Disposable email › Guides
How to secure your email account: the complete guide
Updated 23 September 2026
Your email address is the key to almost all your accounts: whoever controls it can reset your other passwords. Protecting it is the most cost-effective security step you can take.
Why email is target number one
The "forgot password" link on most websites sends a message to your email address. An attacker who gets into your inbox can therefore take over your social media, online shopping and sometimes more sensitive services within minutes. They also find invoices, scanned ID documents and private conversations there.
1. A long, unique password
- Unique: never used anywhere else. This is the most important rule, because breaches of other sites are used to try the same credentials on your email.
- Long: at least 16 random characters, or a passphrase of several unrelated words.
- Stored in a password manager, built into your browser or phone, rather than in a file or notebook.
2. Two-factor authentication is essential
Two-factor authentication (or two-step verification) adds a second proof on top of the password. Even if your password is stolen, it's no longer enough.
| Method | Protection level | Note |
|---|
| Passkey | Very high | Phishing-resistant, tied to your device |
| Physical security key | Very high | Phishing-resistant, ideal for critical accounts |
| Authenticator app | High | Codes generated offline on your phone |
| Phone prompt | High | Deny any request you didn't trigger |
| SMS code | Medium | Better than nothing, but vulnerable to SIM swapping |
Passkeys, now offered by the major email providers, replace the password with a check on your device (fingerprint, face, device PIN) and can't be typed into a fake website.
3. Up-to-date recovery options
In your security settings, check:
- the phone number and recovery email: they must be current and belong to you;
- the backup codes for two-factor authentication: print them or keep them in your password manager;
- security questions, if the service still uses them: the answers shouldn't be findable on your social media.
4. Review access regularly
Once a quarter, go through these settings pages:
- Connected devices and sessions: sign out anything you don't recognise.
- Third-party apps with access to your account: remove those you no longer use.
- Forwarding rules and filters: this is crucial. A discreet attacker often adds a rule that forwards your mail to their address or deletes security alerts. Delete any rule you didn't create.
- Recent activity: most email services list recent sign-ins with their country.
5. Everyday habits
- Never type your password after clicking a link in an email: open the site or app yourself.
- Deny approval requests you didn't start: repeated prompts often mean someone has your password.
- Keep your phone, computer and browser updated.
- Avoid public computers for email; if you must, sign out and save nothing.
- Give out your address less often: a disposable address for one-off sign-ups reduces leaks and targeted phishing.
Signs your inbox has been compromised
- Contacts receive messages you didn't send.
- Messages appear read, moved or deleted without you doing it.
- You receive unexpected sign-in or password-change alerts.
- Password resets from other websites arrive that you didn't request.
What to do if you're hacked
- Change the password from a clean device, then sign out all other sessions.
- Turn on or reset two-factor authentication and generate new backup codes.
- Delete suspicious forwarding rules and filters, and check the recovery email and phone number.
- Use your provider's official recovery process if you can no longer sign in.
- Change the passwords of important accounts linked to that address, starting with banking and online shopping.
- Warn your contacts that they may have received fraudulent messages in your name.
Get a disposable address
Frequently asked questions
Is SMS two-factor authentication good enough?
It already stops the vast majority of attacks, but an attacker can hijack a phone number or trick you into sharing the code. An authenticator app or a passkey offers much stronger protection.
Should I change my email password regularly?
Current guidance favours a long, unique password combined with two-factor authentication, changed only if you suspect a compromise or leak. Frequent changes often lead people to choose weaker passwords.
How do I know if my address was in a data breach?
Breach-notification services such as Have I Been Pwned tell you whether your address appears in known breaches. Password managers built into browsers also flag compromised passwords.
Read next