Your primary email matters more than your other accounts. When you forget a bank or social media password, that service sends a reset link here. Whoever controls the primary email can try to reset other accounts while deleting the notifications that arrive. That is why the primary email deserves the strongest protection.
Why primary email is a top target
Attackers know one door to email often means a door to many accounts. Attacks are rarely brute password guessing. More often they come through convincing phishing, reused passwords exposed in another breach, or a takeover of the phone that receives codes. Securing the email closes all three paths at once.
Practical steps to secure primary email
Work through them in order. Each step is verifiable, so you know what is actually in place.
1. Use a long, unique password
Make a password used only for the primary email, never reused anywhere else, and store it in a password manager. Avoid any combination that has leaked through another service. Check a service like Have I Been Pwned to see whether your address has appeared in a breach.
2. Turn on two-factor authentication
Enable 2FA. Prefer an authenticator app (such as Google Authenticator, Authy) or a passkey over SMS, since SMS can be intercepted or diverted through number theft. Save the backup codes somewhere safe, separate from the primary device. Without the second factor, a leaked password opens the email straight away.
3. Check forwarding rules and filters
Open the settings for forwarding, filters, and inbox rules. An attacker who got in will often quietly create a rule to forward certain messages to their own address or delete login notifications. Remove any rule you did not create yourself.
4. Review active sessions and third-party apps
Look at the list of devices and sessions currently signed in, and the third-party apps given access to the email. Sign out of sessions and revoke apps you do not recognize or no longer use. Do the same when you buy a new device or sell an old one.
5. Secure the recovery options
Check the recovery email address and recovery phone number. Make sure you still control both and that they are yours. Remove old, unused recovery options. A locked primary email must still be recoverable through the official route.
Example: a quiet forwarding rule
Someone signs in to their email through a phishing link that mimics the login page. The attacker gets in, then creates a rule to forward any message containing "verify" or "reset" to their own address and hide it from the inbox. Days later, the attacker requests password resets on shopping and banking accounts. Because the reset notices never reach the user, everything stays quiet. Checking forwarding rules regularly would expose a foreign rule like this.
If you suspect the primary email was hacked
Stay calm and order the steps. If you can still sign in, change the password at once from a trusted device, check and remove any foreign forwarding rules and filters, and sign out every other session. Turn on 2FA if it was off. If you cannot sign in, use the provider's official recovery option. Once you are back in, check the other accounts tied to this email, especially finance, and change their credentials.
Common mistakes to avoid
- Relying on SMS 2FA with no backup. Number theft can lock you out. An authenticator app or passkey is sturdier.
- Keeping an old email you never open. Abandoned accounts often become silent entry points. Secure or close them.
- Never checking forwarding rules. An attacker's rule can run for weeks without you noticing.
Frequently asked questions
Can I use a passkey for email?
Yes, if the provider supports it. Passkeys reduce dependence on passwords and codes. Keep an official recovery option ready as backup.
Is an authenticator app required?
It is stronger than SMS because it does not depend on the mobile network or your number. Use one when available, and save its backup codes.
How often should I review settings?
At least every few months, or whenever you get a new device, change numbers, or after opening a questionable link.
Sources and further reading
Editorial note: This article is educational and defensive. Menu names differ between email providers. Use the official help center for current technical steps.

