Nobody sets out to run an insecure inbox. It happens gradually, through defaults nobody revisited and
shortcuts that made sense at the time.
The good news is that most of the fixes take minutes rather than an afternoon. Here are the ones that
actually change the outcome.
1. Stop reusing the password on your main account
If the password protecting your inbox has been used anywhere else, treat it as already compromised. Leaked
credentials get tested automatically across thousands of services, and reuse is the reason those tests
succeed.
Length matters more than symbols, which is why the current federal guidance on passwords favours long
passphrases over complicated short ones. Give the inbox a password that exists nowhere else and store it in
a password manager.
2. Turn on two-factor authentication properly
Two-factor authentication is the single most effective change available, but the method matters. Codes sent
by text can be intercepted through SIM swapping, where an attacker persuades a mobile provider to move
your number.
Use an authenticator app or a hardware key instead. Both take a few minutes to set up and remove the
weakest link.
3. Check your recovery settings
Recovery options are a back door that most people set once and never look at again. An old address you no
longer control, or a phone number belonging to someone else now, undoes everything else you have done.
Open the settings, read what is listed, and remove anything you would not want used to reset your account.
4. Slow down on anything urgent
Urgency is the standard tool of anyone trying to take your credentials. A warning that your account will be
closed, a payment has failed or access must be verified immediately is designed to stop you checking.
Open the service directly in your browser instead of clicking the link. If the message was genuine, the notice
will be waiting for you there. The FTC’s online security guidance covers the warning signs in more detail.
5. Reconsider who reads your messages
Free services have to make money somewhere, and the traditional answer was advertising built on user
data. Even where message scanning has been scaled back, metadata about who you contact and when is still
valuable.
An encrypted mail provider funded by subscriptions works differently. End-to-end encryption means the
provider cannot read what it stores, so there is no profile forming in the background.
6. Clear out accounts you forgot about
Every dormant registration tied to your address is another place your details might sit in an unpatched
database. Search your inbox for old sign-up confirmations and close what you no longer use.
It is tedious, but it shrinks the surface area considerably, and you only have to do it properly once.
7. Separate the important from the ordinary
Using one address for banking, work, shopping and newsletters means a single compromise reaches
everything. Splitting them limits the damage.
A dedicated address for financial and official accounts, kept out of mailing lists entirely, is a small amount of
effort for a meaningful reduction in exposure.
The short version
Unique password, proper two-factor authentication, clean recovery settings and a moment of hesitation
before you click. That covers most of what goes wrong.
Everything else on this list is worth doing, but if you only get through the first two, you have already closed
the routes that catch most people.

