The starter journey · Citizen tier · Draft v0.4

Protect your email —
the DEFEND way

Learn all six DEFEND ideas on the account that matters most. Every control below is Citizen-tier — doable without technical skill.

Get notified when we launch

Join our mailing list to be the first to know when DEFEND Digital Life is officially released.

Why email

Email is the master key

When you forget a password — for your bank, your shopping, your social media — the reset link goes to your email. That makes your email the master key to your whole digital life. Protect it well, and you protect everything that depends on it.

It's also the perfect place to learn the framework. DEFEND is six ways of thinking — Decouple, Encrypt, Filter, Evaluate, Neutralize, Deny. Work through them here and you'll be able to point the same six at anything else you own.

About tiers. DEFEND grows with you across three levels: Citizen (everyday protection — this journey), Pro (for when you want to go further), and Ghost (for high-risk people like journalists and activists). Start as a Citizen. The Pro and Ghost ladders are at the end for when you're ready.

The six aren't a strict order — they're six lenses. But if you want the single biggest win first, jump to Deny.
D

Decouple

Separate your identities, so one problem can’t unlock everything

The idea. The most dangerous setup is having your whole life run through one email. That’s a single point of failure — if it falls, it all falls. Decouple means splitting your life into separate mailboxes, each with a job, so a problem in one stays trapped in one.

Email Compartmentalization

DEF-EM-DC-1.1 High
Why
To shrink the blast radius of a compromise by keeping high-risk and low-risk activity on separate email identities.
Do this
  • Run at least three separate mailboxes:
  • A Primary email for your real, everyday correspondence.
  • A Banking / high-value email used only for finance and critical logins, given to almost no one.
  • A Burner email for throwaway sign-ups.
Tools
Your main provider (e.g. Gmail, Proton) for Primary and Banking; a temp/burner service for the throwaway one.

Decouple is about a few separate real mailboxes. The next lens — Filter — is how you get unlimited separation without opening dozens of accounts.

E

Encrypt

Lock your information, so only you can read it

The idea. Encryption turns your mail into something unreadable to anyone without the key — protecting it on your devices, across the network, and on your provider’s servers.

Privacy-Focused Email Provider

DEF-EM-EN-1.1 High
Why
To protect both your email content and its metadata using strong, privacy-preserving encryption.
Do this
  • Use an encrypted, privacy-respecting provider for sensitive mail, rather than a traditional one that scans your messages.
Tools
Proton Mail or Tutanota (both end-to-end encrypted).
F

Filter

Hand out only what’s necessary — stand-in addresses, not your real one

The idea. You rarely need to give anyone your real email. Filter is the habit of limiting what you disclose: hand over aliases — stand-in addresses that forward to your real inbox — so your true address stays private and services can’t link your activity across the web. It’s how you separate your life infinitely without managing dozens of real accounts.

Use Email Aliases

DEF-EM-FA-1.1 Medium
Why
To keep your primary address private and stop different services from correlating you into one profile.
Do this
  • Use a unique alias for every non-essential sign-up — social media, newsletters, one-time downloads.
  • If an alias starts getting spam, you know who leaked it, and you can switch it off.
Tools
SimpleLogin (aliases); temp-mail services for one-time use.
E

Evaluate

Keep watch, so you spot trouble early

The idea. Evaluate is vigilance — actively checking your exposure and access so you catch a problem before it becomes a crisis, rather than finding out months later.

Monitor Email Breaches

DEF-EM-EV-1.1 Medium
Why
To find out early when your address or an account has been caught in a data breach.
Do this
  • Check monthly whether your address appears in a known breach.
  • Better still, let your password manager watch for you automatically.
Tools
Have I Been Pwned.

Review Active Sessions

DEF-EM-EV-1.2 Medium
Why
To catch anyone signed into your email who shouldn’t be.
Do this
  • Once a month, open your account’s active-sessions list and sign out any device you don’t recognize.
Tools
Gmail Security Center, Proton security logs.
N

Neutralize

Blunt the attack, so the common tricks don’t work on you

The idea. Neutralize takes the attacker’s favourite tools — phishing links, tracking pixels, "confirm you’re a real address" bait — and defangs them, so the everyday attacks simply fail against you.

Phishing Link Verification

DEF-EM-NU-1.2 Medium
Why
Most email harm comes from clicking a malicious link, and a simple check habit stops the vast majority of it.
Do this
  • Hover over any link to preview where it really goes before clicking.
  • For anything asking you to log in, reset a password, or pay, check the link with a scanner first.
  • For banking, never click the link at all — open your browser and type the address yourself.
  • Treat urgency ("account suspended in 24 hours") as an automatic red flag.
Tools
URLScan.io, VirusTotal.

Unsubscribe vs. Delete Discipline

DEF-EM-NU-1.3 High
Why
Clicking "unsubscribe" on the wrong email simply confirms your address is live and monitored — inviting more.
Do this
  • Only use unsubscribe links on services you knowingly signed up for.
  • Anything unfamiliar, unknown, or in spam — delete it without clicking, and report it as spam to train your filter.
Tools
Your provider’s filters and block-sender function.

Disable Remote Image Loading

DEF-EM-NU-1.1 Medium
Why
Images in emails can quietly tell a sender you opened their message and track you.
Do this
  • Turn off automatic image loading, at least on your primary and banking mail.
Tools
Your email provider’s settings.
D

Deny

Lock down access — the highest-impact protection there is

The idea. Deny is about the front door itself: making sure only you can get in. The safest access is the access no attacker can gain.

Enable MFA (App-Based)

DEF-EM-DN-1.1 Critical
Why
To require a second, independent factor beyond your password — so a stolen password alone is useless.
Do this
  • Turn on app-based two-factor authentication on your banking and primary email.
  • Prefer an authenticator app over text-message codes.
Tools
Google Authenticator, Microsoft Authenticator.

Strong Unique Password

DEF-EM-DN-1.2 High
Why
To make sure a leak on any other website can never open your email — no password is ever reused.
Do this
  • Use a password manager to generate a unique 16+ character password for each email account.
  • Never reuse one, and don’t store email passwords in your browser’s built-in saver.
Tools
Bitwarden, KeePassXC, Proton Pass, 1Password.

If you only do one thing today

Turn on MFA (DEF-EM-DN-1.1, your only Critical email control). On its own it blocks the large majority of account takeovers. Then come back for the rest.

Keep it up

Once a month: check for breaches and review active sessions. Otherwise, confirm MFA is on and your separate mailboxes are healthy. A few minutes is the whole job.

What you just learned

You ran your email through all six DEFEND lenses — you decoupled your identities, encrypted your mail, filtered what you hand out to stay unlinkable, learned to evaluate your exposure, neutralized the everyday attacks, and denied access to anyone but you. That's the whole framework, on one account.

And these same six lenses work on everything else you own. Email was the lesson. DEFEND is what you keep.

Ready for more?

Your next levels

Pro tier

For when you want to go further

  • Advanced compartmentalization
  • Dedicated recovery email
  • Encrypted attachments
  • Categorized aliases
  • Pseudonymous registration data
  • Audit forwarding rules
  • Review connected apps
  • Recovery-path validation
  • AI-driven attack defense
  • Plain-text email mode
  • Encrypted backup & recovery
  • Secure recovery codes
  • An anti-phishing habit
  • An email-compromise "burn" protocol

Ghost tier

For high-risk individuals — journalists, activists, targeted people

  • Service-level isolation
  • Custom-domain identity
  • Contact & calendar siloing
  • Air-gapped access
  • End-to-end encrypted comms
  • PGP key hygiene
  • Encrypted draft channel
  • Disposable identities
  • Identity rotation
  • Exposure analytics
  • Provider-jurisdiction & warrant-canary monitoring
  • Metadata & header obfuscation
  • Link-tracker stripping
  • Secure retention & deletion
  • Hardware-based authentication
  • Disabling SMS recovery
  • Anti-spoofing (SPF/DKIM/DMARC)
  • A digital succession plan

This is the Citizen-tier starter journey of the DEFEND Digital Life Framework, drawn from the DEFEND Controls catalog. The six Pillars are ways of thinking, not a fixed sequence, and not every Pillar applies to every situation. This journey lowers your risk and helps you stay in control; like any protection, it cannot promise you'll never face a problem. Draft for review — controls, wording, and tier placement are all open to change.