Securing the Account Everything Depends On

Time: about thirty minutes now, then ten minutes a year. Repeat: on the day you replace your phone.

Secure this account before you secure anything else

Do the mailbox first, and finish it before you start hardening your bank or your work login. Every one of those accounts has a button that mails a reset link, and the mailbox is where the link lands. Whoever can read it can become you almost everywhere, without knowing a single one of your other passwords.

That is the whole reason this page exists. It is not a general list of good habits; it is five settings, in the order that closes the biggest hole first. If you keep more than one mailbox, the strongest settings belong on the one that holds the recovery links, and the others follow later. Deciding which one that is takes about a minute once you have read what each extra account costs to run.

Give the mailbox a password that exists nowhere else

Generate a long random password in a password manager and let the manager remember it, rather than inventing something you can type from memory.

A password you also used on a shop or a forum is a password whose safety was decided by that shop or that forum, not by you. Reuse is the one mistake that turns somebody else's bad night into yours, and it is the cheapest one to stop making: you only have to do it properly once, for this account, today.

The manager needs a master password you can remember, and that one lives in your head and on paper. Write it down, put the paper somewhere you would not lose in a fire or a move, and stop feeling clever about not writing it down. A password nobody can reconstruct after you are hit by a bus is a problem you have handed to somebody else, which is a large part of what a mailbox leaves behind.

Move the second factor off text messages

Switch the second step from a code by text message to an authenticator app or a hardware key, and keep the text message only where nothing else is offered.

Codes by text fail in three concrete ways. A number can be moved to a new SIM by somebody who convinces the carrier they are you, and the codes then arrive on their phone. A number stops receiving anything when you travel, lose signal or land somewhere your roaming does not work. A number you give up when you change carrier keeps working for the next person who gets it.

Say the rest out loud as well: a second factor is not a wall. It does not help if you type both the password and the code into a convincing copy of the login page, because the page passes them straight through while they are still valid. It does not help against something already running on your computer. It does nothing at all about an app you authorised years ago that still holds a token and reads your mail without logging in, which is a separate list you have to check.

Add a passkey, then add the second one the same day

If your provider offers a passkey, enrol it, and before you close the page enrol a second one on another device or print the backup codes.

A passkey removes the password from the login, which removes the most common way in. It also concentrates your access in one object. A phone that ends up in a river takes the passkey with it, and the recovery path you never set up is the one you will need at that moment, in a hurry, from a borrowed laptop. Five minutes now against a week of forms later is not a close call, and the four routes back in, along with the way each of them fails, are laid out in the recovery options worth setting up.

Sign out of every device you are not holding

Find the list of active sessions or devices in the account settings and end every session that is not the one you are using right now.

This is the cheapest security action there is and almost nobody performs it. Sessions accumulate: a hotel computer, an old tablet, a phone you sold, a browser at a job you left. Each one is a way in that survives without your password, because it was already trusted before you changed anything.

Four moments make it mandatory rather than tidy. When a device leaves your hands for good, sold or given away. When you have signed in on a machine that is not yours. When a phone is lost or stolen, even if it turns up later. And at the first suspicion that somebody else has been in the account, where the order matters so much that the whole repair is built around it.

Read the sign-in notices instead of clearing them

When a message says a new device signed in, open it and check three things: the time, the place and the device. If any one of them is wrong, treat it as real.

Do not use the link in that message. Fake sign-in warnings are one of the oldest lures going, and they work precisely because they arrive when you are already alarmed. Type the provider's address yourself, or use the bookmark you made when nothing was on fire, and check the session list from inside the account.

Point these notices at an address you actually read. A security alert delivered to a mailbox you open twice a year is a smoke detector in the garage.

Undo the four settings that quietly break everything

Go through these four now, because each one turns a good setup into a locked door with you outside it.

Honest answers to security questions. Your mother's real maiden name is a matter of public record; store a random string in the password manager instead and answer with that.

A recovery address that no longer exists. This is the single most common way people lose an account permanently, and it costs nothing to check.

The second factor living on the same phone as your only mailbox. Lose the phone and you lose both halves at once.

A throwaway address used as the recovery address for something you care about. The inbox this site hands out is built for one-off signups and deletes itself on schedule; that is the feature, and it is exactly why it must never be the address that gets your account back.

The checklist

  • Set a unique random password from a manager, and keep the master password on paper in a place you would not lose in a move.
  • Replace text-message codes with an authenticator app or a hardware key, and keep the phone number only as a last resort.
  • Enrol a second passkey or print backup codes the same day you enrol the first.
  • End every active session except the one in front of you, and repeat it any time a device leaves your hands.
  • Once a year, confirm the recovery address and phone number are still yours, and that security notices arrive somewhere you read.

Read next

All guides