Your primary email account is often capable of resetting passwords for many other services. Protecting it is one of the highest-value security improvements you can make.

Use a unique credential

Never reuse the email account password on another service. If another website is breached, reused credentials can put your inbox at risk.

Enable strong multi-factor authentication

Use the strongest method your provider supports and that you can recover reliably. Store recovery codes safely.

Review recovery information

Old phone numbers and inaccessible backup email addresses can create recovery problems. Keep recovery methods current and protected.

Check active sessions and devices

Major providers usually offer a security page showing recent sign-ins or connected devices. Remove sessions you do not recognize and investigate unexpected activity.

Watch forwarding and filter settings

An attacker with inbox access may create forwarding rules or filters to hide security messages. If you suspect compromise, review these settings in addition to changing the password.

Be cautious with connected apps

Third-party apps can retain account permissions. Periodically remove integrations you no longer use.

Treat unexpected codes as warnings

If you receive a login code or approval prompt you did not initiate, do not approve it. Open the provider’s official app or website independently and review account activity.

Your email account is part inbox and part identity recovery system. Secure it accordingly.

Editorial note: Technology changes quickly. Check current product interfaces and official documentation before making important account or security changes.