Skip to main content

Guide

Your email account is the master key

Your inbox can reset almost every other password you own, so it is the one account worth securing first and properly.

If someone gets into your email, they do not need to break into your bank. They open its password-reset page, receive the link, and set a new password. Then they delete the notification.

That is why this is the first guide in the set. Everything else assumes the inbox is still yours.

Do these four things tonight

  1. 1Set a unique password you have never used anywhere else, at least four unrelated words long. Length beats symbols.
  2. 2Turn on two-factor authentication and choose an app or a hardware key over SMS if the provider offers the choice.
  3. 3Write down the recovery codes and store them somewhere offline — not in the inbox itself, and not in a screenshot in your photos.
  4. 4Open your account's list of active sessions and signed-in devices, and sign out anything you do not recognise.

Check the rules hiding in your settings

  • Forwarding: a single rule can copy every message to an address you do not control, and it survives a password change.
  • Filters: a filter can move security warnings and bank messages out of the inbox automatically, so you never see them.
  • Delegated access: another address may be able to read your mail while looking like a normal setting.
  • Recovery email and phone: if these point somewhere you do not recognise, a reset is easier for someone else than for you.

Keep it that way

  • Never reuse this password anywhere. Reuse is how an unrelated breach turns into an inbox takeover.
  • Treat every unexpected login warning as real until you have checked the sessions list yourself.
  • When you change a password, change it here first — because a reset link for anything else lands here.

Frequently asked questions

Is two-factor authentication by SMS worth having?

Yes, it is far better than nothing, and it removes the most common attacks. An authenticator app or a hardware key is stronger, because SMS can be intercepted or a number can be transferred.

I cannot find the forwarding rules in my settings. Does that mean there are none?

No. Many providers hide them under Settings, then Forwarding, or under Filters, and some only show them on the web version rather than in the app. Check both.

Should I save the recovery codes in my password manager?

That is acceptable if the manager itself is protected by strong two-factor authentication and you can still get in from a second device. Otherwise print them.

Written by The BaitScan team

Last updated September 16, 2026

Results are automated risk estimates based on public indicators and heuristics.