocked by fingerprint, face or PIN. Nothing is typed, so nothing can be phished. If your provider offers these, use them.
- A hardware security key — a physical device you plug in or tap. Extremely strong, and worth it if your email protects something valuable.
- An authenticator app — six-digit codes generated on your phone. A solid default that works offline and cannot be intercepted by a SIM swap.
- Text message codes — the weakest of the real options, because of SIM swapping, but still a large improvement on nothing.
Whichever you choose, save the backup codes the provider gives you. Print them and keep them with your important documents. Storing them as a screenshot on the phone that generates your codes is the most common mistake and defeats the point entirely.
Step three: audit the settings attackers change
This is the part almost everyone skips, and it is the part that matters most if you have ever been compromised. An attacker who gets into an email account rarely just reads it. They set up quiet persistence, so they keep access even after you change the password.
Go through each of these in your email settings today:
- Forwarding rules. Look for any address receiving copies of your mail. This is the classic trick — the attacker keeps receiving your password reset codes indefinitely.
- Filters and rules. Watch for rules that automatically delete or archive messages containing words like "security", "password", "invoice" or "bank". These hide the alerts that would otherwise warn you.
- Recovery email and phone. Confirm both are yours and current. An attacker who adds their own recovery address owns the account permanently.
- Connected apps and third-party access. Revoke anything you do not recognise or no longer use. Some of these have permission to read and send mail on your behalf.
- App passwords. Older accounts sometimes have these, and they bypass two-factor authentication entirely. Delete any you do not actively need.
- Active sessions and devices. Sign out of everything you do not recognise, and everything you no longer own.
- Alternate send-as addresses. Check nothing has been added that would let someone send mail as you.
Do this whether or not you think you have been compromised. It takes ten minutes and it is the only way to find persistence that a password change would not remove.
Step four: reduce what the account is worth
An email account is valuable partly because of what is sitting in it. Most inboxes are an accidental archive of everything: scanned passports, tax returns, bank statements, contracts, photographs of documents sent to a family member years ago.
Search your own mailbox for terms like passport, licence, tax, statement, and contract. What you find is what an attacker would find. Download what you need to keep, store it somewhere encrypted, and delete it from the mailbox. This does not prevent a breach, but it substantially reduces what one costs you.
While you are there, consider separating your identities. Use one address for banking, government and anything tied to your identity; a different one for shopping, newsletters and sign-ups. When a shopping site is breached — and they are, constantly — the exposed address is not the one attached to your bank.
Step five: know the warning signs
Things that mean your email may already be compromised:
- Password reset emails for other services that you did not request.
- One-time codes arriving unprompted.
- Friends receiving messages from you that you did not send.
- Missing emails, or emails appearing as already read.
- Your phone unexpectedly losing mobile signal, which can indicate a SIM swap.
- Login alerts from unfamiliar locations or devices.
If it has already happened
- Change the password immediately, from a device you trust. If you cannot get in, use the provider's account recovery process straight away — speed matters, because an attacker's next move is to change the recovery details.
- Sign out of all sessions everywhere. This is essential, because stolen session cookies allow access without a password or a code.
- Run the full settings audit above. Remove every forwarding rule, filter, connected app and recovery address you did not create.
- Turn on two-factor authentication if it was not already on, and regenerate backup codes if it was.
- Reset the passwords on anything that uses this email for recovery, starting with banking.
- Warn your contacts, since compromised accounts are routinely used to defraud the people in them.
- Check your bank statements for the following months, and report anything unexpected promptly.
The short version
A unique long password, two-factor authentication with saved backup codes, and a ten-minute settings audit to remove forwarding rules and unknown access. That is the whole job, it takes less than half an hour, and it protects more than any other single thing you could do this week.
Frequently asked questions
Why does email matter more than my banking password?
Because your email can reset your banking password. Whoever controls the inbox controls the reset mechanism for nearly every other account you own, which makes it the highest-value target by a wide margin.
What should I check if I think my email was accessed?
Forwarding rules, filters that delete security alerts, recovery email and phone numbers, connected third-party apps, app passwords and active sessions. Attackers set these up so they retain access after you change the password.
Is text-message two-factor good enough for email?
It is far better than none, and weaker than the alternatives because of SIM swapping. Use passkeys or an authenticator app for your email if your provider supports them.
Should I have more than one email address?
It helps. Keep one address for banking, government and identity, and a separate one for shopping and sign-ups. When a retailer is breached, the exposed address is not the one your bank uses.
Why does signing out of all sessions matter?
Because session cookies keep someone logged in without needing the password again. Changing your password alone does not always invalidate them, so an attacker can remain inside the account.