Disposable email Guides

How to secure your email account: the complete guide

Updated 23 September 2026

Your email address is the key to almost all your accounts: whoever controls it can reset your other passwords. Protecting it is the most cost-effective security step you can take.

Why email is target number one

The "forgot password" link on most websites sends a message to your email address. An attacker who gets into your inbox can therefore take over your social media, online shopping and sometimes more sensitive services within minutes. They also find invoices, scanned ID documents and private conversations there.

1. A long, unique password

2. Two-factor authentication is essential

Two-factor authentication (or two-step verification) adds a second proof on top of the password. Even if your password is stolen, it's no longer enough.

MethodProtection levelNote
PasskeyVery highPhishing-resistant, tied to your device
Physical security keyVery highPhishing-resistant, ideal for critical accounts
Authenticator appHighCodes generated offline on your phone
Phone promptHighDeny any request you didn't trigger
SMS codeMediumBetter than nothing, but vulnerable to SIM swapping

Passkeys, now offered by the major email providers, replace the password with a check on your device (fingerprint, face, device PIN) and can't be typed into a fake website.

3. Up-to-date recovery options

In your security settings, check:

4. Review access regularly

Once a quarter, go through these settings pages:

  1. Connected devices and sessions: sign out anything you don't recognise.
  2. Third-party apps with access to your account: remove those you no longer use.
  3. Forwarding rules and filters: this is crucial. A discreet attacker often adds a rule that forwards your mail to their address or deletes security alerts. Delete any rule you didn't create.
  4. Recent activity: most email services list recent sign-ins with their country.

5. Everyday habits

Signs your inbox has been compromised

What to do if you're hacked

  1. Change the password from a clean device, then sign out all other sessions.
  2. Turn on or reset two-factor authentication and generate new backup codes.
  3. Delete suspicious forwarding rules and filters, and check the recovery email and phone number.
  4. Use your provider's official recovery process if you can no longer sign in.
  5. Change the passwords of important accounts linked to that address, starting with banking and online shopping.
  6. Warn your contacts that they may have received fraudulent messages in your name.

Get a disposable address

Frequently asked questions

Is SMS two-factor authentication good enough?

It already stops the vast majority of attacks, but an attacker can hijack a phone number or trick you into sharing the code. An authenticator app or a passkey offers much stronger protection.

Should I change my email password regularly?

Current guidance favours a long, unique password combined with two-factor authentication, changed only if you suspect a compromise or leak. Frequent changes often lead people to choose weaker passwords.

How do I know if my address was in a data breach?

Breach-notification services such as Have I Been Pwned tell you whether your address appears in known breaches. Password managers built into browsers also flag compromised passwords.

Read next