A friend texts to ask why you sent them a link to a crypto site. You did not. Or you open your laptop to a Google alert about a sign-in from a city you have never visited, and a password-reset email for an account you never touched. Something is off, and the question in your head is simple: has someone gotten into my email?
Your email is likely hacked if you see sign-in alerts from unknown devices, sent mail you never wrote, contacts reporting spam from you, or password-reset emails you did not request. Act fast: change your password from a device you trust, turn on two-factor authentication, then hunt for forwarding rules and connected apps the attacker left behind.
How can I tell if my email account has been hacked?
The clearest signs are things happening that you did not do. Your account is the tool an attacker uses, so the evidence shows up as activity you cannot account for. Look for these:
- Sign-in alerts from unfamiliar devices or locations. Google and Microsoft email you when a new device logs in. An alert naming a browser, phone, or country you do not recognize is the loudest warning there is.
- Sent mail you never wrote. Check your Sent folder. Spam or phishing sitting there means someone used your account to mail other people.
- Contacts getting spam from you. Friends asking about a strange link or a plea for money often notice before you do, because the attacker may have deleted the copies from your side.
- Password-reset emails you did not request. A reset code for your bank or another account can mean someone is working through your logins, using your inbox as the master key.
- You cannot log in. A password that suddenly stops working, when you know it, often means the attacker already changed it to lock you out.
- Settings you did not change. A new recovery phone number, a signature with a link you never added, or an auto-reply you did not write are all footprints.
One of these can be a glitch. Two or three together is a compromised account, and the next step is to move quickly.
Why do I see emails in my Sent folder I didn’t send?
Because the attacker is using your account to mail other people, usually spam or phishing aimed at your contacts. Your address is trusted by the people who know you, which makes it a good launchpad. Their filters are more likely to let a message through when it comes from a real friend.
Watch for the reverse clue too. Some attackers delete the messages they send from your Sent folder to stay hidden, so an empty Sent folder is not proof you are safe. If contacts report mail from you that you cannot find, treat that report as the real signal. The FTC’s guidance on a hacked email account recommends telling your contacts directly: warn them not to click links in messages from you and to ignore any request for money.
What are the hidden signs, like forwarding rules and filters?
The dangerous signs are the quiet ones, because an attacker who plans to stay wants your inbox to look normal. Two settings do most of the hiding.
The first is an auto-forwarding rule. The attacker points a rule at their own address so every new message you receive is copied to them silently, while your inbox still shows the original. They can keep reading your mail for months after you change your password, since a forwarding rule does not care what your password is.
The second is a filter. A filter can automatically mark certain messages as read, move them to Trash, or archive them, which lets an attacker suppress the exact security alerts and reset emails that would otherwise tip you off. Barracuda reported in September 2023 that attackers create these inbox rules specifically to evade detection after they break in. Security teams have noted the odd names attackers give them, sometimes just a single period, a semicolon, or a couple of letters, so a strange rule you do not remember making is worth deleting.
What should I do first if my email is hacked?
Work through these steps in order. Each one closes a door, and the order matters, because a step done out of sequence can be undone by the attacker.
- Change your password from a device you trust. Do this from a computer or phone you have scanned for malware. Google, Microsoft, and the FTC all warn that if a keylogger is running on your device, your new password is stolen the instant you type it. Clean the device first, then set a long, unique password.
- Turn on two-factor authentication. With a second factor, your password alone stops being enough to log in. Google calls this 2-Step Verification; Microsoft calls it two-step verification. Use an authenticator app or a security key rather than SMS where you can.
- Sign out every other session. In your account’s security settings, review the list of signed-in devices and sign out everything you do not recognize. On Google this lives under Security and Your devices; on Microsoft, under your account’s sign-in activity. A password change signs out most sessions, but confirm it by hand.
- Hunt for forwarding rules and filters. Open your mail settings and remove any auto-forwarding address and any filter you did not create. This is the step people skip, and it is the one that lets an attacker keep reading your mail after everything else looks fixed.
- Review connected apps. Revoke any third-party app or service you do not recognize or no longer use. App access tokens survive a password change, so a connected app is a back door that a new password does not close.
- Check whether your address is in a breach. Run your address through Have I Been Pwned to see which breaches exposed it, then change the password anywhere you reused the old one.
Then warn your contacts, and check your recovery email and phone number to make sure the attacker did not swap them for their own.
How do I check for forwarding rules and filters an attacker added?
Go straight to the mail settings, not the account settings, because forwarding and filters live inside your inbox. This is the highest-value check on the list, so do it carefully.
In Gmail, open Settings, then See all settings. Under Forwarding and POP/IMAP, remove any forwarding address you did not add. Under Filters and Blocked Addresses, delete any filter that forwards, deletes, or marks messages as read that you do not remember creating. Google’s own guide to a compromised account also flags mail delegation, labels, and IMAP or POP access as places an attacker can hide.
In Outlook.com, open Settings, then Mail. Check Forwarding for an address you did not set, and Rules for anything suspicious. Microsoft’s recovery guide notes that it resets some settings automatically when it detects a hack, but you should still confirm forwarding, rules, and your automatic reply by hand. If a rule reappears after you delete it, the attacker still has access, so return to the sign-out and connected-apps steps.
How do I recover a Google or Microsoft account I’m locked out of?
Use the provider’s account recovery flow, from a device and location you have used before. When an attacker changes your password to lock you out, the recovery page is the way back in, and familiar signals help you pass the identity check.
For a Google Account, go to the account recovery page and answer the verification prompts. Google advises using a device, browser, and location you have signed in from before, since that history raises your odds of getting back in. For a Microsoft account, use the sign-in helper at account.microsoft.com and, if the automated checks fail, complete the recovery form with as much accurate detail as you can: old passwords, the account’s approximate creation date, and subject lines of recent messages. Microsoft account recovery is automated, so even its support agents point you to the same form.
How do I check if my email was in a data breach?
Enter your address at Have I Been Pwned. It is a free service, run by security researcher Troy Hunt since 2013, that indexes billions of accounts exposed in known data breaches and tells you which ones included your address. A breach is often how the attacker got your password in the first place, especially if you reused it.
If your address shows up, treat every password you reused across sites as compromised and change each one. Knowing every account tied to your address tells you where to start. This is the moment a password manager earns its keep: a unique password per site means a single breach cannot unlock the rest of your accounts. Reused passwords are the thread that turns one leaked login into ten hacked ones.
How do I keep my email from getting hacked again?
Close the door the attacker used, then make the account harder to open next time. Most email accounts fall to one of two things: a password exposed in a breach, or a phishing message that tricked you into typing your login on a fake page. Two-factor authentication defends against both, because a stolen password alone no longer gets anyone in.
Phishing is the harder problem, because a convincing fake is designed to bypass your judgment. Modern lures read clean, with correct spelling and your real name, so the old tells no longer help. Our guide to spotting AI phishing emails covers what to check instead, starting with the sender’s real address and where a link actually points. A visit to our security overview explains how read-only, in-browser design limits what any single tool can expose.
Shrinking your inbox lowers the risk too. Fewer senders means fewer footer links to misjudge and fewer messages to sort real from fake each morning. Email Unsubscriber scans your Gmail or Outlook inside your own browser, lists every subscription sender, and fires the real one-click unsubscribe where a sender supports it, which keeps you off sketchy landing pages. The scan runs on your device, and we never read, analyze, or monetize your email content. It is not a spam filter and it will not undo a hack, but a smaller inbox is a smaller target. Our full routine for stopping spam for good covers the rest.
The takeaway
A hacked email account announces itself through activity you did not create: strange sign-ins, sent mail you never wrote, contacts getting spam, resets you did not ask for. When you see it, move in order. Change your password from a clean device, turn on two-factor authentication, sign out every session, and then do the step most people miss: remove the forwarding rules, filters, and connected apps the attacker left behind, because those keep working long after the password is fixed. Check Have I Been Pwned to learn how they got in, warn your contacts, and lock the account down so the next attempt goes nowhere.
