Mailboxes at the Smithsonian National Postal Museum

Improving Your
Email Security

The most common way viruses, ransomware, spyware, or other malware
appear on a company's computer is via e-mail

The technology surrounding email is old and was developed well before sophisticated hacking became prevalent. Email can trace its roots back to ARPANET, a project funded by the U.S. Department of Defense. This research project pioneered many of the basic internet technologies we use every day. Email protocols were initially developed with the expectation that the network carrying the messages would be military-grade and secure so security was never built in.

You are vulnerable to viruses, ransomware, spyware, or other malware even if your large, medium or small business has excellent IT resources and follows a sound security policy. Running anti-virus software on all hardware, installing software security patches regularly, and using firewalls and VPNs on corporate networks won’t completely prevent security threats coming in via email. Security breaches can cost a huge loss of productivity, stolen information, and damaged reputation.

In this article we’ll cover the following topics

  • Creating Strong Passwords
  • Managing Account Settings
  • Changing Behavior
  • Using Multiple Email Accounts

Passwords

Security begins with strong passwords

notepad with password
Never jot down passwords
and leave them out

The single most important concept in security is the use of strong and unique passwords. Email accounts are some of the most critical and should be treated with the same care given to passwords for banking or credit accounts.

In a previous blog, I discuss the topic of passwords and using a password manager to help with keeping track of your online presence. It’s not a bad idea to read through that blog.

Here are some simple password guidelines

  • Never uses obvious easily guessable passwords: “password“,  dates of birth, SSN, names (yours, partners, spouses, children, pets)
  • Mix the case – “GodZilla” is more secure than “godzilla” or “GODZILLA“
  • Add some numbers: “G0dZ1lla“
  • Add some other characters: “G0d-Z1ll@“
  • Each email account should have a unique password
  • Don’t keep passwords on sticky notes around your workspace
  • Don’t keep passwords logged in unsecured spreadsheets or documents
  • Don’t use email account passwords for any other logins
Mailboxes at the Smithsonian National Postal Museum

Managing Account Settings

Most users of the major email services
never review or change the default settings

Most users trust that their email provider has their best interests in mind. The major email providers have a difficult set of engineering challenges to navigate to give users the best experience possible. Better security measures can often be inconvenient for the user in the form of login codes and extra steps. Better spam prevention often requires deeper monitoring and parsing of email content which many users view as a violation of their privacy by a large corporation. These challenges are in often opposition to each other requiring providers to compromise to prevent users from leaving the platforms in mass.

email security diagram

Comprehensive security and privacy legislation are non-existent in the United States so there are no regulatory mandates that email providers must follow. The only exception is the HIPAA rules governing healthcare privacy. In order to maintain HIPAA compliance, healthcare professionals don’t interact with patients using email or messaging outside of secure infrastructure.

Always review your email providers default settings

In addition to creating a strong password, the following actions are highly recommended regardless of who your email provider happens to be:

  • Add a recovery phone number and alternate email address
  • Set up Two-Step Authentication which requires verification at login
  • Turn on spam detection if it is not on by default … Google calls it “Safe Browsing“
  • Allow email alerts to be sent at sign-on so you’ll know if someone is attempting to access your account
  • Limit logins to “approved” devices if your provider has this feature
  • Run security audits if your provider has this feature

Here is some account security support information from the three big email providers.

Changing Behaviors

The most powerful security measure users can take is understanding how to use email securely. This means understanding what to send, how to send it, and where it is safe to send it. Changing our behaviors is more effective than any spam filter or firewall.  

Confidential information should never be shared in email

The following should never be shared in an email

  • Social Security Number
  • Banking Information
  • Financial Documents
  • Credit Card Information
  • Medical Information
  • Mental Health Information
  • Login Credentials

Not Every Email Needs Be Opened

It’s human nature to be compelled to look at every piece of email that lands in our “In Boxes”. One of the most difficult behaviors to change is the feeling to review, respond, or categorize all emails. Marketing firms and scammers understand this and use this to their advantage. 

Never open unsolicited emails from the following sources. They may not be who they claim. Avoid clicking links embedded in an email and NEVER open any attached documents or files

  • Federal, State, or Local Governments –  agencies like the IRS will use the postal service to contact you
  • Law Enforcement Agencies – official contact is in-person, phone, courier, or postal service 
  • Banking or Financial Institutions – contact for security issues usually occurs by phone or via the postal service. Your bank or financial provider may email notifications if you have signed up for them and are considered expected contact. Only interact with institutions that you have a currently working relationship with.
  • Utilities – payment reminders or electronic bill payment confirmations are expected contact. Security issues will be communicated via the postal service.
  • Technologies Companies (Apple, Google, Microsoft, etc) – security breaches aren’t communicated in email and access confirmation emails are expected communication. If you receive an unexpected access message DO NOT click on any links in the email to investigate. Log into your account independent of the email and check for notifications. If your actions didn’t trigger the notification, deny the access request and report it to your provider. Verify that the email sources are genuine. 
Use the Preview Feature if Your Email Client Has One

Use caution when opening emails from the following sources. Avoid clicking links embedded in an email and NEVER open any attached documents or files

  • Retailers –  online shopping can result in lots of advertising emails. Verify that they are genuine and consider un-subscribing. Better yet, opting out of most email interactions when making purchases 
  • Shopping Sites (Amazon, eBay) – scammers often try to mask as Amazon or eBay. Verify that the email sources are genuine.
Don't Trust Spam Filters To Catch Everything

NEVER OPEN emails if the following is true. NEVER click any embedded links in questionable emails, and NEVER open any attached documents or files

  • Missing Subject Lines –  Emails missing a subject line are usually caught by spam filters but some can make it through 
  • Garbled or Nonsense in the Subject Line – If the subject is not clearly readable in English or any other languages that you commonly speak
  • Spelling or Grammar Errors in the Subject Line – Spammers and scammers oftentimes aren’t native speakers and make obviously sometimes comical mistakes. Filters usually catch these but not always

Where You Open Your Email Matters

Your physical location and the wireless network used to access emails matter! Some networks are much more secure than others. When traveling away from a trusted network, use cellular data or a reputable US-based VPN (Virtual Private Network). Public wireless networks in the United States are generally considered as safe but it is important to be aware of who’s network you are using.

tea shop laptop users
Avoid Using Open, Public WiFi Networks to Access Email

Here are some guidelines

Safer

You can consider these locations mostly safe for accessing email

Private Corporate Networks
Personal Networks with
Security Features Enabled
Friends Networks with
Security Features Enabled
Cellular Networks in the
United States and Canada
Foreign Cellular Networks
When a VPN is Used
Public WiFi When a VPN is Used

Caution

You should exercise caution when accessing these networks

Personal Networks
with Poor Security
Neighbors Networks With Unknown Security
Public WiFi in the United States

Warning

You should avoid accessing email in these situations

Public WiFi in Foreign Countries Without Using a VPN
Foreign Cellular Networks Without Using a VPN

Changing Your Email Provider

Still Using the Same Email Provider from the 90's?

It is time to let go of those relics of a bygone era. Email service from that favorite 90s search engine or online provider is likely to have some serious privacy and security issues associated with their use. Don’t let history or sentimentality cloud your judgment.

What price are you paying for your free email service?

Avoid

The following email service providers have serious security and privacy issues and accounts should be closed and moved. 

AOL
Yahoo!

Useable

The following email service providers have documented issues but are industry leaders and can be used safely

Apple
Google
Microsoft

Safer

The following providers are in the business of providing more secure email and have policies in place to protect privacy

Protonmail
Hushmail
Tutanota
Runbox
Consider obtaining your own domain

Even personal email accounts can benefit from your own domain. Having your own domain will allow you to transfer between email providers without having to notify a large number of people about changes in your email. Avoid domain provider bundled email services and shop for domain and email services independently.

Use Multiple Email Accounts

Separate Email Accounts into Specific Functions

Having multiple email accounts can seem overwhelming to manage at first but grouping accounts by function helps contain security vulnerabilities and protects your privacy. Using an email client like Apple Mail or Thunderbird allows you to consolidate all your accounts into one place.

Personal

Creating and managing multiple accounts is easier with your own domain but can be done with a combination of free or paid email providers

Master or Administrators Account

Use a master email account for banking or financial institutions and as a recovery account for your Personal Account. This address should be used very sparingly.

Personal Account

Share this email account with close friends and family. Use this account as the recovery account for shopping and social media email account.

Social Media Account

Create an email account specifically for social media. Use this email for all social media interaction

Shopping Account

Create an email account specifically for shopping (Amazon, eBay, etc) and for paying non-credit card bills electronically

Business

Larger businesses tend to operate numerous email accounts but this can also be very beneficial for very small businesses or freelancers as well

Master or Administrators Account

Use a master email account for domain registration, or accounts banking and financial institutions, and as a recovery account for your Personal Account. This address should be used very sparingly.

In many businesses, this account is held by the IT Department or the business owner and a backup person exclusively.

Staff Account

Create accounts for each staff member so they can interact with co-workers, clients, business partners, and vendors.

Marketing Account

Use this account for marketing functions like email campaigns and social media accounts

Information Account

Use this account for responses to contact forms, order confirmations, and status emails

Mailboxes at the Smithsonian National Postal Museum

Conclusion

Changing email behavior will go a long way toward reducing the risk of being victimized by criminals. Education is one of the most powerful tools to prevent users from falling for some of the more common scams. Use the “Report Spam” feature to help your email provider identify and block messages for you and others.

Scams and Ransomware Attacks are Criminal Acts

Shockingly, a large number of ransomware attacks go unreported. If you are a victim of a cybercrime, report it to authorities.

DISCLAIMER:

The information presented above comes from personal and client experiences and is my opinion of best practices.  I am not receiving compensation from any of the sites, products, or services that I mention in this posting.

Resources

I’d like to thank the authors of the following blogs and websites. Their work provided some background research for this article.

Leave a Comment

Your email address will not be published. Required fields are marked *