Protect professional inboxes with unique passwords, multi-factor authentication, recovery planning, and safer credential handling.
Use a unique password for every inbox
A password manager can generate and store long, unique credentials. Reusing a password turns one breach into access to several unrelated services.
Enable strong multi-factor authentication
Use a security key or authenticator app when available. Keep recovery codes offline in a controlled location and document which administrator owns the recovery process.
Treat recovery details as critical access
An attacker who controls a recovery inbox or phone number can often reset the main password. Review recovery options regularly and remove addresses or devices that are no longer authorized.
Be careful with app passwords
App passwords are intended for compatible clients that cannot use the normal sign-in flow. Create them only when needed, label each one, revoke unused credentials, and never treat them as a way around platform security. See our compatibility-focused Gmail option for product scope.
Train for phishing, not just passwords
Verify unusual requests through a second channel, inspect domains carefully, and avoid opening unexpected attachments. Technical controls work best when people know how attacks are presented.