1. Using just one email account.
2. Holding onto spammed-out accounts too long.
3. Not closing the browser after logging out.
4. Forgetting to delete browser cache, history and passwords.
5. Using unsecure email accounts to send and receive sensitive corporate information.
6. Forgetting the telephone option
7. Not using the Blind Carbon Copy (BCC) option.
8. Being trigger happy with the "Reply All" button.
9. Spamming as a result of forwarding email.
10. Failing to back up emails.
full list via itsecurity
#1: Never allow an e-mail client to fully render HTML or XHTML e-mails without careful thought.
#2: If the privacy of your data is important to you, use a local POP3 or IMAP client to retrieve e-mail.
#3: Ensure that your e-mail authentication process is encrypted, even if the e-mail itself is not.
#4: Digitally sign your e-mails.
#5: Avoid unsecured networks.
#6: Turn off automated addressing features.
#7: Use BCC when sending to multiple recipients.
#8: Save e-mails only in a safe place.
#9: Only use private accounts for private e-mails.
#10: Double-check the recipient, every time - especially on mailing lists.
via techrepublic