
Improving Your
Email Security
The most common way viruses, ransomware, spyware, or other malware
appear on a company's computer is via e-mail
The technology surrounding email is old and was developed well before sophisticated hacking became prevalent. Email can trace its roots back to ARPANET, a project funded by the U.S. Department of Defense. This research project pioneered many of the basic internet technologies we use every day. Email protocols were initially developed with the expectation that the network carrying the messages would be military-grade and secure so security was never built in.
You are vulnerable to viruses, ransomware, spyware, or other malware even if your large, medium or small business has excellent IT resources and follows a sound security policy. Running anti-virus software on all hardware, installing software security patches regularly, and using firewalls and VPNs on corporate networks won’t completely prevent security threats coming in via email. Security breaches can cost a huge loss of productivity, stolen information, and damaged reputation.
In this article we’ll cover the following topics
- Creating Strong Passwords
- Managing Account Settings
- Changing Behavior
- Using Multiple Email Accounts
Passwords
Security begins with strong passwords

Never jot down passwords
and leave them out
The single most important concept in security is the use of strong and unique passwords. Email accounts are some of the most critical and should be treated with the same care given to passwords for banking or credit accounts.
In a previous blog, I discuss the topic of passwords and using a password manager to help with keeping track of your online presence. It’s not a bad idea to read through that blog.
Here are some simple password guidelines
- Never uses obvious easily guessable passwords: “password“, dates of birth, SSN, names (yours, partners, spouses, children, pets)
- Mix the case – “GodZilla” is more secure than “godzilla” or “GODZILLA“
- Add some numbers: “G0dZ1lla“
- Add some other characters: “G0d-Z1ll@“
- Each email account should have a unique password
- Don’t keep passwords on sticky notes around your workspace
- Don’t keep passwords logged in unsecured spreadsheets or documents
- Don’t use email account passwords for any other logins

Managing Account Settings
Most users of the major email services
never review or change the default settings
Most users trust that their email provider has their best interests in mind. The major email providers have a difficult set of engineering challenges to navigate to give users the best experience possible. Better security measures can often be inconvenient for the user in the form of login codes and extra steps. Better spam prevention often requires deeper monitoring and parsing of email content which many users view as a violation of their privacy by a large corporation. These challenges are in often opposition to each other requiring providers to compromise to prevent users from leaving the platforms in mass.

Comprehensive security and privacy legislation are non-existent in the United States so there are no regulatory mandates that email providers must follow. The only exception is the HIPAA rules governing healthcare privacy. In order to maintain HIPAA compliance, healthcare professionals don’t interact with patients using email or messaging outside of secure infrastructure.
Always review your email providers default settings
In addition to creating a strong password, the following actions are highly recommended regardless of who your email provider happens to be:
- Add a recovery phone number and alternate email address
- Set up Two-Step Authentication which requires verification at login
- Turn on spam detection if it is not on by default … Google calls it “Safe Browsing“
- Allow email alerts to be sent at sign-on so you’ll know if someone is attempting to access your account
- Limit logins to “approved” devices if your provider has this feature
- Run security audits if your provider has this feature
Here is some account security support information from the three big email providers.
Changing Behaviors
The most powerful security measure users can take is understanding how to use email securely. This means understanding what to send, how to send it, and where it is safe to send it. Changing our behaviors is more effective than any spam filter or firewall.
Confidential information should never be shared in email
The following should never be shared in an email
- Social Security Number
- Banking Information
- Financial Documents
- Credit Card Information
- Medical Information
- Mental Health Information
- Login Credentials
Not Every Email Needs Be Opened
It’s human nature to be compelled to look at every piece of email that lands in our “In Boxes”. One of the most difficult behaviors to change is the feeling to review, respond, or categorize all emails. Marketing firms and scammers understand this and use this to their advantage.
Never open unsolicited emails from the following sources. They may not be who they claim. Avoid clicking links embedded in an email and NEVER open any attached documents or files
- Federal, State, or Local Governments – agencies like the IRS will use the postal service to contact you
- Law Enforcement Agencies – official contact is in-person, phone, courier, or postal service
- Banking or Financial Institutions – contact for security issues usually occurs by phone or via the postal service. Your bank or financial provider may email notifications if you have signed up for them and are considered expected contact. Only interact with institutions that you have a currently working relationship with.
- Utilities – payment reminders or electronic bill payment confirmations are expected contact. Security issues will be communicated via the postal service.
- Technologies Companies (Apple, Google, Microsoft, etc) – security breaches aren’t communicated in email and access confirmation emails are expected communication. If you receive an unexpected access message DO NOT click on any links in the email to investigate. Log into your account independent of the email and check for notifications. If your actions didn’t trigger the notification, deny the access request and report it to your provider. Verify that the email sources are genuine.
Use the Preview Feature if Your Email Client Has One
Use caution when opening emails from the following sources. Avoid clicking links embedded in an email and NEVER open any attached documents or files
- Retailers – online shopping can result in lots of advertising emails. Verify that they are genuine and consider un-subscribing. Better yet, opting out of most email interactions when making purchases
- Shopping Sites (Amazon, eBay) – scammers often try to mask as Amazon or eBay. Verify that the email sources are genuine.
Don't Trust Spam Filters To Catch Everything
NEVER OPEN emails if the following is true. NEVER click any embedded links in questionable emails, and NEVER open any attached documents or files
- Missing Subject Lines – Emails missing a subject line are usually caught by spam filters but some can make it through
- Garbled or Nonsense in the Subject Line – If the subject is not clearly readable in English or any other languages that you commonly speak
- Spelling or Grammar Errors in the Subject Line – Spammers and scammers oftentimes aren’t native speakers and make obviously sometimes comical mistakes. Filters usually catch these but not always
Where You Open Your Email Matters
Your physical location and the wireless network used to access emails matter! Some networks are much more secure than others. When traveling away from a trusted network, use cellular data or a reputable US-based VPN (Virtual Private Network). Public wireless networks in the United States are generally considered as safe but it is important to be aware of who’s network you are using.

Avoid Using Open, Public WiFi Networks to Access Email
Here are some guidelines
Safer
You can consider these locations mostly safe for accessing email
Private Corporate Networks
Personal Networks with
Security Features Enabled
Friends Networks with
Security Features Enabled
Cellular Networks in the
United States and Canada
Foreign Cellular Networks
When a VPN is Used
Public WiFi When a VPN is Used
Caution
You should exercise caution when accessing these networks
Personal Networks
with Poor Security
Neighbors Networks With Unknown Security
Public WiFi in the United States
Warning
You should avoid accessing email in these situations
Public WiFi in Foreign Countries Without Using a VPN
Foreign Cellular Networks Without Using a VPN
Changing Your Email Provider
Still Using the Same Email Provider from the 90's?
It is time to let go of those relics of a bygone era. Email service from that favorite 90s search engine or online provider is likely to have some serious privacy and security issues associated with their use. Don’t let history or sentimentality cloud your judgment.
What price are you paying for your free email service?
Avoid
The following email service providers have serious security and privacy issues and accounts should be closed and moved.
AOL
Yahoo!
Useable
The following email service providers have documented issues but are industry leaders and can be used safely
Apple
Microsoft
Safer
The following providers are in the business of providing more secure email and have policies in place to protect privacy
Protonmail
Hushmail
Tutanota
Runbox
Consider obtaining your own domain
Even personal email accounts can benefit from your own domain. Having your own domain will allow you to transfer between email providers without having to notify a large number of people about changes in your email. Avoid domain provider bundled email services and shop for domain and email services independently.
Use Multiple Email Accounts
Separate Email Accounts into Specific Functions
Having multiple email accounts can seem overwhelming to manage at first but grouping accounts by function helps contain security vulnerabilities and protects your privacy. Using an email client like Apple Mail or Thunderbird allows you to consolidate all your accounts into one place.
Personal
Creating and managing multiple accounts is easier with your own domain but can be done with a combination of free or paid email providers
Master or Administrators Account
Use a master email account for banking or financial institutions and as a recovery account for your Personal Account. This address should be used very sparingly.
Personal Account
Share this email account with close friends and family. Use this account as the recovery account for shopping and social media email account.
Social Media Account
Create an email account specifically for social media. Use this email for all social media interaction
Shopping Account
Create an email account specifically for shopping (Amazon, eBay, etc) and for paying non-credit card bills electronically
Business
Larger businesses tend to operate numerous email accounts but this can also be very beneficial for very small businesses or freelancers as well
Master or Administrators Account
Use a master email account for domain registration, or accounts banking and financial institutions, and as a recovery account for your Personal Account. This address should be used very sparingly.
In many businesses, this account is held by the IT Department or the business owner and a backup person exclusively.
Staff Account
Create accounts for each staff member so they can interact with co-workers, clients, business partners, and vendors.
Marketing Account
Use this account for marketing functions like email campaigns and social media accounts
Information Account
Use this account for responses to contact forms, order confirmations, and status emails

Conclusion
Changing email behavior will go a long way toward reducing the risk of being victimized by criminals. Education is one of the most powerful tools to prevent users from falling for some of the more common scams. Use the “Report Spam” feature to help your email provider identify and block messages for you and others.
Scams and Ransomware Attacks are Criminal Acts
Shockingly, a large number of ransomware attacks go unreported. If you are a victim of a cybercrime, report it to authorities.
DISCLAIMER:
The information presented above comes from personal and client experiences and is my opinion of best practices. I am not receiving compensation from any of the sites, products, or services that I mention in this posting.
Resources
I’d like to thank the authors of the following blogs and websites. Their work provided some background research for this article.
- A Brief History of E-Mail – https://phrasee.co/blog/a-brief-history-of-email/
- 4 E-Mails You Should Never Open – https://www.cygnussystems.com/4-emails-you-should-never-open/
- The Big Risk in the Most-Popular, and Aging, Big Tech Default E-Mail Programs – https://www.cnbc.com/2023/01/15/the-most-popular-big-tech-email-programs-are-old-and-vulnerable.html
- G-Mail Security Tips – https://support.google.com/mail/answer/7036019?visit_id=638095869895843486-705249758&rd=1#zippy=
- Microsoft Account Info and Security Codes – https://support.microsoft.com/en-us/account-billing/microsoft-account-security-info-verification-codes-bf2505ca-cae5-c5b4-77d1-69d3343a5452
- Use the Built-in Security and Privacy Protections of iPhone – https://support.apple.com/guide/iphone/use-built-in-security-and-privacy-protections-iph6e7d349d1/ios
- International Travel Guide for US Government Mobile Device – https://www.cio.gov/assets/files/FMG%20International%20Travel%20Guidance%20-Final.pdf
- Seven Best Email Providers for 2023 (Ranked and Reviewed) https://www.chrisbournelis.com/secure-email-providers/