---
title: "Insecure email password"
canonical_url: "https://www.zone.lv/help/kb/insecure-email-password/"
post_type: "ht_kb"
published: "2026-01-06T10:32:19+00:00"
modified: "2026-01-06T10:32:19+00:00"
language: "en"
author: "Tanel"
taxonomies:
  ht_kb_category:
    - name: "Security"
      url: "https://www.zone.lv/help/kb-categories/security/"
    - name: "E-mail"
      url: "https://www.zone.lv/help/kb-categories/e-mail-en/"
---

# Insecure email password

If Zone detects that your email account password has been leaked or is not sufficiently secure, we will notify you by email. The notification is sent to the **contact email address associated with your ZoneID account**.

 Information To ensure that notifications always reach you, please make sure that the contact details of your ZoneID account are correct and up to date. You can view and update your contact details in the **[My Zone](https://my.zone.lv/dashboard/en/zoneid-profile)** environment.

 Good to know! To check the security of email account passwords, we use several sources, including the public breach database [**Have I Been Pwned**](https://haveibeenpwned.com/). The check is performed using a secure hashing method, which means that the **actual password is never transmitted or disclosed**. You can find more details on this process [in our blog](https://www.zone.lv/blogi/nuud-turvame-su-kirjavahetust-ka-lekkinud-salasona-eest/).

### What does “insecure password” mean?

An insecure password is usually either **weak** or **reused**:

1. **A weak password** is easy to guess (for example, short, simple, or a commonly used word).
2. **A reused password** is one that has previously been used for another service where user data has been exposed in a data breach.

### What should you do next?

1. Change your email account password to a more secure one **as soon as possible**. You can find instructions [here](https://www.zone.lv/help/en/kb/changing-email-password/).
2. A secure password should be **at least 10 characters long**. We recommend using a password manager (such as 1Password, Bitwarden, etc.) to generate and store strong passwords.
3. Avoid using the following in your password:

    - your name or company name
    - common passwords (e.g. Passw0rd!)
    - simple sequences (e.g. q1w2e3r4)
4. We also strongly recommend enabling **[two-factor authentication (2FA)](https://www.zone.lv/help/en/kb/e-mail-2fa/)** for your email account.
5. 2FA adds an additional layer of protection — even if someone learns your password, they will not be able to access the account without the second verification factor.

### Has the password already been misused?

1. [**In webmail**](https://webmail.ee/), you can review the mailbox **security events** to see whether there have been logins from suspicious locations. Instructions can be found [here](https://www.zone.lv/help/en/kb/webmailee-faq/#h3security-eventsh3).
2. In **[My Zone](https://my.zone.lv/dashboard/en/webhosting/webhost/email/mailboxes)** mailbox management, check whether anyone has configured automatic email forwarding or copying messages to an external email address.

 Attention! If the password has been maliciously misused, the confidentiality of the email account has been compromised. You can find more detailed information about this [here](https://www.zone.lv/help/en/kb/what-to-do-if-the-confidentiality-of-your-email-account-has-been-compromised/).
