Secure the Parent's Email First

The parent's email is the master key: reset a password for the bank, the brokerage, Medicare, or any other account and the reset link lands in the inbox. Secure the inbox and the family protects everything at once. This page is the 30-minute setup and the checks that catch a takeover early.

Last reviewed August 2026 Reading time: 6 minutes

email first, because email unlocks the rest

The 30-minute email security setup

Almost every account recovery flows through email: an attacker who controls the inbox can reset the parent's bank password or lock the family out. The 30-minute setup makes that mailbox the hardest target in the family's life.

  1. Minute 1-10Unique password + two-factorChange the email password to one not reused anywhere else, a passphrase the parent can type. Turn on two-factor authentication: the single most effective login protection, and the email account with 2FA is the one account a scammer cannot quietly reset.
  2. Minute 10-20Recovery optionsAdd a recovery phone and email so the family can get back in after a forgotten password, and keep the paper backup with the recovery codes. If the recovery options show something unrecognized, an attacker set it: change it immediately.
  3. Minute 20-25Check the forwarding rulesAttackers quietly add a forwarding address so copies of every email go out the door. Checking that no unknown forwarding address exists takes one minute and is the single best early-warning check.
  4. The early-warning checksSent mail and login alertsEmails the parent did not send mean the account is already compromised, so follow the 60-minute response. Enable login alerts so the family hears about a takeover the day it happens. The parent stays in charge; the family does the setup with them, not for them.

Why email first: almost every account recovery flows through email. An attacker who controls the inbox can reset the parent's bank password, drain a brokerage, or lock the family out. The hacked-account response starts with email for the same reason.

The 30-minute email setup

  1. Change the password to a unique one. The parent's email password must not be reused anywhere else. A passphrase the parent can type (three or four unrelated words) beats a short jumble, per the passwords-first guide.
  2. Turn on two-factor authentication. The FTC's phishing guidance and CISA's Secure Our World campaign both recommend it as the single most effective login protection. The parent-friendly 2FA setup covers the practical choices.
  3. Add a recovery phone and email. If the parent forgets the password, the recovery option is what gets the family back in. The recovery-codes guide explains the paper backup for the same reason.
  4. Check the forwarding rules. Attackers quietly add a forwarding address so copies of every email go out the door. Checking that no unknown forwarding address exists takes one minute and is the single best early-warning check.

The checks that catch a takeover early

  • Sent mail. Emails the parent did not send (password resets, money requests) mean the account is already compromised; follow the 60-minute response.
  • Login alerts. Most email providers can notify on new-device logins. Enabling the alert means the family hears about the takeover the day it happens, not the week after.
  • Recovery options. If the recovery phone or email is one the parent does not recognize, an attacker set it. Change it immediately.

Where the family fits

The parent stays in charge of the account; the family does the setup with them, not for them. The before-taking-over rule applies: this is protection, not a takeover, and the refusal playbook covers the parent who pushes back.

Related guides

Sources & verification

This page is checked against the standards in our editorial policy, preferring government sources for security guidance. Reviewed August 2026:

Found an error? Report it: we log and correct material mistakes publicly.

Quick answers

Common questions, answered plainly. The details match the sources above.

Why does email matter more than the other accounts?

Because almost every account recovery flows through email. Whoever controls the inbox can reset passwords for the bank, brokerage, Medicare, and more, so securing email protects everything at once.

What is the single most important step?

A unique password plus two-factor authentication. The FTC and CISA both recommend 2FA as the most effective login protection, and a password the parent does not reuse anywhere means one leak does not become every account.

Found an error? Report it.