Treat the mailbox as part of your business

Your email may hold customer conversations, invoice copies, job addresses and password-reset messages. A small business can rely on one mailbox for much more than sending notes.

List the accounts connected to that address and who can access it. Identify the people who send invoices or approve changes to payment instructions. This makes the next security checks specific to the way your business operates.

Start with the mailbox you use every day. A useful review is one you can finish and repeat when a staff member, device or service changes.

Strengthen sign-in and recovery

Use a long, unique password and a password manager. Turn on multifactor authentication, which adds another check to sign-in. Do not approve an unexpected authentication prompt.

The FTC's small-business cybersecurity guide recommends strong passwords, multifactor authentication and software updates. Follow your email provider's current setup instructions, including its recovery options.

Keep recovery codes in a protected place you can reach if the usual device is lost. If several people need access, use the provider's account or delegation features instead of passing one password around. Review access when a person leaves.

Verify changes to payment details separately

Imagine receiving a message that appears to come from a familiar supplier, but asks you to pay an invoice to a new account. The familiar name and conversation history are not enough to verify the change.

Call through a number already in your records or use another established contact method. Do not use the new number supplied in the suspicious message as your only check. The FTC's phishing guidance recommends verifying questionable messages through a known, genuine contact.

Use the same principle with your own customers. Have a consistent process for explaining and verifying genuine payment changes. Make sure anyone who handles invoices knows when to pause for confirmation.

Check messages and protect the sending domain

Review unexpected attachments, links and urgent demands before acting. The FTC's small-business scam guide describes impersonation, fake invoices and pressure to act quickly.

For email sent from your own domain, ask the email provider to help configure SPF, DKIM and DMARC. These authentication tools help receiving systems evaluate messages claiming to come from that domain. The FTC cybersecurity guide explains their roles.

Authentication does not replace checking a request, and it does not stop every scam. Keep genuine invoices consistent enough that a customer can verify the sender, reference and payment instructions without relying on an unfamiliar link.

Know what to do if something looks wrong

If you suspect a mailbox compromise, contact the email provider or your IT support through a known channel. Describe the unexpected activity and follow the provider's recovery process. If a payment may be affected, contact the payment provider promptly.

Keep copies of suspicious messages and the time you noticed them. Depending on what happened, you may need to address customer information, account access or a payment as well as the mailbox itself. The FTC's data breach response guide gives businesses a place to start planning those steps.

Use the Security Checklist to turn these checks into a routine. Keep a backup of important business records as well; our cloud sync and backup guide explains why the two are different.

Give yourself a repeatable checklist.

Use the free Security Checklist to review accounts, devices, backups and recovery details.