Back to Blog

Secure Email Practices: Encryption, Providers, and Habits That Protect You

LeakedSource Team
|

Why Email Security Matters

Email is the backbone of digital identity. It is the recovery mechanism for virtually every online account, the channel through which sensitive documents are exchanged, and the primary vector for phishing attacks. Compromising someone's email often means compromising everything connected to it: banking, social media, cloud storage, and work accounts.

Despite decades of advancement in cybersecurity, email remains built on protocols designed in an era when trust was assumed and encryption was optional. Securing your email requires deliberate choices at every level.

Choosing a Secure Email Provider

Not all email providers treat your privacy equally:

Privacy-focused providers:

  • ProtonMail offers end-to-end encryption by default between ProtonMail users, zero-access encryption for stored messages, and is based in Switzerland under strong privacy laws
  • Tutanota provides end-to-end encrypted email and calendar with servers in Germany, subject to strict EU privacy regulations
  • Fastmail does not offer end-to-end encryption but has strong privacy policies, no advertising-driven data mining, and excellent security features

Major providers with caveats:

  • Gmail offers strong account security features and excellent spam filtering, but Google's business model involves scanning email content for advertising purposes
  • Outlook/Microsoft 365 provides robust security in enterprise environments but processes data under Microsoft's broad privacy policies
  • Yahoo Mail has a history of large-scale breaches and advertising-driven data practices

Understanding Email Encryption

Email encryption exists at multiple levels, and understanding the differences matters:

Transport encryption (TLS) encrypts email in transit between servers. Most major providers now enforce TLS, which prevents eavesdropping during transmission. However, the email is decrypted and stored in plaintext on the provider's servers.

End-to-end encryption (E2EE) encrypts the message so that only the sender and recipient can read it. The email provider cannot access the content. PGP/GPG and S/MIME are the traditional standards. ProtonMail and Tutanota implement this transparently between their users.

The practical reality: End-to-end encryption only works when both parties support it. Sending an encrypted email to someone using standard Gmail results in the message being decrypted on Google's servers. For truly sensitive communications, both parties need compatible encryption.

Essential Email Security Habits

Use strong, unique passwords. Your email password should be the strongest password you have because email is the skeleton key to your digital life. Use a password manager to generate and store it.

Enable two-factor authentication. Use an authenticator app or hardware security key. Avoid SMS-based 2FA for your email account specifically, since SIM swapping attacks directly target this vulnerability.

Be methodical about phishing detection:

  • Verify the sender's actual email address, not just the display name
  • Hover over links before clicking to check the destination URL
  • Be suspicious of urgency, threats, or too-good-to-be-true offers
  • When in doubt, navigate to the purported sender's website directly rather than clicking links in the email
  • Check for subtle misspellings in domain names (paypa1.com vs paypal.com)

Treat attachments with suspicion. Even attachments from known contacts can be malicious if their account has been compromised. Be especially wary of unexpected attachments with extensions like .exe, .zip, .docm, or .js.

Use email aliases. Services like SimpleLogin, AnonAddy, or built-in aliasing features in ProtonMail and Fastmail let you create unique email addresses for each service you sign up for. If one alias starts receiving spam or appears in a breach, you know exactly which service leaked it and can disable just that alias.

Organizational Best Practices

For businesses and teams:

  • Implement SPF, DKIM, and DMARC records to prevent email spoofing of your domain
  • Deploy email filtering that scans attachments and URLs for known threats
  • Conduct regular phishing simulations to train employees to recognize attacks
  • Establish clear policies for sending sensitive information via email
  • Use encrypted file sharing instead of email attachments for confidential documents

The Recovery Email Problem

Your recovery email address is a critical vulnerability. If an attacker compromises your recovery email, they can reset passwords on all accounts linked to it. Secure your recovery email with the same rigor as your primary email. Consider using a separate, highly secured email address solely for account recovery purposes.

What to Do If Your Email Is Compromised

Act immediately:

  1. Change your email password from a trusted device
  2. Review and revoke any unfamiliar connected apps or sessions
  3. Check for email forwarding rules that an attacker may have created
  4. Change passwords on all accounts that use the compromised email for recovery
  5. Notify your contacts that your account was compromised, as the attacker may have sent phishing emails from your address

Check LeakedSource to find out if your email address and credentials have been exposed in data breaches, because a compromised email password is the first domino in a chain of account takeovers.

Check Your Breach Exposure

Find out if your email address has been compromised in any known data breaches.

Scan Your Email Now

LeakedSource Support

AI assistant — a human reviews escalated chats

This chat has been escalated to our support team — a human will reply here or by email. If you haven't shared your email yet, just type it here so we can reach you.
Hi! I'm the LeakedSource assistant. Ask me about scans, breaches, billing, or your account.