Changing your email password is an essential action that you should carry out regularly to keep your account secure. Whether you suspect that your password has leaked, have forgotten the password, or simply want to strengthen your security, changing your email password is fortunately easy. In this extensive guide we explain step by step how you can change your email password with different providers and in various email programs.

When should you change your email password?

There are various situations in which it is wise or even necessary to change your email password. Do you recognize one of the scenarios below? Then it is time to take action immediately:

  • Suspicion of unauthorized access - you see unknown activity in your account, such as sent messages you did not write or read receipts of emails you did not open
  • A data breach at a service - a website or service where you use the same password reports a data breach
  • A shared password - you have shared your password with someone who should no longer have access to it
  • Regular maintenance - it is a good habit to change your password every 3 to 6 months
  • A weak password - your current password is too short, too simple or contains personal information
  • A phishing incident - you accidentally entered your login details on a fake website
  • Departure of an employee - a colleague who had access to shared email accounts leaves the company

Changing your email password through your hosting provider

The most direct way to change your email password is through your hosting provider's control panel. Below we describe the process for the most popular control panels and providers:

Changing a password through cPanel

cPanel is one of the most used hosting control panels. Here is how to change your email password:

  1. Log in to cPanel (usually reachable through yourdomain.nl:2083 or yourdomain.nl/cpanel)
  2. Go to the Email section and click on Email Accounts
  3. Find the email address for which you want to change the password
  4. Click on Manage next to the relevant account
  5. Scroll to the Security or Password section
  6. Enter your new password in both fields
  7. Click on Update Password to save the change

Changing a password through DirectAdmin

DirectAdmin is another widely used control panel at Dutch hosting providers. The process is similar:

  1. Log in to DirectAdmin (usually through yourdomain.nl:2222)
  2. Click on Email Accounts under the Email Management heading
  3. Click on the email address you want to change
  4. Enter the new password and confirm it
  5. Click on Change to save the password

Changing a password through Plesk

Plesk is the third major control panel that is widely used:

  1. Log in to Plesk
  2. Go to Mail and select your domain
  3. Click on the email address for which you want to change the password
  4. Change the password in the field provided
  5. Save the change

Do you use email from a major provider? Below you will find the specific steps per provider to change your password:

ProviderWhere to changeSteps
Microsoft 365portal.office.comProfile > Change password
Google Workspacemyaccount.google.comSecurity > Password
TransIPmy.transip.nlEmail > Account > Password
Antagonistmijn.antagonist.nlEmail > Mailbox > Change
Versioklantengebied.versio.nlEmail > Manage > Password

Changing your email password in your email program

After changing your password with your provider, you also have to update the new password in all email programs and apps where you use this account. Otherwise you can no longer receive or send new emails. Below are the steps for the most popular email clients:

Updating the password in Microsoft Outlook

  1. Open Outlook and click on File
  2. Click on Account Settings and choose Account Settings
  3. Select the email account and click on Change
  4. Remove the old password and enter the new one
  5. Click on Next and then on Finish
  6. Outlook automatically tests the connection with the new password

Updating the password in Apple Mail (Mac)

  1. Open System Preferences (or System Settings in macOS Ventura and newer)
  2. Go to Internet Accounts
  3. Select your email account
  4. Click on the password field and enter the new password
  5. Close the window to save the change

Updating the password in Thunderbird

  1. Open Thunderbird and go to Settings (through the hamburger menu)
  2. Click on Privacy and Security
  3. Scroll to Passwords and click on Saved Passwords
  4. Find your email account in the list
  5. Click on Remove to delete the old password
  6. Restart Thunderbird, and you will be asked for the new password

Updating the password on iPhone and iPad

  1. Open Settings on your iPhone or iPad
  2. Go to Mail and then Accounts
  3. Tap the relevant email account
  4. Tap your email address at the top
  5. Change the password in the password field
  6. Tap Done to save

Updating the password on Android

  1. Open the Settings app on your Android phone
  2. Go to Accounts or Passwords and accounts
  3. Select your email account
  4. Tap Account settings
  5. Change the password in the field provided
  6. Save the change

Choosing a strong email password after changing it

Changing your password only makes sense if you choose a strong new password. A good email password meets the following criteria:

CriterionMinimumRecommended
Length8 characters14+ characters
Uppercase lettersAt least 1Several, spread out
Lowercase lettersAt least 1Several
DigitsAt least 1Several, not at the end
Special charactersAt least 1Several (!@#$%^&*)
Personal infoAvoidNever use

Tips for an uncrackable password

  • Use a passphrase - a phrase such as "MyCatEats3TimesADay!" is strong and easy to remember
  • Use a password manager - tools such as Bitwarden, 1Password or KeePass generate and store strong passwords for you
  • Never reuse passwords - each account should have a unique password to limit the risk in the event of a data breach
  • Avoid dictionary words - hackers first try known words and commonly used passwords
  • Do not use patterns - avoid consecutive digits (123456) or keyboard patterns (qwerty)

Extra security after changing your email password

Changing your password is a good first step, but there are additional measures you can take to secure your email account even better:

Enabling two-factor authentication (2FA)

Two-factor authentication adds an extra security layer on top of your password. After entering your password you have to perform a second verification, usually through a code you receive by SMS, through an authenticator app or through a physical security key. Even if your password is stolen, an attacker cannot log in without the second factor.

Checking login history

Most email providers offer the option to view your recent login activity. After changing your password, check whether there have been any suspicious login attempts from unknown locations or devices. With Microsoft 365 you find this under My account and Security, with Gmail under Recent security activity.

Revoking app passwords

If you have apps or services that use an app-specific password to access your email, revoke these after changing your main password. Then generate new app passwords for the services you still want to use.

Updating recovery details

Make sure your recovery details are up to date, so that you can regain access to your account if you forget your new password. This usually includes an alternative email address and a phone number. Check these details immediately after changing your password.

Frequently asked questions about changing your email password

How often should I change my email password?

It is recommended to change your email password at least every 3 to 6 months. If you use a strong, unique password and have enabled two-factor authentication, you can extend this period to 12 months. Change your password immediately if there are indications of unauthorized access.

What if I have forgotten my current password?

If you no longer know your current password, you can reset it through your provider's forgot-password function or through your hosting control panel. You then receive a reset link at your alternative email address or a verification code on your phone. If you have not set up any recovery details, contact your provider's customer service.

Do I have to change my password on all devices at once?

You change the password in one place: with your email hosting provider or in your provider's account management. Then you have to update the new password in all email programs and apps on all your devices. This is not a change, but an update of the stored password in each client.

Can my provider retrieve my password?

No, reliable email providers store passwords encrypted (hashed) and cannot retrieve your exact password. They can only reset it to a new password. If a provider claims to be able to give you your password in plain text, that is a serious security problem.

Changing your email password is a simple but important action that you should carry out regularly. By changing the password through your hosting provider and then updating it in all your email programs, you keep your account safe against unauthorized access. Combine a strong, unique password with two-factor authentication for the best protection. Do you not yet have a professional email address? Then start today with setting up your own email address with your domain name.

Changing your email password: security and best practices

Regularly changing your email password is an important part of your digital security. With the right approach you protect your email account against unauthorized access.

When should you change your password?

Change your password immediately if you suspect that someone else has had access, if you receive a warning about a data breach at a service where you use the same password, if you have entered your password through an unsecured connection, or if it is more than six months ago that you last changed it. Check through haveibeenpwned.com whether your email address is involved in known data breaches.

Choosing a strong password

A strong password is at least 12 characters long and contains a combination of uppercase letters, lowercase letters, digits and special characters. Even better is a passphrase: a series of four or more random words that you can easily remember but that is hard to guess. Never use personal information such as your date of birth, the name of your pet or the word password. Use a password manager such as Bitwarden, 1Password or LastPass to generate and securely store unique passwords.

Changing your email password per provider

The steps to change your email password differ per provider. Below you will find instructions for the most popular options.

Changing the password with your hosting provider

If your email runs through your hosting plan, you change the password through the control panel. In DirectAdmin you go to Email Accounts, click on the account, and enter the new password. After changing it you also have to update the password in all email programs and apps where the account is configured: Outlook, your mobile phone and any webmail access.

After changing: update all devices

After you have changed your email password, you have to enter the new password on every device on which your email is configured. This includes your desktop email program, the mail app on your smartphone and tablet, webmail in your browser, and any other applications that use your email. If you use IMAP, these programs will ask for the new password as soon as they try to synchronize.

Extra security measures for your email

A strong password is only the beginning. Take additional measures to protect your email account optimally.

Enabling two-factor authentication

Where possible, enable two-factor authentication (2FA) on your email account. With 2FA you need, in addition to your password, a temporary code from an authenticator app. This makes it virtually impossible for attackers to log in, even if they know your password. Most major providers (Gmail, Outlook.com, Yahoo) support 2FA as standard.

Recognizing suspicious activity

  • Unknown login activity - check the login history of your account regularly
  • Sent messages you did not write - a sign that someone else has access
  • Received password-reset emails - someone may be trying to take over your account
  • Changes to forwarding rules - attackers often set up automatic forwarding rules
  • Contacts reporting spam from your address - your account may be being misused

Read more about email security in our article about SPF, DKIM and DMARC and how to filter spam effectively.

Changing your email password: frequently asked questions

We answer the most frequently asked questions about changing your email password here. Do I have to change my password regularly? Security experts advise changing your password when there is a concrete risk (a data breach, suspicious activity), not on a fixed schedule. A strong, unique password with two-factor authentication is more effective than regularly replacing a weak password. What if I forget my password? Use your provider's forgot-password function or contact your hosting provider for a reset through the control panel. How do I synchronize the new password on all my devices? Update the password first on your primary device, then on your phone, and finally on other devices. Use a password manager to manage all your passwords centrally and securely.

Changing your email password: automation

Manually changing your email password on multiple devices is time-consuming. Use a password manager such as Bitwarden (free and open-source), 1Password or LastPass to streamline this process. A password manager generates strong, unique passwords and automatically synchronizes them between all your devices. When changing a password you update the password in one place and it is immediately available on all your devices. Combine a password manager with SPF, DKIM and DMARC for a complete email security strategy that protects both your password and your email traffic against misuse.

Changing your email password: summary

Regularly and correctly changing your email password is an essential part of your digital security. Always use a strong, unique password of at least 12 characters. Enable two-factor authentication for extra security. Update the password immediately on all devices after a change. Use a password manager to store all your passwords securely. Monitor your account for suspicious activity and respond immediately at signs of unauthorized access. At Theory7 you can easily change your email password through the control panel, and our customer service is happy to help you with any problems.

Changing your email password: best practices

Follow these best practices when changing your email password for optimal security. Use a password manager such as Bitwarden, 1Password or LastPass to generate and securely store strong, unique passwords. Enable two-factor authentication through an authenticator app (not through SMS, which is less secure). Change your password immediately when you suspect unauthorized access. Never use personal information in your password: no names, dates of birth or addresses. Never share your password through email or chat. Check regularly on haveibeenpwned.com whether your email address appears in known data breaches.

Changing your email password: on different devices

After changing your email password you have to update the new password on all devices that use your email. On your computer: open your email program (Outlook, Thunderbird or Apple Mail), go to account settings and update the password. On your smartphone: go to Settings, select your email account and enter the new password. On your tablet: follow the same steps as on your smartphone. Do not forget any devices: also check your work laptop, any second phone and webmail bookmarks. If you do not update the password on a device, the server may temporarily block access to your account after several failed attempts.

Changing your email password: when is it needed?

It is immediately necessary to change your email password in these situations: you suspect that someone has unauthorized access to your account, you have shared your password with someone who should no longer have access, your email address appears in a data breach on haveibeenpwned.com, you receive confirmation emails for actions you did not take, or you see unknown messages in your sent items. As a preventive measure we advise changing it every three to six months for optimal security of your email communication.