PanicStation.org
us Technology & digital loss

What to do if…
your email account is sending messages or spam you did not create

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat the account as potentially compromised. From a trusted device, open your email provider’s official website or app directly, change or recover the password, remove unfamiliar access and settings, and turn on multifactor authentication.

Do not do these things

  • Do not use a link or phone number from an unexpected account-warning message.
  • Do not approve an unexpected sign-in request or share a verification code.
  • Do not reuse the old password or another account’s password.
  • Do not send sensitive information from the account until you have secured it.
  • Do not delete the account, wipe the mailbox, or remove unfamiliar messages before noting what happened.
  • Do not pay an unsolicited person or service claiming it can recover the account.
  • Do not assume every device and account you own has been accessed.

What to do now

  1. Use a device you trust, if one is available. Open the provider’s official app or type its known website address yourself instead of following a link in an email or text message.

  2. Change the email account password to a strong, unique password. If you cannot sign in, use the provider’s official account-recovery process. For a work or school account, contact the organization’s IT or security team promptly.

  3. Check recent account activity, signed-in devices, and active sessions. Use the provider’s security controls to sign out unfamiliar sessions and remove devices you do not recognize.

  4. Check the recovery email address, recovery phone number, security methods, and other account details. Correct or remove anything you did not add.

  5. Turn on multifactor authentication using a method offered by the provider. Do not approve any sign-in request you did not initiate.

  6. Review forwarding addresses, inbox rules, filters, delegates, automatic replies, connected applications, and app passwords. Disable or remove unfamiliar entries.

  7. Look in the Sent, Trash or Deleted, and account-activity areas. Note unfamiliar messages, sign-ins, password resets, or setting changes so you can describe the incident to the provider or your organization.

  8. Warn recent contacts through another trusted channel that messages from your address may be unsafe. Ask them not to open unexpected links or attachments, send money, or share information in response.

  9. If you recently opened an unexpected attachment, entered your password on an unfamiliar page, or installed software, update the device and run its built-in or reputable security scan before using it for further account changes.

  10. If the old password was used on other accounts, change it on those accounts through their official websites or apps. Prioritize accounts used for password recovery, money, phone service, or important files.

  11. If contacts received messages but you find no unfamiliar sent mail, settings, devices, or account activity, the sender address may have been spoofed. Keep the account secured and contact the email provider if the messages continue.

  12. If the incident caused unauthorized financial activity or misuse of your personal information, contact the affected organization through verified contact details and use IdentityTheft.gov for recovery steps.

What can wait

You do not need to identify who sent the messages, determine exactly how it happened, review every old email, close the account, choose a new address, or contact everyone you have ever emailed right now. Secure the account, remove unfamiliar access and settings, and warn the contacts most likely to act on the messages first.

Important reassurance

Messages sent without your knowledge are a reason to act, but they do not prove that every device, file, or account you own has been accessed. Sender addresses can also be forged, so checking the account methodically is more useful than assuming the worst.

Scope note

This guide covers immediate containment and account-recovery steps only. Later decisions may require help from the email provider, an organization’s IT or security team, a financial institution, or an identity-theft specialist.

Important note

This is general information, not legal, financial, cybersecurity, or other professional advice. Email providers use different menus and recovery processes, so follow the current instructions on your provider’s official website or app.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us