A friend messages you: "Did you send me this? It looks weird." Then another. Then your aunt replies to a link you never sent.
Before you change your password — and almost everyone changes the password first — stop and answer one question, because the answer determines everything else you do.
Is your account actually compromised, or is someone forging your address?
These look identical to the people receiving the messages. They require completely different responses. And doing the wrong one wastes time while an attacker keeps working.
Step 1: Spoofing or Compromise? How to Tell in Five Minutes
Spoofing means a spammer wrote your name and address into the "From" field of a message sent from their own server. They never touched your account. Email was designed in an era of implicit trust, and the sender field is about as verified as the return address you scribble on an envelope.
Compromise means someone has your credentials and is sending from inside your account.
Check these three things:
1. Look in your Sent folder. If the spam appears there, your account is sending it — that is compromise. If your Sent folder is clean, spoofing is far more likely. Be aware that a careful attacker may delete from Sent, so a clean folder is suggestive rather than conclusive.
2. Check your login and security activity. Every major email provider has a recent activity or security page listing sign-ins with dates, approximate locations, device types, and IP addresses. Unfamiliar sign-ins are the clearest evidence of compromise. A clean log with no strange entries points to spoofing.
3. Ask one contact to send you the message headers. Have them forward the spam as an attachment, or use their client's "show original" or "view source" option. In the headers, look at the Return-Path, Received: chain, and the SPF, DKIM, and DMARC results. If authentication shows fail and the originating server has nothing to do with your provider, it was forged elsewhere.
If it is spoofing: there is no account to clean. Tell your contacts your address was forged, that you did not send it, and to delete without clicking. Spoofing campaigns usually burn out within days. It is worth confirming your domain has DMARC configured if you own the domain — for a free consumer address, the provider handles this and there is nothing for you to change.
If it is compromise, or you cannot rule it out: work through the rest of this checklist in order. The order matters.
Step 2: Clean the Device Before You Touch the Password
This is the step that gets skipped, and skipping it undoes everything that follows.
A large share of account takeovers in 2026 begin with information-stealing malware on a computer — software that quietly harvests passwords saved in the browser, session cookies, and authentication tokens. If that malware is still running, the strong new password you set will be captured within minutes of you typing it.
Before changing anything:
- Run a full scan with reputable, up-to-date security software on every device where you check that email.
- Check your browser extensions and remove anything you do not recognize or did not deliberately install.
- Review installed applications for anything unfamiliar that appeared recently.
- If your work computer is involved, tell your IT team now rather than after.
If your device shows signs of infection and you are not confident cleaning it, do the remaining steps from a different, known-clean device — a phone that has not been used for sketchy downloads, or a family member's computer.
Step 3: Regain Control of the Account
Change the password from a clean device. Current NIST guidance favors length over complexity: a long passphrase of several unrelated words beats a short string of symbols and substitutions. Make it unique to this account — email is the master key that resets everything else, so it must never share a password with anything.
If you cannot get in at all, the attacker has likely already changed the password or recovery details. Do not delay; recovery gets harder as the account ages under their control. Our guide on account recovery for every platform type covers how the recovery forms work and what information gets them approved. If the provider has locked the account outright for suspicious activity, see what to do when your account is locked.
Sign out of all sessions everywhere. Changing the password does not automatically end active sessions on every provider. Look for "sign out of all devices," "revoke all sessions," or similar. An attacker holding a valid session cookie stays logged in until you force this. Do this after the password change.
Turn on two-factor authentication, and pick the right kind. An authenticator app or a hardware key beats SMS, which is vulnerable to SIM-swap attacks. Where your provider offers passkeys, they are the strongest option available to consumers — the credential lives on your device, is unique per site by design, and cannot be phished or reused. Save your backup codes somewhere offline.
Step 4: Hunt for What the Attacker Left Behind
This is where most people declare victory too early. A password change locks the front door while the attacker walks through the side entrance they installed. Check every one of these:
Forwarding rules. The single most common persistence mechanism. A rule quietly copying all incoming mail to an external address lets an attacker keep reading your password resets forever, even after you change the password. Check both the account-level forwarding setting and the individual filter rules — they are usually in different places in the settings menu.
Filters and rules that delete or archive. Attackers frequently create rules that auto-delete messages containing words like "security," "password," "verification," or the name of your bank, so you never see the alerts. If your provider's security emails "never arrived," this is usually why.
Auto-reply and signature. Check for a vacation responder pushing spam links or a signature edited to include a malicious URL.
Recovery email and phone number. Look for an added or altered recovery address or number. Some attackers add a second recovery method rather than replacing yours, because that is less likely to be noticed.
Connected apps and third-party access. Review the list of applications with permission to access your account and revoke anything unfamiliar. An OAuth grant survives a password change entirely — this is a common blind spot.
App-specific passwords. If your provider supports these for older mail clients, an attacker may have generated one. Revoke every app password you do not recognize, and regenerate the ones you need.
Aliases and send-as addresses. Check that no extra sending identity has been added.
Mail delegation. Some providers allow granting another account access to yours. Confirm nobody has been added.
Security question answers. If your provider still uses them, review and update.
Step 5: Contain the Damage Outward
Tell your contacts, from a clean account. Keep it short: your address was compromised, you did not send the message, delete it without clicking, and if they clicked, they should change their own password. If your address book is large, a brief note is far better than silence — people who clicked need to know.
Assume every account that resets through that email is exposed. Work through them in priority order: banking and financial, payment and shopping accounts with stored cards, cloud storage, social media, then everything else. Change passwords and enable two-factor as you go.
Check for financial damage. Attackers with mailbox access often place orders, redeem loyalty points, or open accounts using your identity. Review recent statements carefully. If you find charges you did not make, our complete fraud and dispute guide explains how to report them, and how to dispute an incorrect charge covers the evidence to submit. Duplicate or unfamiliar debits are covered in what to do when your bank account is charged twice.
Check whether your credentials were in a known breach. Free breach-notification services let you enter your address and see which incidents included it. If your password appeared in a breach and you reused it elsewhere, change it everywhere it was used. Never enter your actual password into a site that asks for it in full.
Consider a fraud alert or credit freeze if identity documents or financial details were in the mailbox. In the US, IdentityTheft.gov provides a guided recovery plan.
Step 6: Make It Not Happen Again
- Use a password manager. Unique credentials for every account mean one breach stays contained to one account.
- Adopt passkeys wherever offered, starting with your email.
- Stop using SMS as your only second factor where an app or hardware key is available.
- Keep a second, separate recovery email that you do not use for anything else and that is not linked back to the first.
- Treat unexpected security alerts as real — and verify them by going to the site directly, never through a link in the message.
- Never call a support number you found through a search engine. Compromised-email queries are aggressively targeted by fake support operations that will charge you for "fixing" the problem and gain remote access to your device in the process. Read how to spot and avoid fake customer service numbers before you dial anything.
Frequently Asked Questions
My contacts got spam but my Sent folder is empty. Was I hacked?
Probably not. An empty Sent folder combined with no unfamiliar sign-ins in your security log usually indicates spoofing, where a spammer forged your address without ever accessing your account. Confirm by checking the message headers for SPF and DKIM failures.
Why do I keep getting spam even after changing my password?
Almost always a leftover forwarding rule, filter, connected app, or app-specific password. A password change does not revoke OAuth grants or delete rules. Work through Step 4 above in full.
Do I need to delete the account and start over?
Rarely. A thorough cleanup plus two-factor authentication is sufficient in the large majority of cases. Deleting a long-standing address creates its own problems, since dozens of other accounts still route recovery through it.
How did they get in if I have a strong password?
The three most common routes are credential reuse after an unrelated breach, an information-stealing malware infection that harvested saved browser passwords, and a phishing page that captured both the password and the second factor in real time. None of these require your password to be weak.
Should I pay a service to fix this?
No. Every step in this checklist is something you can do yourself for free, and companies advertising emergency email recovery for a fee are frequently the same operations running fake support numbers.
My provider is unresponsive and I still cannot get back in.
Free email accounts often have no human support channel at all, which is why the automated recovery form is worth completing carefully. If a paid provider is ignoring you, see what to do when a company ignores your complaint, and for issues involving financial harm, how to file a CFPB complaint that gets real results.
The Short Version
Diagnose first — check your Sent folder, sign-in log, and the message headers, because spoofing needs no cleanup at all. If it is a real compromise, clean the device before changing the password, then revoke all sessions, then enable strong two-factor. Then hunt down forwarding rules, filters, connected apps, and app passwords, because that is where attackers hide. Warn your contacts, secure everything that resets through that mailbox, and check your statements.
Your email account is the master key to your entire digital life. It deserves your strongest available protection.
Disclaimer: IT Fixed Services is an independent informational platform. We are not affiliated with, endorsed by, sponsored by, or authorized by any company, brand, or service provider mentioned. All trademarks belong to their respective owners. Content is for general guidance only and is not legal or professional security advice.
Article References & Sources
- NIST Special Publication 800-63B, Digital Identity Guidelines — https://pages.nist.gov/800-63-3/sp800-63b.html
- FTC Consumer Advice, Hacked email — https://consumer.ftc.gov/articles/hacked-email
- FTC, IdentityTheft.gov recovery plan — https://www.identitytheft.gov/
- CISA, Secure our World: multi-factor authentication guidance — https://www.cisa.gov/secure-our-world
- Have I Been Pwned, breach notification service — https://haveibeenpwned.com/
- FIDO Alliance, passkeys overview — https://fidoalliance.org/passkeys/
This article was reviewed by the IT Fixed Services editorial team — a group of consumer research writers who track FTC, CFPB, and DOT policy updates.
This article follows our editorial policy.
Comments
0 comments
Leave a Comment
Your email address will not be published. Required fields are marked *