Quick check: open Gmail or Outlook settings and look at filters and forwarding. If a rule forwards mail out or skips the inbox and you don't remember making it, delete it and change your password.
Haven flags rules like that too, in beta on Win/Mac: https://t.co/bHOeIBeEEo
@CRANamibia Nice one. If you've reused passwords in the past, change your email password first, since that's where reset links for every other account land. Then sign out of old sessions on that account so nobody stays logged in.
@Officialwhyte22 Good catch looking at the mailbox itself. If you hit a rule like that, search every mailbox for rules that match words like invoice, payment or wire, since attackers often seed the same rule in more than one account.
@Gozar_4 Solid advice. One cleanup step people skip: after importing everything into the manager, delete the saved passwords left in each browser and the CSV you imported from. Those leftovers are the easiest thing for malware to grab.
@WheelHouseIT Totally. Once it's on, set up a second method too (an authenticator app plus saved recovery codes). Then losing your phone doesn't lock you out. Also worth adding a port-out PIN with your mobile carrier if SMS is still a fallback anywhere.
@jmwein@ChanduThota Agreed on expiry. Until Drive adds it, a quick quarterly pass on files shared as "anyone with the link" and switching old ones to restricted closes most of the gap. I work on Haven, an on-device scanner for risky shares like that: https://t.co/bHOeIBe6OQ
Search your mailbox for has:attachment plus passport, W-2, or license. Scans you emailed to yourself or a landlord years ago are still sitting in Sent. Save what you need somewhere locked down and delete the rest.
Haven is in beta on Windows and Mac if you want a desktop pass at mail and files — https://t.co/9TYHJbhSsf
@betterwaytobank Great kickoff tip. One related habit: if you've ever logged in on a shared or family computer, check that browser's saved passwords and remove yours. "Save password?" on a shared PC quietly hands every account to the next user.
@myumbbank Great reminder. Practical version: if a call, text, or email asks for money or info, hang up and call back using the number on your card or the official website, never the one in the message. Real requests survive a callback.
@kiing_vamp Love this one. Same idea applies to files: old "anyone with the link" shares in Drive/Dropbox rarely expire, so a quick sweep of what's still shared publicly is worth it. I work on Haven, an on-device scanner for that kind of thing: https://t.co/bHOeIBeEEo
@mypasswordsapp Solid tip. One more layer for SIM swaps: call your carrier (or check the app) and set a port-out PIN / number lock. It's free on most carriers and makes it much harder for someone to move your number without you.
@simonAI_X Great setting. One add: before you go all-in on passkeys, keep a second way back in (a passkey on another device or a hardware key), so losing or resetting your phone doesn't lock you out of everything at once.
Once a quarter, search Downloads and Desktop for Google Takeout or mailbox export zips. Those archives are a full copy of mail and files. Delete them when you're done restoring, or they'll sit where backups and sync can pick them up.
Haven is in beta on Windows and Mac if you want a desktop pass at mail rules and sharing — https://t.co/9TYHJbhSsf
@ReadyWisconsin Solid list. One more quick win for Awareness Month: check mailbox forwarding rules and filters — quiet rules can survive a password reset and keep forwarding mail out.
@Michael_Mofic Good instinct. I’d also periodically open your account’s connected-apps / third-party access list and revoke anything you don’t recognize or no longer use — those OAuth grants often outlive the password you thought you rotated.
@StellarTimeLock@_GHSofficial Yes — separate storage is the whole point. Printed codes in a drawer (or a different vault) beat a phone backup that disappears with the same device that held your authenticator.
@ProfSimonOnline This is the checklist that matters. After any suspicious login I’d also open Gmail Settings → Forwarding and Filters, revoke unfamiliar connected apps, and sign out unknown sessions — a password change alone doesn’t clear those paths.
Agreed — a password manager is the highest-leverage habit. Once you’re in, prune old entries, delete leftover plaintext exports, and keep recovery codes out of the same place as the passwords. Haven is in beta for a desktop, on-device-by-default exposure check: https://t.co/9TYHJbhSsf
Once a year, open the account recovery page and look at the email and phone on file. If either is an old job address or a number you don't control, change it before you need it. A reset goes to whoever still has that inbox.
Haven is in beta on Windows and Mac if you want a desktop pass at mail rules and sharing — https://t.co/9TYHJbhSsf
@Jamiwyn@binance Losing a passkey should stay a high-friction, human-verified recovery — not something an AI agent can trigger on its own. Keep a second registered key and printed recovery codes offline so you’re not stuck waiting on a ticket.