Good to know
Using Gmail, Outlook, Yahoo or iCloud?
Every step below applies to any email account — but the exact settings live in different places per provider. For the precise menus and screens, follow your provider's guide:
1. Use a Strong, Unique Password
What makes a strong password?
- Length over complexity — Aim for 16+ characters. A long passphrase like
correct-horse-battery-stapleis stronger thanP@ssw0rd! - No personal information — Avoid names, birthdays, pet names, or anything findable on social media
- No dictionary words on their own — Combine random words or use a generated password
- Never reused — Every account should have a different password
Good to know
2. Enable Two-Factor Authentication (2FA)
Types of 2FA (from strongest to weakest)
- Hardware security keys (FIDO2/WebAuthn) — Physical USB or NFC keys like YubiKey. Phishing-proof and the gold standard for security. Required for Google Advanced Protection.
- Authenticator apps (TOTP) — Apps like Google Authenticator, Authy, or Ente Auth generate time-based codes. Much stronger than SMS and work offline.
- SMS codes — Better than nothing, but vulnerable to SIM swapping attacks where an attacker convinces your carrier to transfer your number to their SIM card.
- Email codes — The weakest form. If your email is compromised, the attacker receives the codes too.
Important
3. Verify and Secure Recovery Options
Checklist
- Recovery phone number — Make sure it is your current number. Remove old numbers you no longer control.
- Backup email address — Use a separate, secure email (not the one you are securing). Ideally one with its own 2FA enabled.
- Security questions — If your provider still uses these, treat the answers like passwords. Do not use real answers that could be found on social media. Store fake answers in your password manager.
- Recovery codes — Most providers generate one-time backup codes when you enable 2FA. Download and store these securely (password manager or printed in a safe).
- Recovery contacts/keys — Apple and some providers offer recovery contacts or recovery keys. Set these up if available.
Important
4. Audit Third-Party App Access
What to look for
- Apps you do not recognise or remember authorising
- Apps you no longer use
- Apps with broad permissions ("read, send, and delete email" when they only need to read)
- App-specific passwords you created for old devices
5. Check Forwarding Rules and Filters
What to check
- Forwarding addresses — Remove any you did not set up
- Filter rules — Look for rules that auto-delete, auto-archive, or redirect emails (especially ones targeting security alerts, bank notifications, or password resets)
- POP/IMAP access — Disable if you do not use a desktop email client. Attackers can use IMAP to sync your entire mailbox.
6. Review Active Sessions and Devices
Good to know
7. Protect Yourself from Phishing
Golden rules
- Never click login links in emails — Always navigate directly to the website by typing the URL or using a bookmark
- Check the sender address carefully — Phishing emails often use look-alike domains (e.g.,
support@g00gle.cominstead ofsupport@google.com) - Be suspicious of urgency — "Your account will be suspended in 24 hours" is a classic phishing tactic
- Hover before clicking — On desktop, hover over links to see the actual URL before clicking
- Use hardware security keys — FIDO2 keys are phishing-proof because they verify the domain cryptographically. Even if you enter your password on a fake site, the key will not authenticate.
8. Set Up Ongoing Monitoring
- Enable login alerts — Most providers can notify you of sign-ins from new devices or locations
- Monitor haveibeenpwned.com — Sign up for breach notifications to be alerted if your email appears in a data breach
- Review account activity monthly — Schedule a quick monthly check of login history, connected apps, and forwarding rules
- Keep your devices updated — Enable automatic updates on your phone, computer, and browser. Unpatched software is a common attack vector.
- Use a secure DNS provider — Services like Quad9 (9.9.9.9) or Cloudflare (1.1.1.1 for Families) can block known malicious domains before you even reach them
Quick Security Checklist
- ☐ Strong, unique password (16+ characters, not reused)
- ☐ Two-factor authentication enabled (preferably authenticator app or hardware key)
- ☐ Recovery phone and backup email verified and current
- ☐ Recovery/backup codes saved securely offline
- ☐ Unfamiliar third-party apps revoked
- ☐ No unexpected forwarding rules or filters
- ☐ POP/IMAP disabled if not in use
- ☐ All unrecognised devices/sessions removed
- ☐ Login alerts enabled
- ☐ Signed up for breach notifications at haveibeenpwned.com
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers



