Skip to main content
.com domains from $2.99 — free WHOIS privacy on every name

Account hardening · Beginner · 30 minutes

How to secure your email account — Your Mailbox Is the Reset Endpoint for Everything Else

A password change feels like the end of an incident, and the forwarding rule the intruder left behind is still copying every message out.

The short answer

Work out the blast radius before you choose the controls: your mailbox is where password resets for the bank, the registrar and the hosting account arrive, so its security is the ceiling on the security of everything it can reset.

Then treat it as two doors rather than one. The mailbox has its own credential; the control panel has another, and anybody inside the panel can read or reset every mailbox on the account without needing the mailbox password at all. Both get unique generated passwords and both get a second factor.

By the HostingFast team · Reviewed 24 August 2026

Beginner

Difficulty grade

30 minutes

Time budget

5

Stages

24/7

Engineer cover

This is a hardening pass rather than an incident response, though the audit step doubles as one. It assumes you can open webmail and the control panel.

The part people leave out is persistence: what an intruder installs so that access outlives the password change. That gets a section of its own, because a mailbox declared clean with a forwarder still running is not clean.

Model the blast radius first

List what can be reset through this mailbox: hosting, registrar, payment processor, analytics, the CRM. Anything whose recovery flow ends in an email lives underneath this account's security, whatever its own password strength happens to be.

Now note which door is worth more. The control panel can read every mailbox on the account and change their passwords, so it sits above the mailbox in the hierarchy — and it is the one people protect less, because it feels like an administrative tool rather than a private inbox.

Credentials: unique, generated, and separate per door

Mailbox, control panel and client area are three credentials, not one. Generate all three in a password manager and let them be long and meaningless; you are never going to type them from memory anyway.

Reuse is what makes breach dumps dangerous. Credential-stuffing runs try leaked pairs against mail servers within hours of a dump circulating, and a password that is unique to this mailbox is simply absent from that dataset.

Persistence: what an intruder leaves behind

Brief access is enough to plant a silent forwarder, plus a filter that moves anything mentioning the forward straight to Trash so the evidence disappears. A password change closes the front door and leaves that pipe running.

So read both lists in full — forwarders and filters — and delete anything you did not create yourself. Then revoke app passwords, which are long-lived credentials that bypass two-factor by design, and sign out any sessions or connected clients you no longer recognise.

Transport and access hygiene

Use IMAP over TLS on 993 or POP over TLS on 995, and switch off the plaintext ports if nothing needs them. Encrypted IMAP with a unique password is not the weak link people imagine; unencrypted authentication over a hotel network is.

Check last-login records where the panel offers them, and let the platform do its share: spam and virus screening runs on every mailbox as standard, and DDoS filtering is absorbed at the network edge rather than arriving at your account.

The network filtering that soaks up attacks before they reach a site

The platform this hardening pass was run on

Every setting named here exists in the account you would be given — cPanel, webmail, the same two-factor implementation — so the audit describes your screens rather than a generic checklist.

Mailboxes on your own domain are part of the plan, with IMAP, POP and SMTP included; email is never sold back to you at the checkout.

  • Blast radius modelled first
  • Two doors, two credentials
  • Persistence hunted, not assumed gone
  • Engineers on shift at any hour

Why HostingFast

Standard on every plan

Blast radius modelled first

Work out what the mailbox can reset before deciding how hard it is worth defending.

Two doors, two credentials

The panel and the mailbox are separate entrances and should never share a key.

Persistence hunted down

Forwarders, filters and app passwords are how access survives a password change, so they get their own pass.

App passwords in scope

Long-lived credentials that bypass two-factor by design, named and dealt with rather than forgotten.

Transport checked

IMAP and POP over TLS with the ports stated, and the plaintext ones switched off where nothing needs them.

Screening and edge filtering included

Spam and virus scanning on every mailbox, with DDoS filtering absorbed at the network edge.

Quick Start

From order to online

  1. 1

    List what this mailbox can reset

    Hosting, registrar, payments, analytics. Five minutes with a password manager's list tells you exactly how much sits underneath this one account.

  2. 2

    Generate separate credentials for both doors

    One for the mailbox, one for the control panel, neither reused anywhere else, both stored in a manager rather than remembered.

  3. 3

    Enable two-factor on webmail and the panel

    The panel matters more, because access to it means access to every mailbox on the account without needing any mailbox password.

  4. 4

    Audit forwarders, filters and app passwords

    Read both lists end to end and delete anything you did not create. Revoke app passwords that no longer match a device you still own.

  5. 5

    Review protocols, sessions and last-login records

    Turn off the plaintext protocols nothing uses, sign out unrecognised sessions, and check the last-login data where the panel provides it.

Built In

Loaded onto every plan

  • Spam and virus screening on every mailbox as standard
  • DDoS filtering absorbed at the network edge
  • Mailboxes on your own domain, included with the plan
  • IMAP, POP, SMTP and browser webmail on every mailbox
  • Daily backups with restores you trigger yourself from the panel
  • cPanel — the panel most of the industry already automates against
  • 99.9% uptime as the target, monitored around the clock
  • Staging environments for testing before anything ships
  • NVMe SSD storage on every tier, not just the expensive ones
  • Engineers on shift every hour of every day, not a queue that opens at nine

Frequently Asked

What people ask us most often

Which setting or log tells me a mailbox is already compromised?

Four places: the forwarder list, the filter list, the Sent folder and any last-login record the panel exposes. A forward you did not create, a filter that deletes messages mentioning it, sent mail you did not write, or a login from a country you have never worked in — any one of those means reset and audit now rather than later.

Are app passwords safer than the account password?

They are more scoped and less safe in one specific way: they exist to let an application authenticate without a second factor, so a leaked app password walks straight past your two-factor setup. Issue one per device, name them so you can tell them apart, and revoke them the moment the device is retired.

What does moving up a tier actually involve?

You upgrade in place. Plan changes happen from the client area with zero migration and zero downtime, and the range runs from compact shared accounts through VPS up to full dedicated servers. Growth becomes an account setting, not a hunt for a new host.

Do you handle the migration, and what does it cost?

Yes. Open a ticket with your current host's login details and we bring everything across — files, databases, mailboxes, configuration. You review the copy before DNS moves, and your old site keeps taking traffic right up until the new one is serving it, so visitors never hit a gap.

Keep reading

Changing hosts? Run through our checklist first.

A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.

You'll get the checklist email, then occasional pointers on keeping a site running fast. Unsubscribe the moment you want out — the privacy policy covers the rest.

Lock the door that opens all the others.

Free SSL, free migration, renewal at the rate you signed up at, and engineers on shift around the clock.

View VPS Hosting plans