How to Protect Your Primary Email Account
Why your main inbox is a security hub and the steps that reduce the risk of account takeover.
Your primary email account is often capable of resetting passwords for many other services. Protecting it is one of the highest-value security improvements you can make.
Use a unique credential
Never reuse the email account password on another service. If another website is breached, reused credentials can put your inbox at risk.
Enable strong multi-factor authentication
Use the strongest method your provider supports and that you can recover reliably. Store recovery codes safely.
Review recovery information
Old phone numbers and inaccessible backup email addresses can create recovery problems. Keep recovery methods current and protected.
Check active sessions and devices
Major providers usually offer a security page showing recent sign-ins or connected devices. Remove sessions you do not recognize and investigate unexpected activity.
Watch forwarding and filter settings
An attacker with inbox access may create forwarding rules or filters to hide security messages. If you suspect compromise, review these settings in addition to changing the password.
Be cautious with connected apps
Third-party apps can retain account permissions. Periodically remove integrations you no longer use.
Treat unexpected codes as warnings
If you receive a login code or approval prompt you did not initiate, do not approve it. Open the provider’s official app or website independently and review account activity.
Your email account is part inbox and part identity recovery system. Secure it accordingly.