Email Security Tips: Your Practical Checklist
Your email is the master key to your online life. If someone gets into it, they can reset your other passwords one by one. These security tips are a plain checklist you can run through today, from locking the account itself to spotting a scam before you click. A disposable email address backs it all up by keeping your real inbox off risky sites.
Your Next Inbox Lasts 10 Minutes
Click once and use a private address that cleans up after itself - No account needed.
Your 10 Minute Mail Address:
Waiting for incoming emails...
Unique passwords
One long, different password for every account.
Two-factor login
A second code stops a stolen password cold.
Spot phishing
Check the tone, the sender, and the link first.
Use a stand-in
Keep your real address off risky sign-ups.
Lock down the account itself
Most break-ins start with a weak or reused password. Close that door first.
Use a long, unique password
Give every important account its own password, and make each one long. A short phrase of a few random words beats a clever but short one. Never reuse the password from your email anywhere else. A password manager can create and remember these for you, so you never have to.
Turn on two-factor login
Two-factor login asks for a second code after your password, usually from an app on your phone. It is the biggest single upgrade you can make. Even if a thief steals your password, they cannot get in without that code. Switch it on for your email first, then your bank and anything with your card on file.
Spot phishing before you click
Phishing emails try to scare or rush you into clicking a fake link. Slow down and check three things.
- The tone: Threats, deadlines, and "act now or lose access" are classic bait. Real companies rarely rush you like that.
- The sender: Hover over the name and read the real address. A close-but-wrong domain is a giveaway.
- The link: Hover before you click. If the address does not match the real site, do not touch it. Open the site yourself in a new tab instead.
Some threats hide even when you do not click. Read about the tracking pixels buried in ordinary emails to see what a simple open can reveal.
Handle codes and resets safely
One-time codes are only safe if they reach the right inbox.
Route untrusted codes through a stand-in address
For a quick verification on a site you do not fully trust, route the code through a throwaway address so it never touches your main account. Our walkthrough on grabbing a verification code without giving up your email shows the exact steps.
- Turn on two-factor login for your main email first.
- Use a long, unique password for every account.
- Slow down and check the tone, sender, and link before clicking.
- Route codes for untrusted sites through a throwaway address.
Frequently asked questions
What is the single most important email security step?
How can I tell if an email is a phishing scam?
Does a disposable address make me safer?
Run the checklist today
Pick one item and do it now: switch on two-factor login, or grab an address at the top of this page for your next sign-up. To keep your account list tidy over time, follow our guide to managing your privacy, and to build wider habits, see how to protect your privacy online.