Skip to content

Home Topics Email Security Management Mailbox account takeover

Email Security Management · Mailbox account takeover

How to set up email account takeover: step-by-step guide (2026)

Short answer

To set up email account takeover: Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance; Review third-party OAuth grants monthly and restrict user consent; Alert on impossible-travel logins and mass downloads. Then have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.

A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.

How to implement email account takeover#

  1. Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
  2. Review third-party OAuth grants monthly and restrict user consent.
  3. Alert on impossible-travel logins and mass downloads.
  4. Have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.

How to verify it worked#

Send a test message to seed mailboxes at Gmail, Outlook, and Yahoo, then inspect the Authentication-Results and delivery headers. Repeat after any DNS or sending-platform change.

Common mistakes#

  • SMS-based MFA for high-value accounts.
  • Not checking forwarding rules after remediation.

Frequently asked questions#

What are signs of a compromised email account?

Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.

Keep reading on Mailbox account takeover