Secure the mail through which you recover other accounts

Password and 2FA are the beginning. Also check active sessions, messages and applications that can read mail.

2 min readFor execution: 15-20 minutes to review the settings
In this guide

The box stores correspondence, but often also acts as a key to other services. Whoever controls it can receive links to reset passwords and notices of changes. Therefore, it is worth a separate review of it.

Open the settings by a known address or application. If you just see signs of break-in, go first to reactions to suspicious sessionThe following text also serves to calmly check your account without a confirmed incident.

Secure login and recovery

Set a password that you do not use anywhere else, and add the supported 2FA or passkey method. Check the login test while keeping the current session until the action is confirmed.

Look at the backup address and phone number. Do you still have access to them? Is the backup box also secure? Removed number or old business account may not be an effective method of recovering access.

Keep the recovery codes offered by the supplier in a place available without this box. Mail sent to yourself will not help if the problem is not access to the mail.

Check who's logged in

Find a list of devices and the last activity. Collect your browser name, system, date and own actions. The location based on the IP address may not be accurate, especially with VPN or mobile network.

Log out unused devices. If you can’t explain a particular session, treat it as a suspect and check the rest of the settings. Just delete the session is not enough if someone still knows the password or added their own recovery method.

Check for transfer, filters and posting

This is an easy to skip part. The box can send copies of the messages to another address without a new intruder login. The filter can transfer security alerts to the wastebin or signify them as read.

Check the automatic transmission of the entire mail, the rules for selected messages and people with delegated access. In Gmail, transfer settings and filters are separate places – it is worth reviewing both.

If you see a foreign address, keep its name and rule information before removing access. This can help you report an incident. Explain an unknown rule with the administrator in the service box.

Browse the combined applications

An external mail client or application may operate on the basis of previously granted permissions. Password change does not always invalidate any such access. Delete unused integrations and unknown application passwords according to the supplier's instructions.

Finally, check the folder of the messages sent and deleted. When you have detected the interception, warn people who may have received a false request from you. Safe login restores control, but does not cancel the sent correspondence.