# Business email security: phishing and account protection

https://civema.com/en/knowledgebase/article/business-email-security-phishing-and-account-protection

Spam and malware filters reduce risk but cannot recognize every harmful message. Give each employee separate credentials, keep devices updated and use the official webmail address.

## Prevent fraud

Check real sender addresses and link destinations. Verify bank-detail changes or urgent payments using a previously known channel, not a number supplied in the suspicious message. Do not open unexpected executable files or enable document macros.

## Protect access

Enable supported two-step verification and store recovery codes safely. Do not assume web two-step verification protects every IMAP/SMTP client in the same way; confirm application-password requirements.

## If compromise is suspected

Change the password from a clean device, contact support, review forwarding and Sent mail, and request session and sending checks. Preserve timestamps and evidence. Never send passwords, API keys or recovery codes in tickets.

[View business email plans](https://civema.com/en/business-email)
