• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
    • Internet & Social
    • Gadgets
    • Car Tech
    • Business
    • Science & Health
  • Reviews
  • Buying Guides
  • How-to
  • AI
  • Computing
    • Apps
    • Security
    • Gaming
  • More
    • Tools
    • Puzzles
    • Mobile
  • Launchpad
  • Sign in
TechEngage » Security & Privacy

How to Protect Your Email from Hackers (MFA, Passkeys, App Passwords)

How-To

Avatar for Jazib Zaman Jazib Zaman Follow Jazib Zaman on X Published: Dec 9, 2019 · 3:08 PM ET Updated: Sep 11, 2026 · 11:01 PM ET

protect email from hacking
FacebookTweetPinLinkedInPrint

Email is still the reset button for half your digital life. If someone owns the inbox, they can reset bank logins, drain cloud storage, and impersonate you at work. Fancy filters help; they do not replace a unique password, MFA or a passkey, and a short list of recovery habits.

This is practical hygiene for Gmail, Outlook/Microsoft, Yahoo, and similar providers — not a lecture about “being careful online.”

Protect email from hackers

  • Unique passwords beat clever passwords
  • Turn on MFA — prefer app codes or passkeys
  • App passwords: use sparingly, revoke often
  • Phishing that still works in 2026
  • Session, device, and forwarding audits
  • Recovery options that save you later
  • Public Wi‑Fi and shared computers
  • FAQs

Unique passwords beat clever passwords

Credential stuffing wins when your email password is the same one from a breached shopping site. Use a password manager, generate a long random password for the mailbox, and never reuse it elsewhere. Change it if that provider ever forces a reset after a breach — or if you typed it into a site that felt wrong.

Turn on MFA — prefer app codes or passkeys

Multi-factor authentication (2-Step Verification / MFA) means a stolen password is not enough. Priority order for most people:

  • Passkeys / security keys when the provider offers them (phishing-resistant).
  • Authenticator app (TOTP) such as Google Authenticator, Microsoft Authenticator, or a manager’s built-in codes.
  • Push prompts tied to a device you control — watch for prompt bombing and deny unexpected ones.
  • SMS codes as a last resort; better than nothing, weaker against SIM swaps.

Gmail / Google: Google Account → Security → 2-Step Verification. Add a passkey or authenticator; store backup codes offline.

Outlook / Microsoft: account.microsoft.com → Security → Advanced security options. Turn on two-step verification; prefer the Authenticator app or a passkey/security key over SMS.

Work accounts may enforce MFA through your employer — still verify you have a second method registered so a lost phone does not lock you out of payroll and Slack resets.

App passwords: use sparingly, revoke often

App passwords are single-purpose passwords for old mail clients that cannot do modern OAuth or MFA prompts. They are useful for a legacy desktop client — and dangerous if you mint dozens and forget them.

  • Create one app password per device/app, label it clearly, store it in the manager.
  • Prefer “Sign in with Google/Microsoft” OAuth in modern clients so you never need an app password.
  • Every few months, revoke unused app passwords in the account security page.
  • If the mailbox was phished, revoke all app passwords and active sessions immediately.

Phishing that still works in 2026

Attackers clone login pages and send “unusual sign-in” mail that looks like Google or Microsoft. Hover (or long-press) links; when in doubt, open the provider by typing the address yourself or using a bookmark — do not use the email’s button.

Also watch for OAuth consent tricks: a site asks you to “Continue with Google” and requests mail or contacts access. Deny anything you did not intentionally connect; review third-party access in the same security pages above.

Session, device, and forwarding audits

After any scare — or twice a year as routine — check:

  • Signed-in devices / sessions and sign out strangers.
  • Mail forwarding rules (Gmail filters/forwarding; Outlook inbox rules). Attackers hide silent forwards to their address.
  • Delegates / “send as” and connected apps.
  • Recovery phone and email — make sure they are still yours.

Recovery options that save you later

Print or download backup codes and put them somewhere offline. Keep a recovery email on a different provider when you can. If your only MFA method is the phone you are about to factory-reset, add a second method first.

Public Wi‑Fi and shared computers

HTTPS protects the mail session in transit on most modern sites, but public PCs can have keyloggers, and captive portals can be hostile. Use your own device, prefer cellular for sensitive admin tasks, and never stay signed in on a hotel business-center browser. A VPN helps on untrusted networks; it does not replace MFA.

FAQs

Is SMS two-factor authentication enough for email?

It is far better than password-only, but SIM swaps and SMS interception exist. Prefer a passkey, security key, or authenticator app when the provider supports them.

What should I do if I already clicked a fake login link?

Change the email password from a known-good device, revoke sessions and app passwords, check forwarding rules, and enable or re-check MFA. Then change passwords on important accounts that used that inbox for resets.

Do I still need a password if I use a passkey?

Providers usually keep a password as fallback. Make it unique and long, and treat the passkey as the daily unlock method.

Are app passwords the same as MFA?

No. An app password is a bypass for clients that cannot prompt for MFA. Limit them and revoke unused ones.

Does a VPN stop email hacking?

A VPN encrypts traffic on rough networks. It does not stop phishing, reused passwords, or missing MFA.

Something incorrect? Report an error in this article. Include a source if you have one; your name and email are optional.

Filed Under: Security & Privacy Tagged With: Email, How-To

Related Stories

  • Openai Pauses Advanced-Model Research After Agent Bypasses Network Restrictions

    OpenAI pauses advanced-model research after agent bypasses network restrictions

    Tech News & AnalysisSep 27, 2026

  • 5 Internet Security Suites To Get For Fortifying Your Internet Security

    5 Internet Security Suites to Get For Fortifying Your Internet Security

    Security & PrivacyMay 24, 2023

  • Google Authenticator Finally Gets Most Awaited Cloud Sync Feature

    Google Authenticator finally gets most awaited cloud sync feature

    Security & PrivacyApr 26, 2023

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
FacebookTweetPinLinkedInPrint
Avatar for Jazib Zaman

Jazib Zaman

Founder & Editor-in-Chief

Jazib Zaman is the founder and Editor-in-Chief of TechEngage, an independent technology publication. With a background in computer science, he writes primarily roundup and buying guides, cryptocurrency and fintech coverage, and software reviews. He also oversees the site's editorial direction across tech news and consumer technology.

Joined TechEngage January 2003First article on TechEngage October 2014

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Usb C Power Meters Techengage |
    Computing & HardwareBest USB-C Power Meters for Chargers and CablesSep 28, 2026
  • Akamai Anthropic Cloud Techengage |
    Tech News & AnalysisAkamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategySep 27, 2026
  • Openai Agent Dns Incident Techengage |
    Tech News & AnalysisOpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026
  • Iphone 18 Pro Availability Sept 18 |
    Tech News & AnalysisiPhone 18 Pro and Pro Max Available Today in 65+ CountriesSep 18, 2026

More in Security & Privacy

  • Openai Agent Dns Incident Techengage |
    OpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Photo 2023 05 23 19 03 36 Jpg |
    5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
  • Google Authenticator Gets Cloud Backup Support Jpg |
    Google Authenticator finally gets most awaited cloud sync featureApr 26, 2023
  • Uk Twitter Accounts Hacked Abdugeek Jpg |
    Twitter’s SMS 2FA is going away today, switch before it’s too lateMar 20, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Submit your company to TechEngage Launchpad Hot
  • TechEngage Brand Kit
  • Contact us
  • Tools & Calculators

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

Download our apps

TechEngage app coming soon on App Store

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact team@techengage.com · WhatsApp +1-307-381-8801

Your analytics choice
Allow Google Analytics to help us understand readership? You can use the site without it and change this choice anytime.

Privacy details