Identify which mailbox your accounts reset through, protect it above everything else, and make sure more than one person can reach it.

Work out which one it is

Most businesses have not identified it, because it was never chosen for the role.

It is whichever address was used when the domain was registered, the hosting was bought, the accounting software was set up, and the bank was arranged.

Frequently that is the owner's personal address, or a generic office mailbox several people can read, or an address at a domain that is itself registered through an account resetting to the same mailbox.

Somebody with that mailbox can reset almost everything else, in sequence, without needing a single other password.

Finding out which address it is takes ten minutes and is the first useful step.

How to identify it

The last is the definitive test. Trigger a reset on a low-stakes account and see which mailbox it lands in, which frequently is not the one anybody expected.

Why it is usually the weakest

The uncomfortable part, since the most valuable account is typically the least deliberately arranged.

It was set up years before the business had anything worth protecting.

Its password predates any password policy and may be reused elsewhere.

It may be a free personal account, chosen because it was convenient at the time.

It may be shared, with the password known to several people including some who have left.

And it is the account most likely to be receiving phishing attempts, because the address is published on the website.

What protecting it actually means

More than a strong password, though that first.

Two-factor on it, using an application or a hardware key rather than a message to a number.

Recovery options pointing somewhere else you control, since an account cannot usefully be its own recovery route.

A password used nowhere else, since a leak from an unrelated service otherwise hands over everything.

Forwarding rules and connected applications reviewed, since those are how access persists after a password change.

And access limited to the smallest number of people who genuinely need it.

Separate the roles

The structural improvement, and it is worth the small inconvenience.

The mailbox that receives account resets should not be the one published on your website and used for customer enquiries.

A published address receives phishing, gets shared, and is known to anybody who wants to attack you.

Create a separate address used only for account registration and recovery, not published anywhere, and move the important accounts onto it over time.

That single change removes the connection between the address attackers know and the address that controls everything.

It takes an afternoon of updating account details and it is the highest-return change in this whole subject.

A worked example

A business traced their accounts and found eleven of thirteen resetting to the owner's personal address, created in 2009.

It had no two-factor, a password he had used elsewhere, and a recovery phone number belonging to a phone he no longer had.

It was also the address printed on the website and on every invoice.

They created a new address on the business domain, used only for accounts, moved all thirteen onto it over an afternoon, and protected it with a hardware key.

The personal address stayed for correspondence and no longer controlled anything.

The exercise cost half a day and closed the route by which one leaked password could have taken the whole business.

More than one person must reach it

The business continuity half, which is a separate problem from security.

An account nobody but the owner can reach is a risk whenever the owner is unavailable, which happens for ordinary reasons.

Where the mailbox is on a business platform, add a second administrator who can restore access without the primary user.

Where it is a personal account, that is not possible, which is one of the stronger arguments for moving it onto something the business owns.

At minimum, hold the recovery codes somewhere the business can reach and make sure somebody else knows they exist.

The scenario to plan for is not an attack, it is an illness or a holiday during a domain renewal.

Watch it more closely than the rest

Since the consequences of a compromise here are different in kind.

Enable new-device alerts and send them somewhere read.

Check forwarding rules quarterly rather than annually, because a rule here copies the reset messages for everything else.

Look at the recent access list at the same time, which takes two minutes.

And treat any unexpected password reset message as an event worth investigating, since a reset you did not request means somebody is trying the route.

The domain sits underneath the mailbox

A dependency worth tracing, since it is circular in a way that surprises people.

If your recovery mailbox is on your own domain, and the domain registrar account resets to that same mailbox, then losing the domain loses the mailbox and losing the mailbox loses the domain.

A lapsed renewal, a transfer, or a registrar dispute takes both at once, with no route back into either.

Break the circle: point the registrar account at an address on a different domain, or at a well-protected account with a provider you do not host with.

Then set the domain to renew automatically, on a card that will not expire, and check the renewal date is not something you are relying on remembering.

The counter-case

This can be over-engineered.

A dedicated recovery mailbox that nobody checks is its own failure, since alerts and reset messages arrive there and go unread.

Splitting addresses also adds a small ongoing overhead, and a very small business may reasonably keep one well-protected mailbox instead.

The essential part is not the separation, it is that whichever mailbox holds this role is identified, strongly protected, and reachable by more than one person.

Find out which one it is, put two-factor on it, and stop using a personal address for it.

What to do

  1. Trigger a reset and see where it lands.
  2. Check the registrar and hosting account addresses.
  3. Put two-factor on that mailbox first.
  4. Use a password found nowhere else.
  5. Create a separate address for account recovery.
  6. Move it off a personal account.
  7. Make sure two people can reach it.

Step five is the structural fix, since the address attackers know and the address that controls everything should not be the same address.

Where a business mailbox should sit is covered in where your email should live.


Frequently asked questions

How do I find which account it is?

Trigger a password reset on a low-stakes account and see which mailbox it lands in. Also check the addresses on your registrar, hosting, and accounting accounts.

Why is it usually the weakest?

Because it was set up years before the business had anything worth protecting, often as a personal account, with a password predating any policy and possibly shared.

What does protecting it involve?

Two-factor with an app or key, a password used nowhere else, recovery pointing elsewhere, reviewed forwarding rules and connected apps, and minimal access.

What is the structural fix?

Separating the published enquiry address from the one that receives account resets, so the address attackers know is not the address that controls everything.

Why does more than one person need access?

Because the scenario to plan for is not an attack but an illness or a holiday during a domain renewal, when nobody else can reach the account.

What should I watch for?

New-device alerts, forwarding rules checked quarterly, and any password reset message you did not request, which means somebody is trying the route.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Accounts resetting to a personal address from 2009?

Trigger one reset and watch where it lands. That mailbox controls more than you think.

Start a Conversation