How to Check If Your Email Has Been Hacked

How to Check If Your Email Has Been Hacked

Quick answer: Check recent sign-ins, sent messages, recovery settings, forwarding rules, and connected apps. If anything looks unfamiliar, change your password from a trusted device and enable two-factor authentication immediately.

Signs that your email may be compromised

Watch for:

  • Password-reset messages you did not request
  • Unfamiliar sign-ins or devices
  • Messages in your Sent folder that you did not write
  • Contacts receiving strange messages from you
  • New forwarding rules
  • Changed recovery email or phone number
  • Unfamiliar connected apps
  • Missing or deleted messages

One unusual email does not prove that your account was hacked. Check the account directly instead of clicking links in the message.

1. Sign in through the official website or app.

Open your email provider’s official app or type its address manually. Do not use a link from a suspicious message.

If you cannot sign in, use the provider’s official account-recovery process. Do not pay an unknown person who claims they can recover your account.

2. Review recent account activity.

Open the account’s security section and look for recent sign-ins, devices, locations, and apps.

For Google, use your Google Account security settings. For Microsoft, Apple, Yahoo, and other providers, search the account settings for SecurityRecent Activity, or Devices.

Sign out of devices you do not recognise. If the location looks unfamiliar but the device is yours, consider whether it could be a mobile-network or VPN location before assuming it is an attack.

3. Change your password

If you see suspicious activity, change your password immediately.

Use a long, unique password that you have not used on another website. Do not reuse the new password anywhere else. A password manager can generate and store a unique password for you.

4. Turn on two-factor authentication.

Two-factor authentication adds a second verification step after your password. An authenticator app or security key is generally stronger than text messages, but any available second factor is better than using only a password.

For more information, read Two-Factor Authentication Explained.

5. Check forwarding and filter rules.

Attackers may create a rule that quietly forwards incoming messages to them or hides security alerts.

Review:

  • Forwarding addresses
  • Automatic replies
  • Filters and rules
  • Deleted and archived messages
  • Blocked addresses

Remove anything you did not create.

6. Check sent messages and contacts.

Look through your Sent, Drafts, Trash, and Deleted folders. If messages were sent from your account, warn affected contacts not to open links or attachments.

Delete suspicious drafts and revoke access from unfamiliar apps.

7. Secure other accounts

Your email may be the recovery key for banking, shopping, social media, and cloud storage accounts. Change passwords on important services if they used the same password or if your email account was accessed.

Prioritise financial accounts, password managers, social profiles, and work accounts.

8. Watch for follow-up scams.

After an account compromise, criminals may send convincing messages pretending to be your bank, email provider, or a friend. Do not share passwords, verification codes, or recovery keys.

Read How to Spot a Phishing Scam for additional warning signs.

What if you cannot recover the account?

Use the provider’s official recovery process from a familiar device and location. Contact the provider through its official support page. If financial information was exposed, contact your bank or payment provider directly using a verified number.

Final verdict

Check the account directly, change the password, enable two-factor authentication, and review forwarding rules. Act quickly, but do not respond to “support” messages that ask for your password or verification code.

Similar Posts