Why start with email?
Email often helps you reset passwords for other accounts. Someone with access to your inbox could read private messages, reset other passwords or impersonate you. That is why this guide starts with email security.
Enable an additional sign-in check
For specific controls, open Google, Microsoft, Apple and other account settings, including recovery codes and reviewing other sign-ins.
Two-factor authentication (2FA) adds a check alongside your password. It reduces the risk of unauthorised access, but cannot prevent every attack.
- Open your provider’s official account website and security settings.
- Follow its instructions to enable 2FA. Depending on the service, the method may use an authenticator app, a security key or a code on your phone.
- Keep recovery codes somewhere secure that you can access without that email account.
- Do not approve sign-ins you did not start or share codes with other people.
Our 2FA guide explains how to choose a method, store recovery codes and respond to an unexpected approval request.
Set a separate password
Use a long password that you do not use for any other account. Three random, unrelated words can make it easier to remember. Avoid names, dates and details from your public posts, and follow the service’s requirements. A password manager can help create and store different passwords. Read more in our strong-password guide.
Change your password through the service’s official settings, not through a link in a message. If the password has already been exposed, follow the password replacement and account-protection steps.
If you notice an unfamiliar sign-in
Reject a request you did not start. Open your account independently of the notification and review recent activity. If you exposed your password, change it wherever else you used it. If you can no longer sign in, follow the account recovery guide.
If money or banking access is at risk, contact your bank immediately through an official channel. For a work account, notify your internal IT or security support team.