Most Security Advice Is Noise
Search for email security and you get lists of thirty things, arranged in no particular order, most of which barely matter. That is not helpful, because nobody does thirty things.
So this is ordered by impact. The first three cover the overwhelming majority of real-world account compromise. If you stop reading after them, you will still have done the important part.
Tier 1: Do These Today
1. Turn on two-factor authentication for your email account first
Not your bank. Your email. This ordering surprises people and it is the single most important idea here.
Your email account is the master key. Whoever controls it can trigger a password reset on nearly everything else you own — bank, shopping, social, cloud storage — and intercept the confirmation. Securing your bank while leaving your email open is locking the door and leaving the key under the mat.
Roughly in order of strength:
- Hardware key — a physical device. Effectively unphishable, because it verifies the site's identity itself.
- Authenticator app — codes generated on your phone. Excellent, free, and what most people should use.
- SMS codes — weakest, because SIM-swap attacks exist. Still enormously better than nothing.
Any of them defeats the most common attack there is: someone typing a leaked password into a login form.
2. Stop reusing passwords
The second most common compromise is credential stuffing: take passwords from a breach, try them automatically against hundreds of popular services, harvest whatever opens. It is cheap, automated, and works because most people reuse.
Nobody remembers a hundred unique passwords, which is what password managers are for. Your browser has one built in and it is genuinely fine. Dedicated apps are better. Either way you remember one password and the software handles the rest.
Start with your email account and anything holding money. The rest can migrate as you log into them.
3. Check what has already leaked
Search your addresses at Have I Been Pwned — free, well established, asks only for the address. Include old addresses; forgotten accounts are where reused passwords hide.
Anywhere a leaked password is still in use, change it. That is the entire action item.
Tier 2: Worth an Afternoon
4. Audit your account's recovery settings
Open your email account's security page and check three things:
- Recovery email and phone. Is the backup address one you still control? A dead recovery address is a lockout waiting to happen.
- Forwarding rules. This is the one people skip. A standard move after compromise is adding a silent forward, so the attacker keeps reading your mail long after you change the password. Look for rules you did not create.
- Connected apps. Revoke anything you no longer use. That service you tried once in 2019 still has access to your mailbox.
5. Adopt the one anti-phishing habit
Never act on a link in an email about your account. Password expiring, payment failed, account suspended, storage full — close it, open a new tab, navigate to the site yourself.
You do not need to identify phishing if you never interact with it. This single rule is worth more than any amount of scrutinising sender addresses.
Its companion: never share a verification code with anyone, no matter who they claim to be or how plausible the reason. Real support never asks.
6. Split your addresses into three tiers
Using one address everywhere means a single breach exposes your identity across every service, with no way to tell who leaked it and no way to switch off one source.
- Real address — banking, tax, medical, employer, paid subscriptions, account recovery. Keep the list short enough to count.
- Alias per company — shops, newsletters, apps. Switch off individually; identify leakers by which alias starts receiving junk.
- Temporary address — one-off downloads, forums, coupons, forms you resent. A disposable inbox deletes itself, so it never joins a list. Never use one for anything you might log back into.
7. Update your devices
Unglamorous and it matters. A large share of successful attacks use vulnerabilities patched months earlier. Turn on automatic updates for your operating system, browser and mail app, then stop thinking about it.
Tier 3: Good Practice
8. Leave remote image blocking on
Most clients block remote images by default. That is deliberate — loading them confirms your address is live and reports when you opened the message. Leave it alone; click through on the rare occasion you need the pictures.
9. Report spam rather than deleting it
Deleting teaches your filter nothing. Reporting feeds a shared system used across millions of inboxes. Thirty seconds with leverage well beyond your own mailbox.
10. Be careful on shared and public machines
Use a private window, log out explicitly rather than closing the tab, and never save the password. On genuinely untrusted machines, assume a keylogger and do not log into anything that matters.
11. Verify payment changes by voice
If an email says a supplier's bank details changed, phone them on a number you already had — never one from the email. Invoice fraud is among the costliest attacks in existence and this one habit stops it.
12. Delete accounts you no longer use
Every dormant account is a database row waiting to appear in a breach. Closing the ones you have abandoned genuinely reduces exposure, and in many countries you can require deletion of your data.
What You Can Skip
Advice that circulates widely and earns little:
- Changing passwords every 90 days. Formally abandoned as guidance. It pushes people toward predictable variations. Change on evidence of compromise, not on a calendar.
- Complicated character substitutions. Replacing letters with symbols adds negligible strength against real cracking. Length beats complexity — a long passphrase is stronger and easier.
- Consumer VPNs as security. Useful for hiding traffic from a network operator. They do nothing about phishing, weak passwords or breaches, which is what actually affects people.
- Paid identity-protection subscriptions. Some are useful. Most sell monitoring you can do free, priced against anxiety. Read what you are buying.
If Something Has Already Gone Wrong
- Change the password on the real site, and anywhere you reused it — email account first.
- Turn on two-factor authentication immediately.
- Check recovery settings and forwarding rules for anything you did not add. Skipping this leaves the attacker inside.
- Review recent activity. Most providers show recent sign-ins and locations.
- If card details were involved, call your bank and ask for a reissue rather than waiting.
- Tell anyone who might receive a message from your account, so they do not fall for it.
Common Questions
Is a password manager safe? Isn't it a single point of failure?
It is a concentrated risk, but the alternative is worse. Reputable managers encrypt everything locally, so the provider cannot read your vault. The realistic comparison is not "manager versus perfect memory" — it is "manager versus the same password on forty sites", and the manager wins decisively.
What if I lose my two-factor device?
Save the backup codes when you enable it. Print them, put them somewhere physical. Most people skip this and then discover the problem at the worst moment.
Do I need encrypted email?
Most people, no. Ordinary email is encrypted between servers and readable by both providers. If that is genuinely unacceptable for something, use an encrypted messenger for that conversation rather than trying to make email into something it is not.
How often should I check for breaches?
Twice a year is plenty, or sign up for notifications and forget about it. The response is the same each time: change any reused password.
The Short Version
Two-factor authentication on your email account. Unique passwords via a manager. Check what has leaked. Never act on a link in an account email, and never share a code. Split your addresses into real, alias and disposable.
That is six things, not thirty, and they cover almost everything that actually happens to people.
