Audit and harden a personal or small-business email account.
Email is often the master recovery channel for an online identity. Securing it means more than changing a password: review recovery contacts, active sessions, trusted devices, forwarding rules, filters, delegated access, connected apps, aliases, and the device and phone number that can regain control.
Use a trusted recovery environment
If compromise is suspected, perform recovery from a device you reasonably trust and navigate directly to the provider. Secure the device, password manager, phone carrier, and recovery email as linked control points. Contact workplace administrators for managed accounts rather than changing policy-controlled settings blindly.
Audit every access path
- Long unique password stored safely and no reused variants
- Strong multi-factor method, backup factors, and protected recovery codes
- Recovery email, phone, security questions, and trusted contacts
- Active sessions, devices, application passwords, API tokens, and connected apps
- Forwarding addresses, mailbox rules, filters, delegates, aliases, and send-as access
- POP or IMAP clients, third-party mail apps, backup, retention, and admin roles
Strengthen authentication thoughtfully
| Method | Strength | Recovery need |
|---|---|---|
| Authenticator or passkey | Reduces dependence on SMS and password alone | Backup device or recovery code |
| Security key | Strong phishing resistance when supported | Registered spare and provider recovery |
| SMS code | Better than password alone in many contexts | Carrier protection and alternate factor |
Harden and verify the mailbox
- Update the recovery device and browser.
- Change an exposed or reused password.
- Add strong MFA and store recovery safely.
- End unfamiliar sessions and remove unknown apps.
- Inspect forwarding, filters, delegates, and sent mail.
- Test alerts and recovery without locking yourself out.
Find persistence after takeover
- Attacker-created forwarding rule
- Unknown app with ongoing mailbox permission
- Recovery address changed to an unfamiliar account
- Reply-to or signature altered for payment fraud
Create an external recovery card
Store provider name, account identifier, official recovery address, MFA methods, recovery-code location, trusted backup contact, carrier route, managed-account administrator, and last audit date somewhere secure that does not depend solely on the email account itself.
Continue with the next decision
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- CISA Secure Our World Official public cybersecurity guidance supporting strong passwords, multi-factor authentication, updates, and phishing recognition.