If you only strengthen one online account this month, make it your primary email. That single inbox is still the recovery path for banking, shopping, social media, cloud storage, and most other services. When an attacker gains access to email, they often gain the ability to reset passwords elsewhere. This is why the first account you should protect is your email—and why the effort pays off across everything else you use.
I have sat with people after an email compromise more times than I can count. The pattern is rarely dramatic at the start. A phishing message gets a click. A reused password works on a less important site that later suffers a breach. An old forwarding rule or app password stays active long after it was needed. Once the inbox is open to someone else, password-reset emails begin arriving for other accounts, and the recovery process becomes a race.
Protecting email first reduces the size of that problem before it starts.
Why Email Still Sits at the Center
Most online services treat email as the authoritative recovery channel. Forgot your password? The reset link goes to email. New device login? The verification code or alert often goes to email. Changed account details? Confirmation lands in the same inbox.
This design is convenient, yet it concentrates risk. A compromised email account can be used to:
Request password resets on other services
Intercept verification codes or security alerts
Set up forwarding rules that quietly send copies of new messages elsewhere
Access years of order confirmations, account statements, and personal correspondence
Even if you use strong unique passwords everywhere else, a weak or reused email password (or a successful phishing attack against the inbox) can bypass those protections. Securing the email account therefore raises the difficulty of many follow-on attacks at once.

Practical Steps That Make the Biggest Difference
Use a Strong, Unique Password and a Password Manager
The email password should not appear anywhere else. A long passphrase or a randomly generated password stored in a reputable password manager is far more effective than a short complex string you try to memorize and then reuse. If you have ever used the current email password on another site, change it now and let the password manager handle the new one.
Turn On Two-Factor or Multifactor Authentication
Enable the strongest form of two-factor authentication the email provider offers. App-based authenticators or hardware security keys are preferable to SMS when both are available. SMS is better than nothing, yet SIM-swap and interception risks make it the weaker option for a high-value account. Once two-factor is active, store backup codes in a safe place offline so you are not locked out if you lose the primary device.
Review Connected Apps and Account Permissions
Open the security or account permissions section of your email provider and examine every third-party app or service that has access. Remove anything you no longer use or do not recognize. Old mail clients, discontinued productivity tools, and forgotten “Sign in with Google/Apple/Microsoft” connections can remain active for years and provide an alternate path into the account.
Check Filters, Forwarding, and Delegates
Look for unexpected forwarding rules, filters that delete or move messages, or delegated access granted to another address. Attackers who gain temporary access sometimes create these rules so they continue receiving copies even after the password is changed. Removing unknown rules and delegates closes that persistence mechanism.

Recovery Options Worth Configuring Now
Add a secondary recovery email address that you control and, if available, a phone number for account recovery. Keep those recovery methods current. An outdated recovery phone or email can turn a simple lockout into a lengthy support process.
Some providers also offer the ability to generate one-time backup codes or to require additional verification for sensitive actions such as changing the password or adding a new recovery method. Enabling those extra checks makes it harder for an attacker who has temporary access to lock you out permanently.
Recognizing Early Warning Signs
Certain signals suggest the email account may already be under pressure:
Unexpected password-reset messages for other services
Security alerts about new device sign-ins you do not recognize
Sent-mail items you did not write
Filters or forwarding rules you did not create
Sudden appearance of unfamiliar connected apps
If any of these appear, change the email password immediately from a trusted device, review the security settings listed above, and check other high-value accounts for similar signs. Acting while the attacker’s access is still limited prevents a wider cascade.
Everyday Habits That Support the Technical Steps
Technical controls work better when paired with a few consistent habits:
Treat unexpected email messages that urge immediate action with skepticism, especially those that ask you to click a link and sign in again.
Open account-security pages by typing the address yourself or using a bookmark rather than clicking links inside messages.
Keep the email app and browser updated so known vulnerabilities are less likely to be exploited.
Sign out of webmail on shared or public computers and avoid saving the password on devices you do not fully control.
These habits cost little time and reduce the chance that a single click undoes the stronger configuration.
Safe enough starts with clear choices. Making the primary email account harder to take over does not eliminate every online risk, yet it removes one of the highest-leverage paths attackers still use against ordinary households. Once email is in better shape, strengthening banking, shopping, and other accounts becomes both easier and more effective.
Related articles in the Account Defense section cover passkeys, password managers, and helping older family members with account security. The same principle applies throughout: start with the account that unlocks the others.