How to secure your email account: six steps
How to secure your email account: a strong password, two-factor authentication, app passwords, recovery codes, a recovery address and a forwarding check.
Step 1. A long password you use nowhere else
A password you have already used somewhere may have leaked with that site’s database. Such passwords are the first ones tried against an email account. So your mailbox password must not be used anywhere else.
- At least 10 characters: the server will not accept fewer. Longer is better — a phrase of four or five random words is easier to remember than a short jumble of characters.
- Keep the password in a password manager. Then you do not have to remember it or make it simpler.
- Enter the password only on the account page and in webmail that you opened yourself — from a bookmark or by typing the address. Not from a link in an email.
- To change the password: your account → “Security” → “Change password”. You will need the current password. Other account sessions are closed after the change.
- After a password change, mail programs are disconnected and mail and Disk app passwords are revoked: enter the new password in your programs or create new app passwords for them (step 3).
Step 2. Two-factor authentication
The second step is a six-digit code from an app on your phone. The code changes every 30 seconds. A password alone is no longer enough to sign in to your account and webmail: the code from your phone is needed too. Disk sign-in goes through the account, so the code is asked for there as well.
You switch it on in your account: “Security” → “Turn on protection”. The page shows 8 backup codes for the second step, and only once. They stand in for the phone if it is lost. Keep them apart from the phone.
Once it is on, mail programs stop accepting the main password — they need app passwords (step 3). Which app to choose and how to turn on the protection step by step is in the guide “Turn on two-factor protection”.
Step 3. App passwords for mail programs
A mail program stores the password on the device. If that is the main password, a lost phone means a lost password to the whole mailbox. An app password is created for one device and revoked on its own. It cannot be used to sign in to your account. More in the guide “App passwords for mail programs”.
- Account → “Security” → “App passwords”. Name the password after the device — “iPhone”, “laptop” — and press “Create password”. You can have up to ten.
- Enter it in the mail program instead of the main password. With the second step on there is no other way, but app passwords work without it too.
- Lost a device? Revoke its password in the same section. The other devices keep working.
- Look through the list from time to time. Revoke any password you do not recognise by its name.
Step 4. Recovery codes
At registration you get 10 one-time codes of 16 digits each. A code lets you set a new password if you forgot the old one or someone else changed it. It is the fastest way back into the mailbox. More in the guide “Recovery codes: how to keep them and how to use them”.
Do not confuse them with the backup codes for the second step. Recovery codes stand in for the password, backup codes for the phone. You need both.
- Keep the codes on paper or in a password manager. Not in the mailbox itself, and not in a cloud you sign in to through this mailbox.
- How many codes are left is shown in your account: “Summary” → “Access and recovery”.
- A new set: account → “Security” → “Issue new codes”. The old codes stop working at once.
Step 5. Recovery address
A recovery address is your mailbox at another mail service. If you forget the password and have no codes at hand, a password reset link can be sent to it. The link works for 30 minutes and only once.
- Account → “Security” → “Recovery address”. Enter the address and save.
- An email with a link goes to that address. Open the link within 48 hours. Until the address is confirmed, no password reset link will be sent to it.
- Choose a mailbox protected at least as well as this one: whoever gets into the recovery address can change the password here too.
- Do not give an address that forwards mail into this same mailbox. If you lose access here, you will not get the link either.
Step 6. Check forwarding, filters and identities
Someone who has been in your mailbox may leave a back door: a rule that forwards your mail to their address, or a hidden copy of all your outgoing mail. Changing the password in your account does not remove such settings. You have to find and delete them yourself.
Go through this list every few months. And right away if you get a note about a security change you did not make. If the mailbox may have been broken into, change the password first, then check. Check again a couple of days later.
- Webmail → “Settings” → “Filters”. Open every rule. Be wary of the actions “Redirect message to” and “Send message copy to” with an unfamiliar address, and of an auto-reply you did not set. How filters work is in the guide “Filters, folders and the out-of-office reply”.
- Webmail → “Settings” → “Identities”. The “Bcc” and “Reply-To” fields must hold no strangers’ addresses, and the signature no strangers’ links.
- Account → “Security”. Check for unfamiliar app passwords and make sure the recovery address is yours.
- Disk → “Settings” → “Security” → “Devices & sessions”. Remove unfamiliar devices and Disk app passwords. Changing the mailbox password revokes them all at once — yours too, so Disk programs will need new ones.
What the server does by itself
This works without any settings on your side.
- Risky actions ask for your password again if more than 10 minutes have passed since you last entered it: a new app password, new recovery codes, changing the recovery address, turning on the second step, new hosting passwords. Changing the password always asks for it; turning off the second step asks for the password and a code from the app (or a backup code).
- When the password or the recovery address is changed, the second step is turned on or off, a new app password is created or new recovery codes are issued, a note “Mailbox security changed” from noreply@alpost.ch arrives in your Inbox. If it was not you, change the password and go through step 6.
- After five wrong passwords in 15 minutes, sign-in to this mailbox through the website and webmail is paused for up to 15 minutes — for everyone, you included. Wrong second-step codes count the same way.
- Mail programs: after five wrong passwords in 10 minutes, the address they came from is blocked for an hour, and for longer on repeat — up to a week. For sending mail, four errors are enough.
- After access is recovered, all mail app passwords are revoked, connected mail programs are disconnected, and a note about what happened arrives in the Inbox.
- A recovery request without codes is reviewed by a person. Before the password can be changed through it, an email with a cancellation link goes to the mailbox and to the confirmed recovery address. There are three days to cancel.
What is not here
- No alerts about a sign-in from a new device or another country. Notes arrive only about the security changes listed above and only in the mailbox itself — with the time, the address and the country the change was made from. A copy goes to the recovery address only when an access recovery request is submitted.
- No note is sent when an app password is revoked.
- No sign-in log. The account Summary shows only the last sign-in — time and address. Most often that is your own mail program.
- No “sign out everywhere” button — changing the password does that job: it closes all other sessions — on the site, in webmail (within two minutes), on Disk and in mail programs — and revokes mail and Disk app passwords. It does not touch forwarding rules or webmail identities, so still go through step 6 afterwards.
- No second step that survives access recovery: a recovery code, a link sent to the recovery address and an approved request turn it off together with the password change — otherwise anyone who lost their phone could never get back in. So guard recovery codes and the recovery address as carefully as the password.
- The server does not check the password against lists of leaked or common passwords — only the length is checked. Choosing a strong password is up to you.