HomeGuidesIf your email falls, everything falls

If your email falls, everything falls

Why this one account outranks the rest

Think about what happens when you forget a password. You click “reset”, and a link arrives in your e-mail. Your bank does it, your employer does it, every shop and social account does it. Your inbox is therefore not one account among many — it is the key that opens the others, and most people protect it with less care than their streaming subscription.

This guide is about giving that single account the best protection you have. It takes an evening, none of it is clever, and boring is the goal. It also does not depend on your threat model: whoever you are worried about, this is the account they would want. Everything else in your digital life gets safer as a side effect.

Step 1: A password you cannot remember

The password on your e-mail should be one you could not recite if someone woke you at three in the morning: long, random, and used nowhere else. That means a password manager, because no one can remember such a thing. For a start, the manager already built into your browser or phone is perfectly adequate — the point is to stop reusing, not to pick the perfect tool.

While you are in there, check whether your current e-mail password appears in a known breach. Most managers and browsers will tell you. If it does, change it tonight rather than next week.

Step 2: Two-step verification worth having

Turn on two-step verification, and choose the method deliberately, because they are not equal. A passkey or a hardware security key is the strongest and cannot be phished. An authenticator app on your phone is very good. A code by text message is the weakest, because a determined attacker can persuade a mobile operator to move your number onto their SIM — but it is still far better than nothing, so if it is the only method you will actually keep, keep it.

Then do the part everybody skips: save the backup codes somewhere you can reach when your phone is lost, stolen or wiped. Printed on paper in a drawer is a perfectly respectable answer.

Step 3: Close the back doors

An attacker who cannot guess your password looks for the recovery route instead. Open your account settings and work through it like a checklist. Is the recovery address one you still control, or an old work address someone else may have inherited? Is the recovery phone number still yours? Are there security questions whose answers can be found in twenty minutes of searching — your mother’s maiden name, your first school, the name of your dog? If your provider lets you delete them, delete them. If not, answer them with random text stored in your password manager.

Step 4: Read the delegation list

This is the step that actually catches intrusions. In your settings, find forwarding, filters and connected applications. A quiet forwarding rule that copies everything to an address you do not recognise is the classic signature of a compromised inbox — and it survives a password change. So do filters that move bank or security messages straight into the archive so that you never see them.

Then read the list of apps and services with access to your mail. Most people find several they have long forgotten: an old calendar tool, a newsletter service, a mail app on a phone they no longer own. Remove everything you do not actively use. Every entry there is a spare key held by somebody else.

Step 5: Look at who is signed in

Every major provider shows recent sessions and devices. Read the list. Sign out anything you do not recognise and anything you have not used in a year. If a laptop you sold two years ago is still listed, this is the moment.

Step 6: What your provider can read

E-mail is not end-to-end encrypted. The connection between you and your provider is encrypted, usually the hop between providers too, but the message rests on their servers in a form they can read — which is why they can search it for you, and why a court order can reach it. That is a structural property of e-mail, not a setting you can flip.

The honest conclusion: an inbox is good enough for ordinary correspondence and the wrong place for your most sensitive conversations, which belong in a properly encrypted messenger — our guide to encrypted messaging without the myths covers how to choose one. It is also the wrong filing cabinet for scans of your passport, contracts and photographs of documents. An archive going back nine years is one break-in away from being somebody else’s copy.

Step 7: Stop being one address

A quiet but powerful habit: do not use one address for everything. Keep one for banks, government and work, and never publish it anywhere. Use a second for shops, newsletters and registrations. Many providers now offer aliases or “hide my address” features that make the split nearly effortless.

Most providers also support a simpler trick that needs no setup at all: a plus tag. Mail sent to yourname+shop@example.com arrives in the ordinary inbox at yourname@example.com, but you can filter on the tag, and if that address later turns up in a leak or in unrelated marketing, you know exactly which company let it out. It is a genuinely useful audit tool. Be honest about its limits, though: anyone can strip the tag back to your real address, some sites refuse the plus sign outright, and the part before the tag is still the same identity, so a plus tag reveals the source of a leak rather than preventing one. Real aliases and separate addresses do the protective work; plus tags do the detective work.

The benefit of splitting is twofold. When a shop is breached, the address that leaks is not the one guarding your bank. And because a shared address is one of the identifiers used to match records between databases, splitting it makes the work of the data brokers measurably harder.

Step 8: The habit that beats every setting

Almost no inbox is lost to clever hacking. It is lost to a convincing message: your account will be closed, a payment failed, a document is waiting — please log in. The page looks exactly right, because copying a login page takes ten minutes.

One habit defends against nearly all of it: never log in from a link. If a message says something is wrong with an account, open the app or type the address yourself and look. A second habit: treat urgency as a warning sign rather than a reason to hurry, since urgency is the tool being used on you. And if a page asks for your two-factor code after you followed a link, stop completely — that is what a live attack looks like.

If you think it has already happened

Order matters. Change the password, then sign out all other sessions, then check forwarding rules and filters, then connected apps, then the recovery address and phone. Done in the wrong order, you can lock out an intruder who has already arranged a way back in. Afterwards, tell the people whose messages sat in that inbox: the attacker’s next move is usually to write to your contacts as you.

The evening, in order

  1. A long, unique password on your e-mail, kept in a password manager.
  2. Two-step verification on — passkey or app if you can, text message if that is what you will really keep.
  3. Backup codes saved somewhere physical.
  4. Recovery address, recovery phone and security questions checked.
  5. Forwarding rules and filters read; anything you did not create deleted.
  6. Every connected app you do not use removed.
  7. Unknown and unused devices signed out.
  8. Addresses split: one private, one disposable.
  9. One rule adopted for good: never log in from a link.

What this doesn’t solve

A hardened inbox does not make e-mail private from your provider, does not protect a message once it lands in somebody else’s careless account, and will not save you if the device you type on is already compromised. It cannot undo what has already leaked from a company you trusted.

What it does is shut the door that opens all the others. Of all the security work available to you, this evening has the best return — and unlike most of it, you only have to do it once.

Get the weekly briefing

Five things worth your attention — censorship, privacy, algorithms and digital rights. One email a week, no noise.

We’ll send you a confirmation email first. No tracking, no sharing, unsubscribe in one click. See our Privacy Policy.

Must Read

spot_img