goJumboGPT

Security Signing in safely: 2FA, passkeys and account recovery

Your email account is the master key: lock it properly

Why the email account is the single most valuable target, the settings that stop a silent takeover, and the hidden forwarding rules attackers leave behind.

8 min read How we write

The short answer

  • Your email account can reset the password on nearly every other account you own, which makes it a more valuable target than your bank login.
  • The core of the job is a long unique password, a passkey or authenticator app rather than text codes, and recovery details that are current and themselves protected.
  • Changing your password does not remove a forwarding address, a filter rule or a connected app, which is exactly why attackers leave those behind.
  • A filter that quietly archives anything mentioning verification codes or your bank is the trick that keeps you from seeing your own security alerts.
  • Aliases and plus addressing keep your real address out of the shops, forums and newsletters that leak it.
  • If you find a rule you did not create, treat it as a live break in: change the password, sign out everything, remove the rule, then work down the accounts that reset through this mailbox.

Your email account is the account that can reset every other account you own, which makes it worth more to an attacker than your bank login. Lock it in this order: a long unique password that exists nowhere else, a second factor that is not a text message, recovery details that are current and protected, and then a sweep of the four places a takeover hides after the password is changed. That last part is the step almost everybody skips, and it is the reason people get robbed twice.

Why email sits at the root of everything

Think about what happens when you forget a password. You click forgot password, a link arrives in your inbox, you set a new one. The service never verified that you are you. It verified that you control the mailbox. That is the security model of most of the internet, and it puts your email account above your bank, your cloud storage and your tax portal in the hierarchy, whether you think of it that way or not.

The mailbox is also an archive: years of statements, an insurance claim with a scan of your passport, delivery confirmations with your address, and the names of everyone you deal with. An hour of reading that is enough to impersonate you convincingly, which is how most real cases of identity theft begin.

And it is a trust machine. A message from your real address, in your real thread, asking a colleague to change bank details works far better than any fake. Attackers often leave the account looking untouched for weeks for exactly that reason.

The front door: password and second factor

The password needs two properties. Long, because length is what defeats cracking, and used nowhere else, because reused passwords are harvested from other companies' breaches and tried everywhere. Four or five random words is easier to type on a phone than a mangled short password and far stronger. Storing it in a password manager is fine, provided the manager is not protected by that same password.

Then add a second factor, and be specific about which one. Any second factor stops the automated attack that uses passwords bought in bulk. Only a passkey or a hardware key also stops a convincing fake sign-in page, because those check the real domain before answering, and the trade offs are laid out in two factor authentication explained. For email, prefer a passkey where it is offered, otherwise an authenticator app with a working backup. Text codes are the weakest option, since a number can be ported away from you, and still much better than nothing.

Save the recovery codes the moment you enable any of this, somewhere physical. Losing the second factor is a far more common disaster than being hacked.

One setting quietly undoes all of it: legacy app passwords, the long codes some providers issue so an old mail program can sign in without the second factor. Every one still in the list is a key that bypasses your protection. Delete the ones you no longer use.

The hidden rules: forwarding and filters

This is the part worth reading twice. When someone gets into a mailbox, the professional move is not to read it and leave. It is to set up a copy that survives you fixing the problem.

The classic is a forwarding address. Every message arriving in your inbox is silently copied to an address they control. You change your password, congratulate yourself, and the copies keep flowing, including reset links for every other account you own.

The subtler version is a filter rule: any message containing verification code, security alert, reset your password or the name of your bank gets marked as read, archived or deleted. The intruder triggers a reset on your bank, collects the code through the forwarding rule, and you never see the alert because your own mailbox hid it. Some providers also allow a send mail as address, which lets someone send messages that appear to come from you without touching your inbox.

Go and look now, before anything is wrong. The settings sit under forwarding, filters and blocked addresses, or rules, and business mail systems may hold separate rules on the server that your desktop program never shows. Read every rule. A rule called Newsletters that quietly deletes anything mentioning your bank is a rule you did not write.

Sessions, connected apps and recovery details

Active sessions. Your provider lists every device and browser signed in, with a rough location and a last used time. Locations are often wrong by a city or two, so judge by device type and time rather than the map pin. Sign out all devices after changing the password, not before, or the intruder simply carries on.

Third party app access. Over the years you granted a calendar tool, a newsletter service or a scanner app access to your mail, and some of those permissions include reading every message. Each entry is an independent way in that needs no password and no second factor. Revoke what you do not use and recognize. The same logic covers your browser, where an extension with permission to read every page is reading your webmail too.

Recovery details. An attacker who cannot pass your second factor has another option: claim to be you and ask for the account back. That process runs on your recovery phone number and recovery email address, so those are part of the lock rather than an afterthought.

Check three things. The recovery number should be one you still control, which sounds obvious until you remember the number you gave up two moves ago and which has since been reissued to a stranger. The recovery email should itself have a second factor, because a weak backup mailbox makes your strong main one irrelevant. And nothing in either list should be unfamiliar, since adding a recovery address is a standard way of preparing a takeover. Account recovery done before you need it covers the setup.

If text messages appear anywhere in this chain, protect the number itself. Ask your carrier for a port freeze or an account PIN, so nobody can move your number to their own SIM by calling a call center and sounding confident.

Aliases and plus addressing shrink the target

The other half of the job is giving out your real address less often. Every shop, forum and newsletter holding it is a place it can leak from, and a known address is the starting point for both credential stuffing and targeted phishing.

Plus addressing is the quick version. Many providers deliver anything before a plus sign to the same inbox, so yourname+shopname@example.com arrives normally and tells you who leaked it when the spam starts. It is also trivially stripped back to the base address, so treat it as leak tracing rather than protection, and expect some sites to reject the plus sign outright.

Aliases are stronger: separate, unrelated addresses that deliver into the same mailbox and can be switched off one at a time. Masked or relay addresses from password managers do the same with random names. Either way, the useful structure is three tiers.

TierUsed forGiven outIf it leaks
Private addressBank, government, tax, insurance, workNever posted, never used to sign up for anythingSerious, but very unlikely
Everyday addressFriends, family, real correspondencePeople you knowSpam, and phishing that names you
Alias per serviceShops, forums, newsletters, trialsFreelySwitch that alias off and move on

One structural point: an address at a domain your internet provider controls disappears when you change provider, and a free service address cannot be moved either. A domain you own and can point anywhere is the version that survives.

If you find something you did not set up

Treat it as a live compromise, not a curiosity, and work in this order from a device you trust.

  1. Change the email password to something new and unique. Do not reuse a variation of the old one.
  2. Sign out all other sessions and devices, after the password change.
  3. Delete the forwarding address, the filter rules, any send mail as entry and any app password you did not create.
  4. Revoke third party app access you do not recognize, then re-enable your second factor and generate fresh recovery codes.
  5. Fix recovery details: remove unknown phone numbers and addresses, confirm your own.
  6. Read the Sent, Archive, Trash and Spam folders for what was sent and what was hidden. This tells you which other accounts were targeted.
  7. Change the password on every account that resets through this mailbox, starting with anything that moves money.
  8. Tell the people who were emailed from your address, especially anyone asked to pay something.

Then check whether the original password is already circulating, using the method in how to check whether your password has leaked. If the entry point was a link you clicked rather than a reused password, the immediate steps in what to do after clicking a phishing link cover the rest of the hour.

The twenty minutes worth spending today

Open your email security settings and do six things. Set a long unique password. Turn on a passkey or an authenticator app and write the recovery codes on paper. Read every forwarding and filter rule. Sign out of unfamiliar sessions. Revoke connected apps you no longer use. Confirm the recovery phone and address are yours.

Then set a reminder six months out to read the rules and the app list again. Nothing else on your security list protects as many accounts at once, because everything else you own is downstream of this one.

Common questions

How do I check if someone else is reading my email?

Look at three lists in your account settings. Active sessions shows every device signed in right now, with a rough location and a last used time. Forwarding and filter rules show whether mail is being copied or hidden. Connected app access shows which outside services can read your messages. An entry you cannot explain in any of those three deserves to be removed today.

Why would a hacker set up email forwarding instead of just reading my mail?

Because forwarding survives you noticing. Once the copy is flowing, they no longer need your password, your second factor or an active session, and none of the usual warning signs appear. It also lets them catch password reset links for other accounts at the moment those are sent, which is how one mailbox turns into a bank problem.

Is a text message code good enough for my email account?

It is much better than no second factor and weaker than the alternatives. A text code stops the automated attacks that use passwords stolen from other companies. It does not stop a fake sign-in page, and the phone number itself can be moved to an attacker's SIM through the carrier. If a passkey or an authenticator app is offered, use that and keep the text code as a backup.

Should I have a separate email address just for my bank?

It helps more than most people expect. An address you have never posted publicly, never used to sign up for a shop and never given to a newsletter is very unlikely to appear in a breach list, which removes you from mass phishing and credential stuffing. It also means an unexpected message to that address is immediately suspicious.

What is the difference between plus addressing and an alias?

Plus addressing adds a tag to your existing address, so anything before the plus sign still reveals the real mailbox and anyone can strip it back. It is useful for spotting who leaked your address. An alias is a genuinely separate address that delivers to the same inbox and can be switched off on its own, which is what you want when a service starts sending junk.