Email security basics
The essential steps to keep your business email accounts secure — passwords, two-factor authentication, and everyday habits.
- Difficulty
- Beginner
Email is one of the most targeted entry points for attackers. A compromised email account can lead to financial loss, data breaches, and reputational damage. This guide covers the basics every business owner should have in place.
Quick summary
The most important email security steps are: use a strong, unique password; enable two-factor authentication (2FA); learn to recognize phishing attempts; and don't share your password with others. Get those four right and you've done most of the work.
Use a strong, unique password
Your email password should be:
- At least 16 characters long
- A mix of letters, numbers, and symbols — or a long passphrase
- Unique — not used for any other account
If an attacker gets your password from a data breach on another site (a shopping site, for example) and you've reused it for email, your inbox is now compromised.
The easiest way to manage unique passwords is a password manager. It generates and stores strong passwords for you — you only need to remember one.
Enable two-factor authentication (2FA)
Two-factor authentication (2FA) — sometimes called multi-factor authentication (MFA) — requires a second form of verification in addition to your password. Even if someone knows your password, they can't sign in without the second factor.
How to enable it:
- Google Workspace: open your Google Account, go to Security & sign-in, and under "How you sign in to Google" choose Turn on 2-Step Verification. Google warns that on a work or school account these steps might not work — if you can't set it up, ask your administrator for help.
- Microsoft 365: an administrator turns it on for everyone, either with security defaults in the Microsoft Entra admin center or with Conditional Access policies. Each person then manages their own verification methods in My Sign-Ins.
Verification options include:
- A passkey or a hardware security key — the strongest option, because these protect the account against phishing
- An authenticator app such as Google Authenticator or Microsoft Authenticator, which generates one-time codes and works without a signal
- A code sent by text message or voice call — better than nothing, but Google warns these can be vulnerable to attacks on your phone number
See Two-factor authentication explained for a full guide.
Important
Do not skip 2FA setup. As Microsoft puts it, using a password on its own "leaves an insecure vector for attack" — if the password is weak or has leaked from somewhere else, an attacker can simply use it. A second factor is much harder for them to get hold of. This matters most for the email address you use to manage other accounts: if your inbox is compromised, attackers can request password resets for every service linked to it.
Don't share your password
Never share your email password with colleagues, clients, or vendors — including Chykalophia. Use delegate access or shared mailboxes instead.
- For team inboxes: use a shared mailbox
- For granting access to your admin: grant admin roles, not your personal password
- For temporary access: grant temporary admin credentials rather than sharing your personal login
Be alert to phishing emails
Phishing is when an attacker sends an email pretending to be someone you trust — your bank, Google, Microsoft, or a colleague. The goal is to trick you into clicking a link and entering your credentials on a fake website.
See How to recognize a phishing email for a detailed guide on spotting these.
The most important habits:
- Hover over links before clicking to see where they actually go
- Be suspicious of any email asking you to click a link and log in
- When in doubt, go directly to the service's website by typing the address in your browser — don't click the link
Keep your recovery options up to date
Both Google and Microsoft use a recovery email address and phone number to help you get back into your account if you're locked out. Make sure these are current — especially if you've changed your phone number.
Watch for account compromise signs
Signs your email may have been compromised:
- Emails you didn't send appearing in your sent folder
- Contacts saying they received strange emails from you
- You can't log in (attacker changed the password)
- Unexpected password reset emails from other services
- Unexpected changes to your account settings (auto-forwarding set up, filters created)
If you suspect your account has been compromised, act quickly. See What to do if an account is compromised.
Keep your email platform up to date
Google Workspace and Microsoft 365 are managed services — the underlying software is always kept up to date by the provider. But:
- Keep your browser and mobile apps updated (they patch security vulnerabilities)
- If you use Outlook desktop, keep it updated
- Review your account's connected apps occasionally — revoke access for apps you no longer use
Business email compromise (BEC)
Business Email Compromise is a sophisticated scam where attackers either gain access to a business email account or create a lookalike address. They then impersonate a director or supplier to request fraudulent payments.
This is the email scam we take most seriously for clients, because a single fraudulent payment can be costly. The keys to protection:
- Require phone or in-person confirmation for any unusual payment requests
- Be suspicious of any email asking for an urgent wire transfer or change of bank details
- Set up DMARC to prevent others from spoofing your domain
See Business email compromise explained.
Common questions
How do I know if my account has been breached?
Check Have I Been Pwned — it shows whether your email address appears in any known data breaches. Change your password and enable 2FA if you're listed.
Someone on my team clicked a suspicious link. What should we do?
Act immediately. Change the account password, check for auto-forwarding rules or account changes, review sent mail, and report it to your IT contact or Chykalophia. See What to do if an account is compromised.
Can my email be hacked if I have 2FA?
It's much harder, but 2FA isn't a force field. Google's own guidance is that although any form of 2-Step Verification adds security, codes sent by text or voice call can be vulnerable to attacks on your phone number — so an authenticator app is a step up. Passkeys and hardware security keys are stronger again, because they protect the account against phishing.
Do I need to set up security separately for each team member?
2FA should be required for every user, and in both platforms an administrator can require it rather than leaving it to each person. In Google Workspace, a super administrator enforces 2-Step Verification from the Admin console under Security → Authentication → 2-step verification. In Microsoft 365, turning on security defaults in the Microsoft Entra admin center requires every user to register for multifactor authentication. Microsoft says organizations on a paid Microsoft Entra ID plan, or with more complex security requirements, should use Conditional Access policies instead.
Related guides
- How to recognize a phishing email
- Two-factor authentication explained
- Password managers
- Business email compromise explained
- What to do if an account is compromised
Need a hand?
Learn more
Last updated
Email sent from your website explained
How your website sends automatic emails — form submissions, order confirmations, password resets — and what needs to be set up for them to work reliably.
How to recognize a phishing email
Learn to spot the warning signs of a phishing email before you click a link or enter any information.