Email account security
Protect the inbox that resets other accounts by reviewing recovery, forwarding, sessions, app passwords and phishing-resistant sign-in.
How to use this section
Use the Email account security directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.
What belongs in this section
Primary email often controls password resets for the rest of a digital identity. Review forwarding and filters as carefully as the password, and keep recovery contacts current and independent.
Email App Passwords: Risks and Safe Use
Understand provider-generated app passwords, legacy clients and revocation.
Open guide →Email Forwarding Rule Audit
Find forwarding, filters, delegates and mailbox rules that can silently leak messages or hide alerts.
Open guide →Phishing-Resistant Email Login
Move high-impact email accounts toward passkeys or hardware security keys with protected recovery.
Open guide →How to Protect Your Primary Email Account
Build a layered plan for the mailbox that can reset your most important accounts.
Open guide →Recovery Email Security
Protect the alternate mailbox that can reset a primary account.
Open guide →What to Do After an Email Account Hack
Secure devices, remove persistent access, review messages and reset dependent accounts in the right order.
Open guide →Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.