Secure your primary email account

Protect the account that can reset the passwords for most of your other online services.

Difficulty
Beginner
Time
About 15 minutes
Platforms
Any

Your primary email account is often the key to the rest of your digital life. Anyone who controls it may be able to reset passwords, impersonate you and hide security warnings.

Before you begin

Use a device you trust. If you think someone is monitoring your device or account, changing settings may alert them. Consider getting specialist help before proceeding.

Step 1: Set a unique password

Use a long, randomly generated password that you do not use anywhere else. Save it in a password manager rather than relying on memory.

Do not make small variations of an existing password. If another service exposes the original, those variations are easy to guess.

Step 2: Enable two-step verification

Open the provider’s security settings and enable two-step verification, which may also be called two-factor authentication or 2FA.

Prefer a passkey, security key or authenticator app when the provider supports one. SMS verification is still better than using only a password, but phone numbers can be vulnerable to account recovery and SIM-swap attacks.

Step 3: Store recovery codes

Download or print the one-time recovery codes. Store them somewhere separate from the device used for verification, such as an encrypted backup or physically secure location.

Never send recovery codes to someone who contacts you. A legitimate support agent should not need them.

Step 4: Review recovery details

Check the recovery email address and phone number. Remove anything you no longer control and secure the recovery email account too.

Review any security questions. Use answers that cannot be discovered from social media or public records, and store those answers in your password manager.

Step 5: Review active sessions and access

Sign out devices and sessions you do not recognise. Review:

  • applications with access to the account;
  • automatic forwarding rules;
  • filters that hide or delete messages;
  • delegated or shared mailbox access;
  • recent security events.

Unexpected forwarding rules are especially important because they can silently copy password-reset messages.

Step 6: Enable alerts and verify recovery

Turn on alerts for new sign-ins and security changes. Confirm that those notifications reach a device or address you control.

Finally, test that you can access your password manager, second factor and recovery codes. Avoid deliberately locking yourself out to test recovery.

Sources and further reading

This page was last reviewed on 26 July 2026