How to secure your email account.

Your email often receives password resets, sign-in alerts, bills, and private conversations. Protecting it first helps protect the other accounts that rely on it for recovery.

A laptop and phone with email, passkey, and authentication security objects
  1. Open the account through a trusted route

    Use the provider’s official app or type its known web address yourself. Do not begin from an unexpected security-alert link. If you suspect the device is infected or remotely controlled, switch to a trusted device before changing account settings.

  2. Replace reused or exposed passwords

    Use a password manager to create and store a unique password. NIST says the most important property of a password is length and recommends at least 15 characters when you must create one yourself.[1] Never reuse the new email password elsewhere.

  3. Enable the strongest practical MFA option

    Turn on multifactor authentication in the account’s security settings. MFA adds a second barrier when a password is compromised; NIST notes that some methods are more resistant to phishing than SMS or one-time codes.[2] Choose a phishing-resistant option if your provider offers one and you can use it reliably.

  4. Secure recovery methods and backup codes

    Confirm that every recovery email address and phone number belongs to you. Remove old or unfamiliar options. Generate new backup codes if prior codes may have been exposed, then store them somewhere separate from the email account.

  5. Review active sessions and connected apps

    Sign out devices or locations you do not recognize. Review third-party apps that can read mail, manage contacts, or access account data, and remove access you no longer need. Recheck the list after changing the password.

  6. Check forwarding, filters, and delegates

    An intruder may create a rule that forwards messages, hides security notices, or deletes replies. Review automatic forwarding addresses, inbox rules, filters, delegates, and send-as settings. Remove anything you did not configure and save screenshots if you need evidence.

  7. Protect the accounts that email can reset

    Prioritize banking, shopping, cloud storage, social media, and password-manager accounts. Change any reused credentials and enable MFA. If the compromise began with a deceptive message, the FTC advises contacting the company through a phone number or website you know is real—not through the message.[3]

Menu names differ by provider. Follow the current instructions in the official account settings and contact the provider’s support or fraud team if you cannot regain control.

Signs that deserve an immediate review

One sign may have an innocent explanation. Several together should move account review to the top of your list.

Unrequested reset messages
Password or MFA changes you did not start can indicate someone is testing or changing access.
Unknown sent mail
Messages, replies, or drafts you did not create may show that another person used the mailbox.
Missing security notices
Check trash, archive, filters, and forwarding if alerts disappeared unexpectedly.
Recovery details changed
An unfamiliar recovery address, phone number, device, or app connection requires prompt action.

Email security FAQ

Short answers for the decisions that commonly slow recovery.

Should I change the password before enabling MFA?

If you still control the account, do both during the same secure session: replace a reused or exposed password, then enable MFA and refresh backup codes. If access is uncertain, follow the provider’s official recovery process first.

Is text-message MFA better than no MFA?

NIST says MFA adds protection, while also noting that some methods—including SMS codes—are more vulnerable than phishing-resistant options.[1] Use the strongest reliable option your provider supports.

What if I clicked a phishing link?

Do not return through the message. Open the real provider directly, secure the account, and follow the FTC’s response guidance. If sensitive identity or financial information was shared, use the relevant official recovery resources.[3]

Sources

Primary government guidance used for this checklist.

  1. NIST — How Do I Create a Good Password?
  2. NIST — Multi-Factor Authentication
  3. Federal Trade Commission — How To Recognize and Avoid Phishing Scams