The settings that actually stop someone from getting into your account

Most email hacks happen because the password is weak or reused, not because the email system itself is broken. But the settings inside your email account can make it much harder for a hacker to stay in even if they do get your password. The three that matter most are two-factor authentication (a second proof you're really you), recovery options (a way to get back in if you're locked out), and app passwords (separate passwords for older programs that can't handle two-factor). Setting these up takes about 20 minutes and closes the gaps that hackers actually use.

This guide covers Gmail, Outlook, and Yahoo — the three services that handle most personal email in the United States. The steps are slightly different for each one, but the logic is the same: you're telling the service who you are, how to reach you if something goes wrong, and which devices are allowed to use your account.

Key Takeaways

  • Two-factor authentication requires a second proof of identity — usually a code from your phone — and stops most hacks even if your password is stolen.
  • Recovery options (a backup email address and a phone number) let you regain access if a hacker locks you out, and should not be the same as your main email.
  • App passwords are separate, one-time passwords for older programs like Outlook desktop or Apple Mail that cannot handle two-factor authentication.
  • Reviewing your connected apps and devices every few months removes access from programs you no longer use.
  • Security keys — small USB devices or phone apps — are stronger than codes sent by text, but optional unless you handle sensitive information.

Two-factor authentication: the second lock on your door

Two-factor authentication means you prove who you are in two ways instead of one. The first is your password. The second is usually a code that appears on your phone, either through an app or a text message. A hacker who steals your password still cannot get in without that second code, and they cannot intercept it unless they also have your phone.

For Gmail: Go to myaccount.google.com, click "Security" in the left menu, scroll to "How you sign in to Google," and click "2-Step Verification." Google will ask you to confirm your password, then offer you a choice: receive codes by text message, or use the Google Authenticator app (which works even without cell service). Text is simpler; the app is safer because a hacker cannot intercept a code that never leaves your phone. Choose one, follow the prompts, and save the backup codes Google gives you in a safe place — you'll need them if you lose your phone.

For Outlook: Go to account.microsoft.com, click "Security" at the top, then "Advanced security options." Click "Two-step verification" and choose whether to receive codes by text, phone call, or the Microsoft Authenticator app. Outlook will send you a test code to confirm it works. Like Gmail, save your backup codes.

For Yahoo: Go to account.yahoo.com, click "Account security" in the left menu, and click "Two-step verification." Yahoo offers text message or the Yahoo Mail app. Complete the setup and store your backup codes.

Recovery options: how to get back in if you're locked out

A recovery option is a second way to prove you own the account if you lose access to your main phone or password. It is usually a backup email address or a phone number. The key is that it should not be the same as your main email — if a hacker takes over your main email, they can use the same address as a recovery option and lock you out completely.

For Gmail: Go to myaccount.google.com, click "Personal info" in the left menu, and look for "Email" and "Phone number." Add a backup email address (a different account you control, like one from work or a family member's domain) and a phone number where you can receive calls or texts. Do not use the same Gmail address as your recovery email.

For Outlook: Go to account.microsoft.com, click "Your info" at the top, and look for "Email addresses" and "Phone numbers." Add a backup email and a phone number. Outlook will send a code to confirm each one works.

For Yahoo: Go to account.yahoo.com, click "Account info," then "Phone number" or "Email address." Add both a backup email and a phone number. Test them by having Yahoo send you a confirmation code.

App passwords: letting older programs sign in safely

Some older programs — like Outlook desktop on Windows, Apple Mail, or some printers that scan to email — cannot handle two-factor authentication. They need a password, but you should not give them your real password, because they store it in plain text and a hacker who finds it could use it to sign in without the two-factor code.

The solution is an app password: a separate, one-time password that only works for that one program. If the program is hacked or the password is stolen, the hacker can only use it in that one place, not to sign into your email on the web or on your phone.

For Gmail: Go to myaccount.google.com, click "Security," scroll to "App passwords" (this option only appears if you have two-factor authentication turned on), and select the app and device you want to use. Google generates a 16-character password. Copy it into the program's password field — do not try to remember it or type it by hand. Google will not show it again.

For Outlook: Go to account.microsoft.com, click "Security," then "App passwords." Select the app and device, and Outlook generates a password. Copy it into the program. You can delete the password later from the same page if you stop using the program.

For Yahoo: Go to account.yahoo.com, click "Account security," then "Generate app password." Select the app and device, and Yahoo generates a password. Copy it into the program.

Reviewing connected apps and devices

Every time you sign into your email on a new device or in a new app, the service remembers it. Over time, you accumulate old phones, old computers, and programs you no longer use. A hacker who finds one of those old devices or breaks into an old program can use it to sign into your email without your knowledge.

For Gmail: Go to myaccount.google.com, click "Security," scroll to "Your devices," and click "Manage all devices." You will see every phone, computer, and browser that has signed into your account in the last few weeks. If you see a device you do not recognize, click it and select "Sign out." If you see a device you used to own but no longer have, sign it out. Do this every few months.

For Outlook: Go to account.microsoft.com, click "Security," then "Recent activity." You will see a list of devices and locations where you have signed in. Click "View all activity" to see older sign-ins. If you see something unfamiliar, click it and select "This wasn't me" — Outlook will ask you to change your password and will sign out all other devices.

For Yahoo: Go to account.yahoo.com, click "Account security," then "Recent activity." You will see devices and locations. Click on any entry to see details. If something looks wrong, click "This wasn't me" and Yahoo will ask you to change your password.

Security keys: the strongest option if you handle sensitive information

A security key is a small device — usually a USB stick or a key fob — that you plug into your computer or tap to your phone when you sign in. It is stronger than a code sent by text because a hacker cannot intercept it, and it cannot be fooled by a fake website that looks like Gmail or Outlook.

Security keys are optional for most people, but worth considering if you use your email for banking, business, or anything else that would cause real harm if a hacker got in. They cost between $20 and $80, and the most common brands are Yubico (YubiKey), Google (Titan), and Feitian. All three work with Gmail, Outlook, and Yahoo.

For Gmail: Go to myaccount.google.com, click "Security," then "2-Step Verification," and scroll to "Security keys." Click "Add security key," plug in the key or tap it to your phone, and follow the prompts. Add at least two keys in case you lose one.

For Outlook: Go to account.microsoft.com, click "Security," then "Advanced security options," and look for "Security info." Click "Add sign-in method," select "Security key," and follow the prompts.

For Yahoo: Go to account.yahoo.com, click "Account security," then "Two-step verification," and select "Security key" as an option alongside text or app codes.

What to do if you think your account has been hacked

If you notice sign-ins from places you do not recognize, or if you cannot sign in at all, act quickly. Change your password when ready from a device you trust — a computer or phone that you know is yours. Use a password that is at least 16 characters long and includes uppercase, lowercase, numbers, and symbols.

After you change your password, sign out all other devices (Gmail and Outlook both have a "Sign out all other sessions" button). Then review your recovery options and two-factor settings to make sure a hacker has not changed them. If you cannot sign in at all, use your recovery email or phone number to regain access. If you cannot reach those either, contact the email service's support team — they can verify your identity and help you back in, but it takes longer.

Frequently Asked Questions

Is two-factor authentication by text message really safe?

Text message is safer than no two-factor authentication, but not as safe as an app or security key. A hacker who has your password and your phone number can sometimes trick your phone company into sending codes to a different phone. If you handle sensitive information, use an authenticator app or security key instead. For most personal email, text is fine.

What if I lose my phone and cannot get the two-factor codes?

That is why you save backup codes when you set up two-factor authentication. Write them down or store them in a password manager, not in your email. If you lose your phone before saving the codes, use your recovery email or phone number to sign in, then turn off two-factor authentication temporarily and set it up again with a new device.

Do I need a security key if I just use email for personal messages?

No. Two-factor authentication by text or app is enough for most people. Security keys are worth the cost and effort if your email is connected to banking, business accounts, or anything else where a hack would cause real damage. For personal use, focus on a strong password and two-factor authentication first.

Can I use the same app password for multiple programs?

Technically yes, but do not. Each program should have its own app password. If one program is hacked or the password is stolen, the hacker can only access that one program, not all of them. It takes a few extra minutes to generate separate passwords, and it is worth it.

What if my backup email address gets hacked too?

Use a backup email from a different service — if your main email is Gmail, use Outlook or Yahoo as your recovery email. That way, a hacker who breaks into one service cannot use it to take over the other. Also add a phone number as a recovery option so you have two ways to get back in.