cybersecurity

Email Is the Only System on Earth That Holds Everything and Was Designed to Protect Nothing

By The Most Secure Man Alive | WISECLICK Ambassador


In 1971, a quiet engineer in Massachusetts sent the world's first email.

It travelled about one metre, between two computers in the same room. He later admitted he couldn't remember what it said. Probably something like QWERTYUIOP.

The most important business tool of your life began as a shrug.

The network it travelled on connected a few hundred people. Scientists, mostly. Researchers. They knew each other by name. Many of them had shaken hands.

So when they designed the system, they left something out.

Locks.

Not through carelessness. There was simply no one to lock out.


The system with no locks

Here is the part they don't print on the box. The rulebook that moves the world's email, standardised back in 1982, was never built to check that a sender is who they claim to be. It was written for a network of colleagues, and it assumed everyone on it could be trusted, because back then, everyone on it could.

That rulebook still runs the show today. The big providers have bolted on clever checks over the decades — background systems that help spot the obvious fakes — but they were never part of the original design, they're unevenly enforced, and they do nothing for the contents of a mailbox once someone is inside it.

Fifty-five years after that one-metre message, more than four billion of us pour our entire lives into the same system. Invoices. Contracts. Client records. Tax returns. The scan of your passport you sent the conveyancer in 2014. The reset link for your bank account. All of it, resting comfortably inside a design that was never asked to guard anything.

The criminals never broke email. They just read the manual.

Nearly every email scam you've ever read about is a footnote to that single design decision. There are no shadowy geniuses. There is a fifty-five-year-old trust system doing precisely what it was built to do, and people who noticed.


What happens when someone else reads your story

In October 2025, the Australian Federal Police described a case from Tasmania. A woman was renovating her home. She'd been emailing her builder for months, the way you do. Quotes, schedules, the usual back and forth.

Then an invoice arrived, from an address so close to her builder's that nobody would look twice. An exact replica of the real invoice, down to the last detail, except for the bank account it pointed to.

$120,000. Gone. Not recovered.

Here is the detail worth sitting with. In the same release, the AFP describes how these crews generally operate, and it isn't smash and grab. They settle quietly inside a compromised mailbox and read. They plant silent rules that catch any message mentioning invoice, purchase or payment. They study the relationship. The tone. The timing. Then, when the moment suits them, they simply continue the conversation as if they'd always been part of it.

They didn't forge her story. They read it. Then they wrote the next chapter.

And notice whose inbox did the damage. Not hers. The building company's. When a business's mailbox gets read, it's the clients who pay the bill, and the business that wears the reputation. According to the Australian Signals Directorate's latest Annual Cyber Threat Report (cyber.gov.au), email compromise sits at the top of self-reported cybercrime for Australian businesses. Across cybercrime of every kind, the average small business loss now runs to $56,600 per report, up 14 per cent in a year, and a cybercrime report lands somewhere in Australia every six minutes.

I don't share those numbers to raise your pulse. I share them the way a builder shares a soil report. It's simply the ground we're standing on.


Your inbox is your unofficial autobiography

Nobody sits down to write their life story. Most of us have written one anyway. It lives in our inbox, fifteen years deep. Tax returns, medical letters, payslips, contracts, flight bookings, the licence you photographed for a real estate agent, and several hundred conversations meant only for the people who had them.

And it's more than an archive. It's the master key. Every "forgot password" link you have ever clicked flowed through that one account. Your bank. Your super. myGov. Your accounting software. Someone who holds your email doesn't need most of your passwords. Plenty of accounts can be reset from the inbox alone — and the better-guarded ones, the banks that ask extra questions, still leak enough detail through the inbox to help someone try.

Your inbox knows more about you than your accountant. And it never forgets.

So we have an autobiography and a master key, stored together, in a system designed without locks. The question isn't whether that deserves ten minutes of your attention. The question is what those ten minutes look like.


The Ten-Minute Inbox Sweep

Put the kettle on. Open your email. One adjustment before anything else: set the search to cover everything, not just the inbox. In Outlook, that's the dropdown next to the search bar — change Current Folder to All Outlook Items. In Gmail, open the search options and set the folder to Mail & Spam & Trash, because Gmail's ordinary search politely ignores the bin. In Apple Mail, choose All Mailboxes, and check in Mail's settings that Bin and Junk are included in search results. The wording differs by app; the idea doesn't. We're searching the whole house, not just the hallway table.

Now, search one word:

passport

Have a look at what comes back. Take your time. I'll wait.

Now run four more searches, one at a time: licence, TFN, statement, password.

What you're looking at is the part of your autobiography a stranger would read first. Here's how I handle what turns up:

  1. Anything worth keeping moves to a proper vault. An encrypted cloud drive with its own login, or the document storage inside a reputable password manager. Somewhere built to guard things, because your inbox wasn't.
  2. Then the email copies go. Inbox, sent items, and the bin. And here I mean go. Delete them, then empty the bin. If your email offers a recover-deleted-items option — Outlook usually does — clear that too, because some services keep a quiet second copy of "deleted" mail for a while, waiting for you to change your mind. In my experience the bin is the biggest folder in most people's inboxes. They treat it as a sort of archive. Which means the room marked RUBBISH is where the autobiography keeps its best chapters.
  3. From today, sensitive documents don't travel by plain email. Secure portals and encrypted transfers exist for exactly this. The inbox is for conversation, not custody.

One caveat, said once: business and tax records have legal lives — generally five years in Australia — so those move to the vault, never to the bin. We're relocating the archive, not shredding it.

And check one more room on the way out: the Downloads folder. Every attachment you've ever opened from an email landed there first, and stayed. The statement you glanced at once in 2019. The scan you forwarded to the broker. Most people's Downloads folder is the inbox's shadow, quietly keeping copies of everything the sweep just cleaned out. Sort it by date, move the keepers to the vault, and empty the rest.

Mine is empty, by the way. It's a hallway too.

That's the sweep. Ten minutes, once, and the crown jewels are out of the hallway.

I treat my inbox like a hallway, not a safe. Things pass through it. They don't live there.


The lock the 1971 engineers never needed

The sweep thins out what a reader could find. This next move decides whether they get to read at all.

Multi-factor authentication on the email account itself. A code from an app on your phone, or better still a passkey, standing between your password and your front door. The engineers of 1971 never needed it. You and I are not on a network of a few hundred colleagues.

The Australian Cyber Security Centre rates multi-factor authentication among the most effective defences available, and it's one of the Essential 8 for good reason (cyber.gov.au). Here's how I handle it: the authenticator app rather than SMS codes where the choice exists, enabled on the email account before anything else I own, because the account that can reset every other account earns the strongest lock in the house.

Ten minutes. Once. Save the backup codes somewhere safe while you're at it — every good lock deserves a spare key. Then it simply works, quietly, in the background.

The best lock is the one you never think about again.


The two-minute check most people have never done

One more, and this one comes straight from the Tasmanian playbook.

Open your email settings and look at two pages: forwarding rules and connected apps.

A quiet rule, silently sending copies of your mail somewhere you've never heard of, is the oldest trick in the modern book, and it's exactly how a reader stays in the room after you've changed the locks. (In Outlook on the web, that page lives at Settings → Mail → Rules. In Gmail, it's the Filters and Forwarding tabs under Settings.)

Connected apps are the politer version of the same problem. Every time you've connected a service to your account — an app that helped once in 2019 and was never thought of again — you may have handed over a key. Not every connection can read your mail; the permissions list tells you which ones can. And those keys don't expire when you change your password. They sit on that settings page, still working, until you take them back. Scroll the list, paying particular attention to anything with permission to read or send mail. Anything you don't recognise or no longer use loses its access today.

Most people have never once opened either page. I visit mine quarterly, with a coffee. Two minutes. Nothing to see, most of the time. That's rather the point.


If you run a business, your inbox is the business

Everything above counts double at work, because a business inbox is also the company's informal filing cabinet, and, as Tasmania shows, the damage flows outward to the people who trust you.

Two things I'd do this week. First, run the sweep on the business mailboxes. Second, write one sentence into how you operate: bank details never change on the strength of an email alone. Any change gets confirmed by a phone call to a number you already had. That single sentence would have kept $120,000 in Tasmania.

Policy doesn't have to be a binder. Sometimes it's one sentence everyone can recite.

See where you stand. 30 minutes. Plain English. $149.

Take the Ransomware Readiness Check →

Your inbox is one door. The Check walks all eight.

I ran my own sweep the afternoon I learned how these crews operate. Found a passport scan from 2013, moved the keepers, deleted the rest, put the strong lock on the front door, and went back to my coffee. Ten quiet minutes, once. The forwarding-rules page has been empty every quarter since. That's how I like my security — uneventful.

The engineers of 1971 built a system for people who trusted each other. The rest of us just moved in. Lock the door behind you.

Stay protected, my friends.
— The Most Secure Man Alive


Frequently asked questions

Is email really not secure by design?

The transport has improved over the decades, with encryption between mail servers now common. But the underlying rulebook still doesn't verify that a sender is who they claim to be, which is why convincing fakes remain so easy to send and why the habits above matter more than any single setting.

What should I search for in my inbox sweep?

Start with passport, licence, TFN, statement and password. Then add anything specific to your life: Medicare, contract, payslip, visa. Set the search scope to everything first — All Outlook Items in Outlook, Mail & Spam & Trash in Gmail's search options, All Mailboxes in Apple Mail with Bin and Junk enabled in search settings. The sent folder usually holds more than the inbox. And when you're done, run the same five searches over your Downloads folder — attachments you've opened live there too.

Where do I keep documents once they leave my inbox?

An encrypted cloud drive with multi-factor authentication of its own, or the document vault inside a reputable password manager. A place designed for custody, rather than conversation.

What should I use instead of email attachments for sensitive documents?

It depends on how sensitive. For everyday transfers, SwissTransfer is free, needs no account, and lets you set a password, an expiry date and a download limit — though the company operating it could technically access the files, so treat it as a locked courier van rather than a sealed envelope. For genuinely sensitive documents, use a zero-knowledge tool: the free tier of Proton Drive encrypts files on your device before they leave it, so not even Proton can read them, and a shared link can be revoked entirely. Bitwarden Send works the same way for sending a password or account number as a self-destructing link. And if your accountant or lawyer offers a client portal, use it — that is precisely what it exists for. Whichever you choose, one habit: the password travels by a different road than the link. Link by email, password by text. Members will find this list, along with the rest of the tools I actually recommend, in the WISECLICK Cyber Toolkit.

Is an authenticator app really better than SMS codes?

Yes. Codes sent by text can be intercepted through SIM-swap tricks, where a criminal takes over your phone number. App-based codes and passkeys stay on your device. The ACSC recommends phishing-resistant options where available.

What's a forwarding rule and why would I check it?

A setting that automatically sends copies of your email elsewhere. Handy when you create it. A problem when someone else does. It's how a reader keeps reading after you've changed your password, and it takes two minutes to check.

How do criminals get into an email account in the first place?

Most commonly a password reused from another website that was breached, or a convincing sign-in page that harvested it. Unique passwords and multi-factor authentication close both doors.

Deleted emails are gone forever, right?

Not immediately. Deleting moves mail to the bin, and some services — Outlook in particular — keep a recover-deleted-items area for a while after the bin is emptied. Clear each stage your app offers and it's beyond a casual reader's reach, which is what the sweep is for. Copies of things you sent still exist in other people's mailboxes, which is why sensitive documents travel by secure portal from now on.

Does any of this help my business with the Essential 8?

Directly. Multi-factor authentication is one of the eight strategies, and the habits here support several others. The Ransomware Readiness Check shows where you stand across all eight, in plain English.


Get articles like this delivered to your inbox

Reading next

Leave a comment

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.