If an attacker could take exactly one of your accounts, the smart choice is not your bank. It is your email. Banks have fraud departments, transaction limits, and reversal processes. Your inbox has none of that, and it holds something better than money: the "forgot password" pathway to everything else you own. This guide is a 15-minute audit of that one account, in the order that closes the most dangerous doors first.

The lock itself

The password on your email account must exist nowhere else on earth. Not a variant, not the same word with a different number. Reuse is the attack, and this is the one account where it is unforgivable. Then add the strongest second factor the provider offers, which for Gmail, Outlook, and most major providers now means a passkey or, at minimum, an authenticator app. As covered in the two-factor guide, your email deserves the top rung of whatever ladder is available.

The side doors

Recovery methods. Open your account's recovery settings and actually read them. Is the recovery phone number one you still control? A number you abandoned years ago may have been reissued to a stranger, and a recovery number in someone else's pocket is a master key you mailed away. Is the recovery email an old account you never secured, or worse, one from a defunct provider? Your security is the security of your weakest recovery path.

Active sessions. Every major provider has a page showing which devices are signed in and from where. Sign out anything you do not recognize, and anything you do recognize but no longer own, like the laptop you sold.

Connected apps. Over the years you have granted dozens of services access to your mailbox: schedulers, newsletter tools, that thing you tried once in 2019. Each grant is standing access that survives password changes. Revoke everything you do not actively use.

Forwarding rules and filters. This is the door people never check. An attacker who briefly controls your inbox often plants a quiet forwarding rule or a filter that copies "password," "code," and "verify" emails to an address they control, then leaves. Your password changes; the tap stays. Check your forwarding settings and filter list for anything you did not create. This single check has ended a lot of mysterious "how do they keep getting in" stories.

The 15-minute audit
  1. Password: unique to this account, long, stored in your manager.
  2. Second factor: passkey or authenticator app, not SMS if avoidable.
  3. Recovery phone and email: current, controlled by you, themselves secured.
  4. Active sessions: sign out everything unrecognized or retired.
  5. Connected apps: revoke all standing access you do not use.
  6. Forwarding rules and filters: delete anything you did not create.

Do it for the accounts you forgot count as email

The audit applies to every mailbox that can receive a password reset: the old address still listed as recovery on your bank, the ISP address from two houses ago, the secondary Gmail you made for spam that somehow became the recovery address for your Apple ID. An attacker does not care which inbox the reset link lands in. Neither should you.

Keep reading

That last point has a bigger version: every account you forgot you own is still holding your data and an old password:

Old Accounts You Forgot About Are a Liability

Dormant accounts are standing donations of your data to whoever breaches them next. How to find yours and shut the door.

← Back to all guides