How to Check If Your Email Was Hacked: Proven Signs & Fixes

How to check if your email was hacked and how to fix it

To check if your email was hacked, run your address through Have I Been Pwned, review your recent sign-in activity in Gmail or Outlook, and look for unfamiliar sent messages, new forwarding rules, or password-reset emails you didn’t request. If any of those show up, change your password now, sign out of every device, and turn on two-factor authentication before doing anything else.

Email is the master key to almost every account you own. Lose it and you expose banking, work, and identity records too. The FBI’s 2025 Internet Crime Report tallied roughly $20.9 billion in cybercrime losses, with email-linked fraud driving a large share of the total.

This guide covers the fastest checks, the signs that catch people out most, the recovery steps in order, and the myths that make things worse.

What Does It Mean When Your Email Has Been Hacked?

A hacked email means someone else has enough access to sign in, read your mail, send from your address, or reset your other accounts. That can happen through a leaked password from a breach, a phishing link that captured your login, malware on your device, or a weak recovery method. Full account takeover and password exposure in a data leak are different, and each calls for a different response.

The distinction matters. A password that appears in a public breach is a warning signal — your credentials are known to attackers, but they haven’t necessarily used them yet. A confirmed takeover means someone is inside the account and acting on it. You handle the first with a password change; you handle the second like an emergency.

How Do Hackers Actually Get In?

Most compromises come from four routes. Reused passwords exposed in a breach elsewhere. Phishing pages that copy Google or Microsoft sign-in screens. Malware or a shady browser extension that captures keystrokes. And, less often, a SIM-swap attack that hijacks SMS-based two-factor codes.

The common thread is that attackers rarely “hack” the email provider itself. They walk in with your credentials.

How Do You Check If Your Email Was Hacked in Under 5 Minutes?

The fastest check is a five-step sequence: search your address on Have I Been Pwned, open your account’s recent security activity page, scan Sent and Trash for messages you didn’t write, look for new forwarding rules or filters, and audit third-party apps with access. Any red flag on any step means treat the account as compromised.

Here is the exact five-step check I run whenever a client says something feels off:

  1. Search Have I Been Pwned. Go to haveibeenpwned.com and enter your email. It’s a free service, run by security researcher Troy Hunt, that tells you which known breaches include your address. If it lists a recent breach, that password is likely public.
  2. Open your provider’s security dashboard. In Gmail, go to your Google Account, then Security, then “Your devices” and “Recent security activity.” In Outlook, open account.microsoft.com and check “Sign-in activity.” Look for logins from cities, browsers, or devices you don’t recognize.
  3. Scan Sent, Trash, and Drafts. Attackers often send phishing from your address and then move the evidence to Trash so you don’t notice. Sort by date and look for anything you didn’t write.
  4. Check forwarding rules and filters. In Gmail, open Settings, then “Forwarding and POP/IMAP” and “Filters and Blocked Addresses.” In Outlook, open Settings, then Mail, then Rules. A hidden rule that auto-forwards mail to an unknown address is a classic sign of account takeover.
  5. Audit third-party app access. In Google, go to Security, then “Your connections to third-party apps and services.” In Outlook, review app permissions under Privacy. Revoke anything you don’t recognize or don’t use anymore.

Do these in order, and do them from a trusted device. If you suspect malware, run the checks from a different device or after a full antivirus scan.

What About Free Breach-Check Tools From Antivirus Companies?

Avast Hack Check, Norton’s breach detection, and F-Secure Identity Theft Checker all pull from the same public breach data. They’re fine as a second opinion. I still recommend Have I Been Pwned first because it’s the most complete public dataset and adds no upsell layer.

What Are the Warning Signs Your Email Is Compromised?

The clearest warning signs are unfamiliar sent messages, unexpected password-reset emails for other accounts, new forwarding rules or filters, sign-ins from unknown locations, and contacts asking why you sent them a strange link. Any one of these deserves action. Two or more, treat as a live incident.

Sign 1: You can’t log in with your usual password. The most obvious sign. If the password reset also fails, the attacker may have changed your recovery email or phone number.

Sign 2: Password-reset emails you didn’t request. Attackers who have your email try to reset banks, PayPal, or shopping accounts next. A cluster of reset emails within a few minutes is a red flag.

Sign 3: Messages in Sent or Trash you didn’t write. These often go to your contacts and push a fake invoice, gift card, or crypto scheme.

Sign 4: Forwarding rules pointing to an unknown address. This is how attackers stay inside quietly. They forward everything to their own inbox and delete the trace from yours.

Sign 5: A provider security alert. Gmail sends “New sign-in from…” emails, Outlook sends “Unusual sign-in activity.” Don’t dismiss these. Verify the device from your account, not from the alert email (which itself could be phishing).

Sign 6: MFA prompts you didn’t trigger. If your phone shows an “Approve sign-in?” push you didn’t request, someone has your password and is trying to bypass MFA. Decline it and change your password immediately.

Sign 7: Contacts flagging strange messages. If two or more people say they got an odd link from you, take it seriously. Warn everyone else, then follow the recovery steps below.

Sign 8: New devices or sessions you don’t recognize. Both Gmail and Outlook list active sessions. An unknown iPhone, an unfamiliar Windows PC, or a session in a country you’ve never visited is enough reason to force sign-out.

A Real Example

A freelance designer I know got a “Password reset” email from a shopping site at 2 a.m. She almost deleted it. When she checked Gmail’s security page, there was a Chrome session in a country she’d never visited. Someone had her old password from a breach three years earlier, and was trying to walk into her bank next. She rotated passwords on her top ten accounts before any damage was done. The whole rescue took about 45 minutes.

What Should You Do If Your Email Was Hacked? (Recovery Checklist)

If your email was hacked, act in this order: change the password, sign out everywhere, turn on app-based two-factor authentication, remove suspicious forwarding rules and app permissions, then rotate the passwords of any accounts that use email for recovery. Finish by scanning your device for malware and warning your contacts.

Follow this order, not a random one:

  1. Change your password. Make it long, unique, and unrelated to anything you’ve used before. A passphrase like “quiet-oak-lantern-42-north” is easier to remember and harder to crack than “P@ssw0rd!”. Save it in a password manager.
  2. Sign out of all sessions. Both Gmail and Outlook have a one-click “Sign out of all other sessions” option. Do it. That instantly kicks the attacker off.
  3. Turn on two-factor authentication with an app, not SMS. Use Google Authenticator, Microsoft Authenticator, Authy, or 1Password. Avoid SMS codes, which are vulnerable to SIM-swap attacks.
  4. Remove forwarding rules, filters, and app permissions. Delete anything you didn’t set up. Revoke every third-party app connection that isn’t essential.
  5. Update your recovery email and phone. Confirm they still belong to you, not to a number an attacker added.
  6. Rotate passwords on high-value accounts. Bank, PayPal, Apple ID, Google, Microsoft, Amazon, and any account that uses this email for recovery. Prioritize accounts holding money or identity.
  7. Run a full antivirus scan. Windows Defender on Windows, or a reputable free tool like Malwarebytes. On macOS, run the built-in XProtect and consider a dedicated scanner if you clicked something recent.
  8. Warn your contacts. A short message telling them to ignore anything odd sent from you in the last 24 to 48 hours.
  9. Check your bank and credit-card statements. Look for anything you don’t recognize, even small charges. Attackers sometimes test with $1 before larger fraud.
  10. File a report if there’s financial loss. In the US, that means the FTC at ReportFraud.ftc.gov and the FBI’s IC3 at ic3.gov.

If you can’t log in at all, use your provider’s account recovery flow: Google Account Recovery for Gmail, or account.live.com/acsr for Outlook. Expect ID checks and 24 to 72 hours for review.

While you wait for provider recovery, work from a second device you trust, and keep a written log of the times, alerts, and steps you take. That timeline helps if you later need to prove to a bank or an insurer that you acted quickly. It also stops you from repeating steps in a panic.

What Mistakes and Myths Should You Avoid?

The biggest mistakes are ignoring the first warning email, reusing the same password on other accounts, using SMS codes as your only second factor, and stopping after one password change without cleaning forwarding rules or app permissions. Attackers rely on people doing three-quarters of the recovery and skipping the rest.

Mistake 1: Ignoring the “unusual sign-in” alert. These often arrive an hour before an attacker starts moving. If you dismiss it, you lose your best warning.

Mistake 2: Changing only your email password. If any other account uses that same password, or uses your email for reset, the attacker still has a way in.

Mistake 3: Trusting SMS-based 2FA. SIM-swap attacks are common enough that federal agencies now recommend app-based codes. Move away from SMS as soon as you can.

Mistake 4: Leaving old third-party app permissions. A retired app you granted access to five years ago can still hold an OAuth token. Revoke anything you don’t use.

Mistake 5: Deleting evidence before you check it. Before you clean out Sent or Trash, screenshot anything suspicious. If you need to file a report, that evidence matters.

Myth: If I use Gmail, I’m safe. Gmail’s spam and abuse filters are excellent, but they don’t stop a valid login with your real password. A leaked credential defeats even the best inbox protection.

Myth: I’d know right away if I were hacked. Many takeovers stay quiet for weeks. Attackers often lurk, forward mail silently, and wait for a financial trigger like a wire request.

Myth: I have nothing worth stealing. A “clean” personal email is still valuable because it unlocks other accounts. Attackers buy and sell access to boring inboxes precisely because owners aren’t watching.

Myth: A password manager is dangerous — a hacker could get everything. A reputable password manager encrypts your vault with a key only you know. The risk of reused passwords is far higher than the risk of using a manager.

Frequently Asked Questions About Email Hacking

How can I tell if my email is hacked for free?

Search your address on Have I Been Pwned, then open your provider’s security dashboard. In Gmail, that’s myaccount.google.com/security; in Outlook, account.microsoft.com. Both list recent sign-ins and connected devices. Add a Sent-folder scan and a forwarding-rule check, and you’ve done a full free audit in about five minutes.

Is Have I Been Pwned safe and legitimate?

Yes. Have I Been Pwned is run by security researcher Troy Hunt and is widely trusted across the security industry, including by government agencies. It never stores the password you enter — its “Pwned Passwords” check uses a k-anonymity model so the site never sees your full credential. Entering an email address on the main check page is safe.

What’s the first thing to do if my email was hacked?

Change the password immediately from a device you trust. Then sign out of all other sessions in your account settings. Only after those two steps should you turn on app-based two-factor authentication, remove forwarding rules, and audit third-party app access. Doing them in the wrong order lets the attacker back in.

Can hackers still get in if I have two-factor authentication?

App-based two-factor authentication blocks most account takeovers, but not all. SIM-swap attacks defeat SMS codes, and sophisticated phishing kits can capture app codes in real time. Use an authenticator app or a hardware key like a YubiKey for the strongest protection, and be suspicious of any 2FA prompt you didn’t trigger.

How do I know if someone is reading my emails without logging in?

Check for forwarding rules and filters, unfamiliar app connections, and sessions on unknown devices. In Gmail, review Settings > Forwarding and POP/IMAP, and Security > Your devices. In Outlook, check Mail Rules and Sign-in activity. A silent forward to an unknown address is the most common way an attacker keeps reading after you change your password.

Should I delete my email account if it was hacked?

Usually no. Deleting the account can lock you out of any service that uses it for recovery, and abandoned addresses sometimes get recycled by providers. Recover the account, secure it with a strong password and app-based 2FA, and audit connected services instead. Deletion is only reasonable if you’ve already migrated every important account off it.

How long does it take to recover a hacked email?

If you still have access, full recovery and cleanup takes 30 to 60 minutes for the account itself, plus another hour or two to rotate passwords on linked services. If you’re locked out, provider recovery through Google or Microsoft usually takes 24 to 72 hours and may require ID verification. Start the recovery flow the moment you notice.

Conclusion: Check Now, Secure Once, Sleep Better

Checking whether your email was hacked takes about five minutes and costs nothing. Run Have I Been Pwned, review recent sign-ins in Gmail or Outlook, and check your Sent folder, forwarding rules, and connected apps. If anything looks off, follow the ten-step recovery checklist in order — password first, sessions second, app-based 2FA third.

Your action for today is small. Open your account’s security dashboard right now and glance at “Recent activity.” If it’s clean, spend two more minutes turning on an authenticator app. If it isn’t, you’ve caught a problem while it’s still fixable. Bookmark this guide so you can find the checklist again if you ever need it in a hurry.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *