Why this matters
Poor user management is a common cause for site security issues. If you’ve inherited a client site with a lot of user accounts do you really know who is correctly set up or not?
At first glance you might expect all admin capable users to belong to the built-in administrators role, but this isn’t always the case. Users belonging to custom roles with innocent sounding names could be hiding in plain sight. Without taking a detailed look at each role you’d never know if administrator level capabilities are lurking behind them.
Enough with the doom and gloom. Chances are your client site has the standard built-in roles and far too many administrator accounts than is required. Have they removed old staff members, or freelancers who left months ago? Probably not.
Do they all belong to the approved email domains? Let’s find out!
What it does
As an extra security precaution all accounts are checked once a day for administrator level capabilities, and an email address that is not in the allowed domains list. You will receive an email listing these accounts, and their role, if any are found.
In the example below there is one account from evil.com using the built in administrator role. Should any accounts be using custom roles their role name would be included for you to investigate.

How to set it up
Go to ToggleWP > Manage, enable the “Security & Authentication” option. Add at least one email domain and save the settings. Users will be checked once a day and an alert email will be sent if any user triggers it.
