How to Check If Your Email Has Been Hacked - 7 Warning Signs
Most people do not realize their email has been hacked until the damage is already done — a contact asks why you sent them a suspicious link, a password reset email arrives for a service you did not request, or you get locked out of your own account.
The good news is that there are clear warning signs, and checking takes minutes. This guide walks you through how to detect a compromised email account, what to do immediately if you find evidence, and how to prevent it from happening again.
7 warning signs your email has been hacked
1. You cannot log in
The most obvious sign. If your password no longer works and you did not change it, someone else may have. Attackers often change the password immediately after gaining access to lock you out. If you can still use a recovery method (phone number, backup email), do it now — before reading the rest of this article.
2. Emails in your Sent folder you did not write
Check your Sent and Drafts folders. If you see messages you did not compose — especially messages with links, attachments, or requests for money — your account has been used to send spam or phishing. Attackers often delete these from Sent to cover their tracks, so also check your Trash.
3. Password reset emails you did not request
If you are receiving password reset confirmations from services you did not initiate, an attacker may be using your email access to take over your other accounts. This is one of the first things attackers do after compromising an email account — they use it as a gateway to reset passwords on banking, social media, and shopping accounts.
4. Contacts receive spam from your address
If people in your contact list report receiving strange emails from you, your account is either compromised or your address is being spoofed. The difference matters: if the emails actually appear in your Sent folder, the account is compromised. If they do not, the attacker may be spoofing your address without account access.
5. Unfamiliar login activity
Every major email provider lets you review recent sign-in activity:
- Gmail: Scroll to the bottom of your inbox and click “Details” under “Last account activity”
- Outlook: Go to account.microsoft.com → Security → Sign-in activity
- Yahoo: Go to Account Security → Recent activity
- iCloud: Go to appleid.apple.com → Devices (shows all signed-in devices)
Look for logins from unfamiliar locations, devices, or IP addresses. Pay special attention to logins at unusual times (3 AM in a timezone you were not in).
6. Email forwarding rules you did not create
This is a sophisticated attack that many people miss. Attackers add a forwarding rule that silently copies all your incoming email to their own address. Even after you change your password, they continue receiving your emails until you find and delete the rule.
Check forwarding settings in:
- Gmail: Settings → See all settings → Forwarding and POP/IMAP
- Outlook: Settings → Mail → Forwarding
- Yahoo: Settings → More Settings → Mailboxes → your mailbox → Forwarding
Also check for filter rules that automatically move, delete, or forward specific messages. Attackers sometimes create filters to intercept password reset emails so you do not notice their activity.
7. Your email appears in a data breach
Even if your account is not currently compromised, your credentials may have been exposed in a past breach. Check on Have I Been Pwned (haveibeenpwned.com) — enter your email address, and it tells you which breaches included it. If your email appears and you have not changed your password since the breach date, change it immediately.
For more on what happens when your email ends up in a breach database, see What Happens to Your Email Address After a Data Breach.
What to do immediately if your email is hacked
Speed matters. Attackers move fast — often within minutes of gaining access. Follow these steps in order:
Step 1: Regain access
If you can still log in, change your password immediately. Use a strong, unique password that you have never used elsewhere. If you are locked out, use your provider’s account recovery process (recovery phone number, backup email, security questions).
Step 2: Enable two-factor authentication
Before doing anything else, enable 2FA. Use an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) or a hardware security key — not SMS, which is vulnerable to SIM swapping. This prevents the attacker from getting back in even if they still have your password.
Step 3: Check and remove forwarding rules
Go to your forwarding settings and filter rules immediately. Delete any forwarding addresses or filters you did not create. This is critical — if a forwarding rule remains active, the attacker continues receiving your email even after you have secured the account.
Step 4: Revoke all active sessions
Sign out of all devices and sessions. In Gmail, click “Details” at the bottom of your inbox, then “Sign out all other web sessions.” In Outlook, go to account.microsoft.com → Security → Sign-in activity and sign out everywhere.
Step 5: Review connected apps
Check which third-party apps have access to your email account. Attackers sometimes authorize a malicious app that maintains access even after a password change. Revoke anything you do not recognize:
- Gmail: myaccount.google.com/permissions
- Outlook: account.microsoft.com → Privacy → Apps and services
- Yahoo: Account Info → Account Security → Manage app passwords
Step 6: Check for damage
Review your Sent folder, Trash, and Spam for messages the attacker sent. Check your other accounts (banking, social media, shopping) for unauthorized password changes or activity. If the attacker used your email to reset passwords elsewhere, secure those accounts too.
Step 7: Warn your contacts
If spam or phishing was sent from your account, let your contacts know. A simple message explaining that your account was compromised and that they should ignore any suspicious messages from you prevents further damage.
How to prevent email hacking
Use a unique password
The most common way email accounts get hacked is credential stuffing — attackers take passwords leaked from one service and try them on email accounts. If you use the same password for your email and a shopping site that gets breached, your email is compromised. Use a password manager to generate and store unique passwords for every account.
Enable two-factor authentication
2FA stops the vast majority of account takeover attempts. Even if an attacker has your password, they cannot log in without your second factor. For maximum security, use a hardware key or authenticator app rather than SMS. For a full guide, see What Is Two-Factor Authentication?
Be cautious with links and attachments
Phishing remains the most effective way to steal email credentials. Never enter your password on a page you reached through an email link. Always navigate to your email provider directly by typing the URL. For how to spot phishing, see How to Report Phishing in Gmail.
Use email aliases to limit exposure
Every service you sign up for with your real email address is another potential breach point. If a service gets hacked and your email/password combination is exposed, attackers will try that password on your email account. Using a unique email alias for each service means a breach exposes the alias, not your real email address — and the alias has no password to try on your actual email login.
Monitor breaches proactively
Set up breach notifications on Have I Been Pwned so you are alerted when your email appears in a new breach. For email aliases, set up notifications for each alias — if a specific alias appears in a breach, you know exactly which service leaked it and can disable the alias immediately.
Hacked vs. spoofed: know the difference
If contacts report spam from your address, your account may not actually be compromised. Email spoofing lets anyone send email that appears to come from your address without needing access to your account. The difference:
| Sign | Hacked | Spoofed |
|---|---|---|
| Messages in your Sent folder | Yes | No |
| Unfamiliar login activity | Yes | No |
| Password still works | Maybe not | Yes |
| Forwarding rules added | Possible | No |
| You can stop it by changing password | Yes | No |
If your account is being spoofed (not hacked), the solution is different: ensure your domain has proper SPF, DKIM, and DMARC records. For personal email on Gmail/Outlook/Yahoo, the provider handles this for you. For custom domains, see our SPF/DKIM/DMARC guide.
The bottom line
Checking if your email has been hacked takes five minutes: review login activity, check forwarding rules, scan your Sent folder, and run your address through Have I Been Pwned. If you find anything suspicious, act immediately — change your password, enable 2FA, revoke sessions, and remove unknown forwarding rules.
The best protection is prevention: unique passwords, two-factor authentication, and email aliases that keep your real address out of breach databases. For more on what happens when your address ends up in a breach, see Your Email Was in a Data Breach - Now What?
Ready to take control of your inbox?
Start protecting your email with Cleanbox — free plan available, no credit card required.
Get started free