The Email Security Checklist
Your email account is the key to everything else, and that’s why this email security checklist matters.
Think about it. Your website login, your bank, your domain registrar, your hosting, your social media. Almost every one of them lets you reset the password by email. If someone gets into your mailbox, they can get into all of it.
And business email has an extra risk. Once a scammer is in, they can quietly watch your conversations, wait for an invoice to go out, and then send your customer “updated payment details.” By the time anybody notices, the money is gone.
I’ve helped clean up after more than one of these. Here’s the email security checklist I wish everyone followed before it happened.
1. Use strong, unique passwords
- Every email account gets its own password. Never reuse it anywhere else.
- Use a password manager so you don’t have to remember them all.
- If you’ve used the same password on other sites, change it now. Passwords leak from other sites all the time, and scammers try them everywhere.
2. Turn on two-factor authentication
This is the single biggest thing you can do. Even if someone steals your password, they can’t get in without the second step.
- Use an authenticator app (like Google Authenticator, Microsoft Authenticator or Authy) instead of text messages when you can.
- Turn it on for every person on your team, not just yourself.
- Save your backup codes somewhere safe.
3. Check your forwarding and inbox rules
This is the one almost nobody checks, and it’s the first thing a scammer sets up.
Attackers often create a hidden rule that forwards copies of your email to them, or quietly moves certain messages (like replies about invoices) to a folder you never look at. That way they can keep watching even after you change your password.
- In Gmail: Settings → See all settings → Forwarding and POP/IMAP and Filters and Blocked Addresses
- In Outlook: Settings → Mail → Rules and Forwarding
If you see a rule or forwarding address you didn’t create, remove it, and treat the account as compromised.
4. Review connected apps and devices
- Look at which apps have access to your account (often listed as “third-party access” or “connected apps”). Remove anything you don’t recognize or no longer use.
- Check recent sign-in activity for logins from places or devices you don’t recognize.
- Sign out of devices you no longer use.
5. Keep your recovery info current
Make sure your recovery email and phone number are ones you still have. If they’re out of date, you could get locked out of your own account, and an outdated recovery address can be a back door for someone else.
6. Protect your domain from spoofing
Even if your mailbox is secure, scammers can still send email that looks like it’s from your domain. Setting up SPF, DKIM and DMARC stops that. Here’s how: SPF, DKIM & DMARC in Plain English.
7. Slow down on payment requests
Most business email fraud isn’t high-tech. It’s a convincing email at the right moment.
- Never change payment details based on an email alone. Call the person at a number you already have, not one from the email.
- Be suspicious of urgency: “This needs to go out today,” “I’m in a meeting, just handle it.”
- Look closely at the sender address. Scammers use lookalike domains with one letter changed.
Share this rule with your team and your customers. A two-minute phone call can save thousands of dollars.
8. Watch for phishing
- Don’t click login links in emails. Go to the site directly.
- Be wary of “your mailbox is full,” “shared document,” and “password expiring” emails. They’re classic tricks.
- When in doubt, ask someone before you click.
If your account has been compromised
Act fast:
- Change the password from a device you know is clean.
- Sign out all other sessions.
- Turn on two-factor authentication.
- Remove any forwarding addresses and inbox rules you didn’t create.
- Remove unfamiliar connected apps.
- Check your Sent folder to see what went out.
- Warn your contacts, especially anyone you invoice, not to act on recent payment requests without calling you.
- Change passwords on any other accounts that use the same password or can be reset from this email.
The email security checklist
- Strong, unique passwords in a password manager
- Two-factor authentication on every account
- No unknown forwarding or inbox rules
- No unknown connected apps or devices
- Recovery email and phone up to date
- SPF, DKIM and DMARC in place
- Verify every payment change by phone
- Train your team to spot phishing
Take 20 minutes and go through it today. Your email is worth it.
If you think your email has already been compromised and you want help cleaning it up, get in touch.
