What to do if…
your email provider warns it will block outgoing mail due to unusual activity
Short answer
Stop sending email for the moment and secure the account from the provider’s official site or app, not from a link in the warning. Change the password, remove suspicious forwarding or rules, and turn on multi-factor authentication.
Do not do these things
- Don’t keep pressing send or repeatedly retrying logins; it can make provider review harder or add delays.
- Don’t use links or buttons inside the warning email unless you independently opened the provider’s official site or app first.
- Don’t assume it is just a glitch if this email account is used for password resets.
- Don’t delete suspicious settings, sent messages, or alerts before you take a few screenshots if you may need to report fraud or ask your provider what happened.
- Don’t install random “cleaner” or “unblock email” apps from ads or pop-ups.
What to do now
-
Pause outbound sending and open the provider safely.
Close your mail app for a moment. Open the provider’s official app, or type the provider’s web address into your browser and sign in there. -
Use the provider’s official verify or unblock flow.
Complete any security prompts shown inside the official site or app. Set a new, unique password that you have not used anywhere else. -
Check recent activity and remove unknown sessions.
In security or account settings, look for recent activity, sign-in history, connected devices, or active sessions. Remove devices or sessions you do not recognize, and choose “sign out of all devices” if it is available. -
Check for mailbox takeover settings.
In mail settings, look for anything you did not create, especially:- Forwarding to another address
- Rules or filters that auto-forward, auto-delete, archive, or hide messages
- Signature changes
- Delegates, shared mailbox access, or send-as permissions
-
Remove unknown apps that can use or send from the account.
In security or connected-app settings, revoke access for apps or services you do not recognize. Remove app passwords you do not need, and check which desktop or mobile mail apps are set up to send through the account. -
Turn on multi-factor authentication and check recovery details.
Add multi-factor authentication or 2-step verification. Confirm your recovery email and phone number are yours, and save backup codes somewhere safe. -
Check the device you used for signs of compromise.
Update the device and run a scan using built-in or reputable security tools. If you suspect the device is compromised, finish account recovery from a different trusted device. -
Check sent, deleted, and archived mail.
Look for messages you did not send, password reset emails you did not request, invoices, payment instructions, or messages asking contacts to click links or send money. -
Warn contacts only after the account is under control.
When sending is restored, send one short correction to people who received suspicious messages from you. Tell them not to open recent unexpected links or attachments from your address. -
If this is a work or organization email, contact IT or security now.
Ask them to check sign-in logs, outbound sending spikes, suspicious rules, and whether other accounts may be affected. -
If money or identity information may be at risk, use official reporting routes.
If a payment, wire, invoice change, gift card request, or business email compromise may be involved, contact your bank, payment service, or workplace finance team immediately. Then file a report with IC3. If identity theft is possible, use IdentityTheft.gov.
What can wait
- Deciding whether to switch email providers can wait.
- Changing every password can wait; first prioritise accounts that reset through this email, especially banking, payroll, cloud storage, shopping, and work accounts.
- Deliverability appeals, domain settings, and email authentication changes can wait unless your provider, IT team, or email administrator tells you they are needed.
- Explaining the whole situation to everyone can wait; secure the account first, then send one calm correction if needed.
Important reassurance
An unusual-activity warning does not always mean someone fully controls your account. Providers may trigger these warnings after a new sign-in, a burst of sending, suspicious app access, or password-risk signals. The immediate job is to prove you are the legitimate user and remove anything that could let someone keep sending as you.
Scope note
These are first steps to stabilize the situation and reduce further harm. Later decisions may need help from your email provider, workplace IT or security team, bank, payment service, identity theft recovery resources, or law enforcement reporting tools.
Important note
This is general information, not legal, financial, cybersecurity, or professional advice. Use official provider channels and protect the email account first, because it may be used to reset other accounts.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.