Secure your main email account before the smaller accounts
Your main email account often receives password resets for other services. That makes it a sensible place to begin a personal account-security review.

Review access deliberately
Open the provider's official security settings. Check recent sign-ins, recovery details and connected devices. Remove access you do not recognise only after considering whether it belongs to a device or app you use. Follow the provider's recovery process if you suspect compromise.
Strengthen sign-in
Use a unique password or the provider's supported passkey option, and enable an appropriate additional authentication method. Store recovery information securely. Do not give a one-time code to someone who contacted you unexpectedly, even if they claim to be support.
Keep the review manageable
Complete the changes while you have access to your recovery phone or email and enough time to test them. Avoid signing out of every device before you know the recovery arrangement works. The NCSC's online-security collection is useful background, while the provider's documentation explains its specific controls. Start with one account and verify the result before moving to the next; security changes are easier to maintain when you understand what you changed.
Sources & further reading
Source material and official guidance. Original practical suggestions are editorial content, not statements from the organisations below. Checked September 14, 2026.
Have a correction or a question about this article? Contact the editorial team. Read our editorial policy and disclaimer.


