Audit the recovery options on every important account. A reset route pointing at an old mailbox or a number you no longer use is a way in that no password protects.

The route that bypasses the password

A strong unique password and two-factor protect the front door.

The reset process is a separate door, designed to let somebody in when they have lost the key, and it is protected by whatever recovery details were set up at the time.

Which for most accounts is an email address chosen years ago and a phone number that may have changed.

Somebody attacking the account does not need to defeat the password. They need to control whatever the reset process sends to.

What the reset relies on

The first two are where the problems are, since both were set once and neither is reviewed, and both can end up pointing somewhere you no longer control.

The addresses that go stale

The most common problem and the least dramatic.

A recovery address at a former employee's mailbox, which the business may still hold or may have closed.

An address at a domain you stopped using, which may have lapsed and been registered by somebody else.

A personal address belonging to whoever set the account up, who no longer works there.

Each of those means the reset route points at a mailbox the business does not control, which is either a lockout waiting to happen or a way in for whoever does control it.

The lapsed domain case is the serious one, since anybody can register an expired domain and receive mail sent to it.

Phone numbers are weaker than they look

Worth understanding, since a text message feels secure and is the weakest of the common options.

A phone number can be moved to a different device by somebody who persuades the carrier to do it, which happens and is a known route.

It also stops working entirely when a number changes, which is an ordinary event nobody connects to their accounts.

Where a service offers a choice, an authenticator application or a hardware key is stronger than a message to a number.

Where a number is the only option, keep it current and treat it as a weaker protection rather than a strong one.

Remove a number entirely once you have a better method configured, since an old recovery route left in place remains usable.

A worked example

A business reviewed the recovery settings on their main accounts for the first time.

Their hosting account listed a recovery address at a domain they had let lapse three years earlier.

Their accounting software listed a personal address belonging to a bookkeeper who had left in 2019.

Two accounts had phone numbers that were no longer in service.

Nothing had gone wrong, and any of those was a route in or a lockout depending on who found it first.

Correcting all of it took about forty minutes across nine accounts, and the lapsed domain was the one that had been genuinely dangerous.

What to set them to

Since the fix is a decision about where to point them.

Use a business address you control, on a domain you will keep, rather than a personal one.

Do not use the account itself as its own recovery address, which several services allow and which achieves nothing.

Consider a dedicated address used only for account recovery, not published anywhere, with its own strong protection.

Make sure that address is reachable by more than one person, so recovery does not depend on somebody's availability.

And protect it as carefully as the accounts it can reset, since it is now the most valuable mailbox in the business.

The support process is a route too

The one you cannot configure and should know about.

Most providers have a human process for somebody who has lost everything, requiring proof of identity or of business ownership.

That process exists to help you and it can be attacked, by somebody assembling enough public information to sound convincing.

You cannot switch it off, and you can make it harder by keeping your account details accurate, since a mismatch is what the process checks against.

Some providers offer enhanced protection that restricts this route, and for a domain registrar in particular that is worth asking about.

A registrar lock, which prevents transfers without extra steps, is the equivalent measure and takes minutes to enable.

Review it on a schedule

Since these details go stale silently.

Once a year, open the security settings on every account that matters and read the recovery options.

Check the address still exists and is controlled by the business, and check the number is current.

Do it at the same time as reviewing who has access, which is the same set of pages.

And do it whenever somebody leaves, since a departure is the event most likely to leave a recovery route pointing somewhere wrong.

Test one, carefully

Since reading a setting tells you what it says and not whether it works.

Pick one non-critical account and go through its recovery process deliberately, to see where the message actually arrives.

That confirms the address is reachable, that somebody is watching it, and that the process is what you assumed.

Do not do this on the account that controls everything else, and do not do it on a Friday afternoon.

Businesses that try this occasionally find the reset message going somewhere nobody has opened in years, which is exactly the finding the exercise is for.

The counter-case

Recovery routes exist for good reasons.

Removing every option in pursuit of security produces an account nobody can get back into, which is a more likely outcome for a small business than an attack.

The balance is to keep the routes and make sure they point somewhere the business controls, rather than to eliminate them.

And the effort should be proportionate: email, hosting, the registrar, and anything financial deserve this, and a newsletter tool does not.

Audit the important accounts annually, point recovery at a business address with more than one owner, and lock the registrar.

The audit

  1. List the accounts that matter.
  2. Read the recovery options on each.
  3. Check the address still exists and is yours.
  4. Check the number is current.
  5. Point recovery at a business address.
  6. Remove old routes once a better one exists.
  7. Enable the registrar lock.

Step three is where the dangerous cases turn up, since a recovery address on a lapsed domain can be received by whoever registered it next.

Reading what has already happened on those accounts is covered in logins from places you have never been.


Frequently asked questions

Why does the reset route matter?

Because it bypasses the password entirely. An attacker does not need to defeat your password, only to control whatever the reset process sends to.

What goes wrong most often?

Recovery addresses that go stale: a former employee's mailbox, an address on a domain you let lapse, or a personal address belonging to somebody who has left.

Why is a lapsed domain dangerous?

Because anybody can register an expired domain and receive mail sent to it, including a password reset for your hosting account.

Are phone numbers secure?

They are the weakest common option. A number can be moved to another device by somebody persuading the carrier, and it stops working entirely when you change numbers.

Where should recovery point?

A business address on a domain you will keep, reachable by more than one person, protected as carefully as the accounts it can reset. Never the account itself.

What about the human support process?

It exists to help you and can be attacked by somebody assembling enough public information. Keep your account details accurate, and enable a registrar lock on your domain.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Never read your hosting account's recovery settings?

Open them now. A recovery address on a domain you let lapse is a way in that no password protects.

Start a Conversation