Skip to content

Home Topics Email Security Management Mailbox account takeover

Email Security Management · Mailbox account takeover

2 common email account takeover mistakes and how to fix them

Short answer

The most common email account takeover mistakes are: sMS-based MFA for high-value accounts; not checking forwarding rules after remediation.

A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.

Mistake 1: SMS-based MFA for high-value accounts#

Why it hurts: this undermines email account takeover at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.

Mistake 2: Not checking forwarding rules after remediation#

Why it hurts: this undermines email account takeover at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Review third-party OAuth grants monthly and restrict user consent.

Frequently asked questions#

What are signs of a compromised email account?

Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.

Keep reading on Mailbox account takeover