The Account That Unlocks All the Others: How to Secure Your Email Account in 20 Minutes

You forget a password, click "forgot password" and a reset link lands in your inbox a few seconds later. You pick a new password and you're back in. It's so routine you barely notice it, but it means your main email quietly holds the keys to almost everything else. If you've ever wondered how to secure your email account properly, this is the place to start, and it takes about 20 minutes.

Prefer to listen? This post goes with this week's podcast episode, The Account That Unlocks All the Others, on Spotify and YouTube.

If You Read Only One Thing

Whoever controls your main email can reset the password on nearly every other account you have. Securing it first, with a unique password, strong two-step verification and a current way back in, protects more of your digital life than any other single change you can make this month.

Your Action Steps

  1. Block out 20 minutes this week and open the security settings of your main email account, the one most of your other accounts use.
  2. Change its password to a long one that you use nowhere else, created and saved by a password manager.
  3. Turn on two-step verification, and choose a passkey or an authenticator app over text message codes if your provider offers them.
  4. Read your recovery phone number and recovery email address, and update anything that is old or that you can no longer open.
  5. Download or write down your backup codes, and store them in your password manager or with your important papers.
  6. Review the list of devices and sessions signed in to your account, and sign out anything you don't recognize.
  7. Open your forwarding settings and your filters or rules, and remove anything you didn't set up yourself. Change your password if you find something.
  8. Write a short list of the 10 to 15 accounts that send their password resets to this email.

Why Your Email Matters More Than Your Bank Password

Most people put their strongest effort into their bank password. That makes sense, but it misses how accounts get taken over. When someone wants into your bank, your Amazon account, your Apple or Google account or your phone carrier, the easiest path usually isn't guessing that password. It's clicking "forgot password" and waiting for the reset link.

That link goes to your email. So if someone is sitting in your inbox, every one of those resets arrives right where they are. Your email isn't one account among many. It's the account that unlocks all the others, and whoever controls it can take over the rest one reset at a time.

The good news is that learning how to secure your email account doesn't require technical skill. It's seven settings, done in order, because each one makes the next one safer.

Step One: A Password Used Nowhere Else

Your email password should be long and used for nothing else. The most common way accounts get taken over isn't clever hacking. It's a password that leaked from some other website years ago and gets tried everywhere. If your email shares a password with an old shopping site, your email is only as safe as that site was.

The simplest way to have a long, unique password is to let a password manager create it and remember it for you. If you don't use one yet, your email is the right first password to move in.

Step Two: Two-Step Verification, the Strong Kind

Two-step verification means that even with your password, nobody gets in without a second proof that it's you. Turn it on, then look at which method you're using, because they aren't equal.

  • Text message codes are better than nothing, but they're the weakest option. A phone number can be moved to someone else's phone if a criminal talks a carrier into it.
  • An authenticator app on your phone is stronger, because the codes stay on your device.
  • A passkey, where your phone or computer confirms it's you with your face, fingerprint or device PIN, is stronger still and often easier to use.

If your email provider offers a passkey or an authenticator app, choose one of those.

Step Three: Your Recovery Phone and Recovery Email

This is the step almost everyone skips, and it's the one I care about most. Your email has its own way back in: a recovery phone number and usually a recovery email address. If you're ever locked out, that's where the help goes.

Open your settings and read them slowly. Is that still your phone number? Is the recovery email an address you still have and can still open? It's common to find a recovery email pointing at an old work address or an internet provider account that closed years ago. That's a door with the key thrown away, or worse, a key someone else could pick up.

Step Four: Backup Codes, Stored Where You Can Reach Them

When you turn on two-step verification, most email providers offer a set of backup codes. They're your way in if your phone is lost, broken or stolen. Keep them somewhere you'll be able to find on a bad day:

  • inside your password manager, or
  • printed and kept with your important papers.

Not in a file called "codes" in your downloads folder, and not only on the phone you might lose.

Step Five: Where You're Signed In

Your email account can show you every phone, computer and browser currently signed in. On most services it's in the security section, under something like "your devices" or "recent activity." You should recognize every entry. Sign out the old laptop you gave away, the phone you traded in and anything unfamiliar. If something truly looks wrong, change your password, then sign out of everything except the device in your hand.

Step Six: Forwarding Rules and Filters

This is the part most people have never heard of. When criminals get into an email account, they often don't change the password, because that would tip you off. Instead they quietly add a forwarding rule that sends copies of certain messages to an address they control, or a filter that moves messages from your bank straight to the trash or the archive so you never see the alerts. Then they wait and read.

Picture this: you realize you haven't seen a statement from one of your accounts in a while. Everything else in your inbox looks normal. Then you find a filter sending every message from that company to an archive folder you never open, and you didn't create it. That filter would be the only visible sign that someone had been in your account.

So look for two things in your settings: forwarding, and filters (sometimes called rules). You should recognize every forwarding address and every rule. If you didn't set it up and don't know why it's there, remove it and change your password.

Step Seven: The Accounts That Depend on This One

Last, write a short list of the accounts that send password resets to this email: your bank and credit cards, your phone carrier, your Apple or Google account, your password manager and anywhere that holds your photos or money. Ten or fifteen is plenty.

The list does two jobs. It shows you how much rests on this one account, which makes the first six steps feel worth it. And if the worst ever happens, it's your to-do list for the first hour: the accounts to check and secure first.

The Habit That Goes With the Settings

Settings are half of it. The other half is a habit. Many email takeovers begin with a message that looks like it's from your email provider: your storage is full, there's a problem with your account, please sign in to confirm. The page it takes you to can look perfect.

The rule I use is simple: verify the request, not the page. Don't judge whether the page looks real. Ask whether the request makes sense. If your provider needs something from you, go to your account the way you always do, by typing the address or opening the app yourself, and see whether the same message is waiting there. If it isn't, the request wasn't real, however good the page looked.

Start With Your Recovery Settings

Block out twenty minutes this week and work through the seven steps in order. If you only have five minutes today, do step three: check your recovery phone number and recovery email. It's the fastest protection you can give the account that protects everything else.

If you'd like the whole safety side of your digital life laid out step by step, that's what my Digital Safety guide is for. It's month two of the Digital Life Management System and covers passwords and the vault that holds them, two-step verification that works, recovery set up before you need it and what to do in the first twenty minutes when something has gone wrong. It's a PDF you get at purchase, $49, with a seven-day guarantee.

And if you know someone who still uses the same password everywhere, send them this post. It may be the most useful thing you share this month.

Resources Outside Haven Smith & Company

Haven Smith & Company Resources

Ashley, Founder, Haven Smith & Company

Free · Two minutes

Where does your digital life stand?

Nine questions on organizing, protecting and preparing. You get your level and the one thing worth sorting out first.

Take the free quiz

Free · Nine questions · No account needed

Previous
Previous

Your Domain Name Belongs in Your Estate Plan

Next
Next

The Login Page Was Real. The Request Was Not.