
Email is often linked to banking services, social networks, hosting, domains, and other accounts. This means unauthorised access to your mailbox may lead not only to someone reading your messages, but also to password resets, access to documents, or emails being sent in your name.
If you notice an unknown login, unusual messages, or lose access to your mailbox, do not spend time looking for the cause first. Regain control of the account and block every possible route of unauthorised access. You can investigate how the breach happened after completing the urgent steps.
What to do first:
- Recover access through the official website of your email provider.
- Set a new unique password.
- Sign out all unauthorised sessions.
- Enable two-factor authentication.
- Check forwarding, filters, and connected applications.
- Secure all accounts linked to the email address.
- Update and check your devices, and warn your contacts if necessary.
Changing the password alone may not be enough. If hidden forwarding, a third-party application, or an active session remains in the mailbox, the attacker may still be able to read your messages.
How to Tell If Your Email Has Been Hacked
The clearest sign is a password that suddenly stops working even though you did not change it. Check the login history as well. An unfamiliar device, another country, or activity at an unusual time may point to unauthorised access. IP-based location data is not always accurate, so one entry does not prove a breach, but several warning signs together require an immediate check.
Review the Sent, Drafts, Spam, Trash, and Archive folders. You may find messages with links, attachments, or requests for money that you did not create. Attackers sometimes delete them immediately, so an empty Sent folder does not guarantee that nothing was sent.
An unknown recovery email, a different phone number, disabled 2FA, a new sign-in method, automatic forwarding, or messages that disappear or become marked as read should also raise concern. Another clear signal is when contacts receive spam or financial requests from your address.
How to Recover Access to a Hacked Email Account
If You Still Have Access
Open the security settings from a trusted device. Change the password, check the recovery email and phone number, sign out unauthorised sessions, and revoke unknown sign-in methods, app passwords, and connected services.
Do not delay these steps even if the suspicious activity happened only once. The attacker may already have copied contacts, found recovery emails for other services, or created a forwarding rule.
If You Can No Longer Sign In
Use the official recovery form provided by the email service. Ownership is usually confirmed through a recovery address, phone number, trusted device, recovery code, or previous password. When possible, submit the request from a device and browser you have used before.
If the phone number or recovery email has been changed, look for a recovery option that does not require access to them. For corporate email or a mailbox on your own domain, contact the administrator or hosting provider immediately. Do not pay third parties who claim they can recover the mailbox. They have no legitimate way to restore access and may try to obtain even more of your data.
Change the Password, End Active Sessions, and Enable 2FA
The new password should be long, unique, and unrelated to the previous one. Changing a single digit will not help if the old password appeared in a data leak or was stolen through a phishing page. Do not reuse it for banking, social networks, hosting, or other services. The easiest option is to generate and store it in a password manager.
After changing the password, open Active Sessions, Your Devices, or Login History and remove unfamiliar connections. Check OAuth permissions, tokens, and app passwords separately, as they are not always revoked automatically.
Then enable two-factor authentication. It does not make the account impossible to compromise, but a stolen password alone will no longer be enough to sign in.
| Method | Protection | What to consider |
| Hardware key or passkey | High | A backup sign-in method is needed |
| Authenticator app | High | Recovery should be configured in advance |
| SMS codes | Medium | The number or code may be intercepted |
| Recovery codes | Backup method | Store them separately from the main device |
SMS is better than having no 2FA, but an authenticator app, passkey, or hardware key is safer. Do not store recovery codes in the same mailbox they are meant to protect.
Check Email Settings and Third-Party Access
Start with automatic forwarding and remove any address you do not recognise. Then review the filters. An attacker may have created a rule that archives, deletes, or marks as read messages from a bank, hosting provider, or security service.
Check delegated access, shared mailboxes, and permission to send messages in your name. Review all connected tools, including email clients, CRM systems, calendars, extensions, and services with OAuth access. Revoke unknown connections and remove those you no longer use.
Also check the signature, sender name, automatic reply, and contact details. They may contain unfamiliar links, payment details, or a phone number that will remain visible even after the password is changed.
Check the Consequences of the Breach
What to Check in Email and Cloud Services
Review sent, deleted, and archived messages, as well as spam and drafts. Look for notifications about password changes, a new device, a 2FA reset, a payment, or a connected application. Some deleted emails can be restored from Trash, although the retention period depends on the provider.
If contacts, documents, a calendar, or cloud storage are linked to the mailbox, check for new sharing links, unknown participants, and files in the trash. An email account is often a gateway to other data.
Which Linked Accounts Need Protection
Start with banking and payment services, domains, hosting, cloud storage, and website management systems. Then check social networks, messaging apps, and other online accounts. Change any reused passwords, end unfamiliar sessions, and verify the recovery details.
For domains and hosting, also review users, API keys, DNS records, transfer requests, and contact information. If spam or requests for money were sent in your name, warn contacts through another channel. Ask them not to open attachments, follow links, or respond to financial requests received from the compromised address.
Check Your Computer and Smartphone
The password may have been stolen through malware, a fake login form, or a dangerous browser extension. Update the operating system, browser, email client, and other applications, then run a full scan with a trusted security tool.
Review browser extensions, installed applications, VPNs, management profiles, and smartphone permissions separately. Remove anything unfamiliar or anything with unnecessarily broad access. If suspicious activity continues, change passwords from another trusted device.
What to Do If a Corporate Email Account Is Hacked
In a company, changing one employee’s password is not enough. Record the time of the incident, the warning signs, suspicious messages, and unknown devices, then report the breach to the system administrator or security team.
The account should be blocked, its password reset, active sessions ended, and tokens revoked. The administrator should review login logs, rules, delegated access, role changes, and connected applications. Logs should be saved before major changes are made so that useful data for the investigation is not lost.
It is also necessary to determine which messages, documents, customer data, and internal systems the user could access, then check other accounts in the organisation. Reused passwords or similar suspicious logins may mean the incident is not limited to one mailbox.
How to Protect Email on Your Own Domain
Corporate email first requires your own domain name. On the RX-NAME domain registration page, you can check whether a suitable name is available and register a domain for your company email addresses.
Use a separate password for every mailbox and enable 2FA for administrators and users who work with important data. Keep the mail server, control panel, webmail, and anti-spam software updated. Administrative access should be limited, and activity logs should be reviewed from time to time.
SPF, DKIM, and DMARC help prevent address spoofing. SPF lists authorised servers, DKIM adds a digital signature, and DMARC defines how failed checks should be handled. These records do not replace passwords and 2FA: if an attacker signs in to the real mailbox, their messages may still appear legitimate.
Important messages and settings should be backed up. Check occasionally that the data can actually be restored from the backup.
How to Prevent Your Email From Being Hacked Again
Do not reuse the email password in other services, and store it in a password manager. Open the login page from a bookmark or type the address manually. Before entering your credentials, check the domain rather than relying only on the appearance of the page.
Regularly review active devices, sessions, and connected applications. If a phone or laptop is lost, end its sessions remotely. Keep the recovery email and phone number up to date.
Revoke access for services you no longer use, save the recovery codes, and plan how you would regain access without your main phone. For corporate email and mailboxes on a custom domain, you should also know who can quickly block the account.
Frequently Asked Questions About Hacked Email Accounts
Is Changing the Password Enough After a Breach?
No. End unauthorised sessions and check 2FA, recovery contacts, forwarding, filters, and connected applications.
Can an Attacker Remain Signed In After the Password Is Changed?
Yes, if the service does not automatically revoke an active session, OAuth token, or app password. These must be ended or revoked separately.
How Can I Recover My Email If the Phone Number Was Changed?
Use a recovery address, recovery codes, a trusted device, or the provider’s official account recovery form. For corporate email, contact the administrator.
Should I Change Passwords in Other Services?
Yes, if the same or a similar password was used elsewhere. Also check services whose access can be restored through the compromised mailbox.
How Can I Check Whether Spam Was Sent From My Email?
Review sent and deleted messages, spam, drafts, and login history. Ask your contacts whether they received anything suspicious.
Can I Find Out Who Hacked the Mailbox?
Logs may show an IP address, approximate location, and device, but this information is usually not enough to identify a person reliably.
Who Should I Contact If I Cannot Recover Access?
Contact the official support team of the email provider or the account administrator. For email on your own domain, contact the server administrator or hosting provider.
Quick Checklist After an Email Breach
- Recover access through the official service.
- Set a long, unique password.
- End unknown sessions and revoke third-party tokens.
- Enable 2FA and save the recovery codes.
- Check forwarding, filters, and connected applications.
- Review deleted messages and login history.
- Secure banking, social networks, domains, hosting, and cloud services.
- Update and check your computer and smartphone.
- Warn your contacts about suspicious messages.
- For corporate email, document the incident and report it to the administrator.
If the mailbox works on your own domain and you cannot regain control yourself, contact the server administrator or hosting provider.
Leave a Reply