Discovering that someone has gained access to your email account can be serious because email is often used to reset passwords for banking, shopping, social media, cloud storage, and work accounts. Acting quickly can limit the damage and prevent an attacker from maintaining access.
The exact recovery options depend on your email provider, but the general process is the same: regain control of the account, remove unauthorized access, secure the account, and then check other services that may have been affected.
Use a Trusted Device to Recover the Account
If possible, start the recovery process from a computer or phone that you normally use and that you believe is secure.
Do not follow account-recovery links from suspicious emails, text messages, or social media messages. Instead, open your email provider’s official website or app directly and use its account recovery or security section.
If you are completely locked out, use the provider’s official recovery process. You may be asked to confirm a recovery email address, phone number, previously used password, or another account detail.
Change Your Password Immediately
If you can still access the account, change the password as soon as possible.
Create a password that is:
- unique to the email account;
- not reused on another website;
- long enough to resist guessing attacks;
- stored securely, preferably in a trusted password manager.
If the compromised password was also used on other websites, changing only the email password is not enough. Those reused passwords should be replaced as well.
Sign Out of Unknown Devices and Sessions
Changing the password may not always immediately remove every existing session, so review the devices and sessions connected to the account.
Look for computers, phones, browsers, or locations you do not recognize and sign them out.
If your provider offers an option such as Sign out of all devices or Log out of other sessions, consider using it after changing the password.
Check Recovery Email Addresses and Phone Numbers
An attacker may change recovery information so they can regain access even after you change the password.
Review:
- recovery email addresses;
- recovery phone numbers;
- trusted devices;
- security questions, if the provider still uses them;
- backup authentication methods.
Remove anything you do not recognize and make sure your own recovery information is current.
Check Email Forwarding and Filter Rules
This step is easy to miss.
An attacker who gains access to an email account may create forwarding rules that silently send copies of incoming messages to another address. They may also create filters that automatically hide, archive, delete, or redirect security notifications.
Open your mail settings and inspect:
- automatic forwarding;
- filters and rules;
- blocked addresses;
- automatic replies;
- mail delegation or mailbox access settings.
Delete any rule or forwarding address that you did not create.
Remove Unknown Connected Apps
Some services allow third-party applications to access email, contacts, calendars, or account information without requiring the password every time.
Review applications and services connected to the account and revoke access for anything you do not recognize or no longer use.
Also check for app-specific passwords if your provider supports them. Remove unfamiliar or unnecessary ones.
Enable Multi-Factor Authentication
After regaining control, enable multi-factor authentication if it is available.
This adds another verification step in addition to the password. Depending on the provider, authentication may use an authenticator app, security key, passkey, or another verification method.
Save recovery codes somewhere secure if the provider gives them to you. Do not store the only copy inside the same email account they are designed to protect.
Review Recent Account Activity
Many email providers show recent logins, devices, security events, and changes to account settings.
Look for:
- sign-ins from unfamiliar devices;
- unexpected locations;
- password changes you did not request;
- new recovery information;
- new connected applications;
- security settings that were disabled.
Keep in mind that location information based on an IP address is not always precise, so an unfamiliar city does not automatically prove that an attacker logged in. Consider the device, time, and other information together.
Check Sent, Deleted, and Archived Messages
Review your Sent, Trash, Deleted, Spam, and Archive folders.
An attacker may have used the account to send phishing messages, request money, reset passwords, or communicate with other services.
Also check for password-reset emails or account notifications that you did not initiate. These can reveal which other accounts may have been targeted.
Secure Accounts Connected to Your Email
Your email address may be the recovery method for many other online accounts. Once an attacker controls email, they may be able to request password resets elsewhere.
Prioritize important accounts such as:
- banking and payment services;
- shopping accounts with saved payment information;
- cloud storage;
- social media;
- password managers;
- work accounts;
- mobile carrier accounts.
Check for unauthorized password resets, profile changes, purchases, or unfamiliar sessions.
Change Reused Passwords
If the hacked email password was reused anywhere else, assume those accounts may also be at risk.
Create a different password for each important service. A password manager can make unique passwords much easier to maintain.
Do not simply change a reused password by adding one number or symbol. Use an entirely different password.
Warn Your Contacts
If suspicious messages were sent from your account, tell the affected contacts that the account was compromised.
Ask them to ignore unexpected links, attachments, requests for money, or messages asking for passwords or verification codes.
This can prevent the compromise from spreading through people who trust messages coming from your address.
Check the Device for Security Problems
If you do not know how the password was stolen, review the device you were using around the time of the incident.
Install operating-system and browser updates, remove unfamiliar browser extensions or applications, and run the security tools provided by your operating system or another trusted security product.
If you suspect serious malware, avoid using the affected device for sensitive account changes until it has been checked.
Be Alert for Follow-Up Phishing
After an account compromise, you may receive convincing messages pretending to be security alerts or recovery instructions.
Attackers may know your email address and other details, which can make these messages look legitimate.
Access your email provider and other important services directly instead of clicking unexpected security links.
If Financial Information Was Involved
If the attacker accessed payment information, made purchases, or used your email to interfere with financial accounts, contact the relevant bank, card issuer, payment service, or merchant promptly.
Keep copies of security alerts, suspicious messages, transaction information, and other evidence related to the incident.
If It Is a Work Email Account
For a company or organization account, contact your IT or security team as soon as possible.
A compromised work mailbox can affect more than one person, particularly if it contains internal documents, customer information, shared accounts, or access to business systems.
Avoid deleting evidence before the organization has had an opportunity to investigate the incident.
Email Account Recovery Checklist
- Use the provider’s official recovery process.
- Change the email password.
- Sign out of unfamiliar devices and sessions.
- Check recovery email addresses and phone numbers.
- Remove suspicious forwarding rules and filters.
- Revoke access for unknown connected applications.
- Enable multi-factor authentication.
- Review recent account activity.
- Check Sent, Deleted, Spam, and Archive folders.
- Secure important accounts connected to the email address.
- Change passwords anywhere the compromised password was reused.
- Warn contacts if suspicious messages were sent.
Conclusion
An email compromise should be treated as more than a single password problem. Regaining access is only the first step. You also need to remove unauthorized sessions, check forwarding and recovery settings, secure connected accounts, and determine whether the attacker made other changes.
Once the account is under control, unique passwords and multi-factor authentication can significantly reduce the chance that a stolen password alone will lead to another compromise.
For more practical online safety guides, explore the Security section on Howzora.






