(1/2)
Tips for protected accounts on Mastodon:

1. at "Profile / Appearances":
(a) enable "Require follow requests"
(b) enable "Hide your social graph" to hide followings/followers
(c) disable "Suggest account to others"

2. at "Preferences / Other":
(a) set default "Posting privacy" to "Followers-only"
(b) enable "Opt-out of search engine indexing"

(2/2)
3. Many apps are still buggy when it comes to default post visibility. Always check for "followers only" before posting!
If in doubt, check your profile in a private tab to see whether anything has been posted publicly.
4. WARNING: Mentions (such as [at]username[at]instance) _always_ enable the post to be visible to the mentioned person. If you do not want that, use a link (such as https://instance/[at]username instead.
Addendum: boosts and favs are _always_ visible for the account who originally published the post.