Your email password stopped working. Or you notice emails in the Sent folder that you didn’t write. Or a friend texts saying they received a strange link from your address. Or nothing obvious has happened — you just have a nagging feeling that one of the breaches you’ve heard about might have included your credentials. All of these are reasons to know how to check if your email was hacked, what the signs look like, and what to do immediately if the answer is yes. This fits into the wider topic we cover in our Complete Guide to Online Security and Privacy.
Email account compromise is among the most consequential digital security incidents a person can experience, because email is the master key to every other account. Most online services use email-based password reset as their recovery method — which means whoever controls your email can reset and take over virtually every other account you own, from banking to social media to cloud storage. Responding quickly limits the damage dramatically compared to discovering the compromise weeks after it occurred.
Warning signs — check these first
Some signs are visible before you even attempt to log in:
- Can’t sign in with a password you know was correct — the attacker has already changed the password to lock you out
- Receiving password reset emails for accounts you didn’t attempt to reset — the attacker is working through your accounts using your email as the reset destination
- Friends or colleagues reporting unusual emails from your address — spam, phishing links, or requests for money indicate active malicious use
- Unfamiliar emails in your Sent folder
- Login notifications from locations or devices you don’t recognise
- Unexpected changes to account recovery settings — alternate email or phone number changed
The account activity log is the definitive record. Check it even if you notice no obvious signs — stealth access that doesn’t change your password or send emails is often missed for months.
Gmail: account photo → Manage your Google Account → Security → Recent security events, and Manage all devices for device access. Also: at the very bottom of the Gmail inbox, there’s a small “Last account activity” link showing recent access with IP addresses and access methods.
Microsoft Outlook/Hotmail: account.microsoft.com → Security → Review activity → filter for recent sign-in activity. An IP address geolocating to a country you’ve never visited, combined with a login time when you were asleep, is definitive evidence of compromise.
Quick check — Have I Been Pwned: navigate to haveibeenpwned.com and enter your email address. The site cross-references your email against over 14 billion credentials from known data breaches and tells you which breaches your email appeared in and what data was exposed. A positive result doesn’t definitively mean your account is currently compromised — but it means your email address and potentially your password are in criminal databases. If the breached service shares a password with your email account, treat the email as compromised and change the password immediately.
Checking for stealth access — third-party apps and forwarding rules
Email compromise doesn’t always mean the attacker knew your password. OAuth app access — where third-party applications are granted access — is a persistent vulnerability that survives password changes. If you ever clicked “Sign in with Google” or granted a third-party app permission to read your emails, that application has OAuth access that persists independently of your password. A malicious application granted OAuth access can read, send, and delete emails without needing your password at all.
Gmail: myaccount.google.com/security → “Third-party apps with account access” → review every listed application. Any application you don’t recognise or no longer use should be removed immediately — click “Remove Access.”
Microsoft accounts: account.microsoft.com → Privacy → App access → review and revoke anything unfamiliar.
Apple ID email: appleid.apple.com → Sign-In and Security → “Apps Using Apple ID” → manage and revoke as needed.
Email forwarding rules are the other form of access that survives password changes. An attacker who accessed your account may have created a forwarding rule that silently copies every incoming email to an external address — meaning they continue to receive all your emails even after you regain control and change the password.
Gmail forwarding: Settings → See all settings → Filters and Blocked Addresses, and then → Forwarding and POP/IMAP. Delete any forwarding addresses you didn’t create.
Outlook forwarding: Settings → Mail → Forwarding — confirm no forwarding is enabled. Remove any rules in the Rules section that forward to external addresses.
Immediate steps after confirming compromise
The response is time-sensitive. Every minute of delay gives the attacker more opportunity to reset accounts using your email, exfiltrate sensitive information, and dig deeper into connected services. Priority order:
- Regain account access first. If the attacker hasn’t yet changed your password, change it immediately using your password manager to generate a strong unique one. If you’re locked out, use the account’s official recovery process — Gmail at accounts.google.com/signin/recovery, Microsoft at account.live.com/acsr. Do not click recovery links from emails received during the compromise — verify the recovery URL manually.
- Enable two-factor authentication immediately if it wasn’t already active. This prevents re-entry even if the attacker still has the password.
- Remove all unrecognised third-party app access and delete any forwarding rules you didn’t create.
- Change passwords for linked accounts — specifically financial accounts, your password manager’s account, and other email accounts. These are the likely targets if the attacker’s motivation was financial or identity theft.
- Check Google Security Checkup (myaccount.google.com/security-checkup) or the Microsoft equivalent (account.microsoft.com/security) — these flag connected apps, recent security events, and risky settings in a single guided review. Takes five minutes and catches problems that manual review across multiple settings pages might miss.
Our guide on setting up two-factor authentication covers the setup process for preventing re-compromise, and our guide on using a password manager covers generating and storing the strong unique passwords that prevent future credential stuffing. For breach monitoring that goes beyond Have I Been Pwned, Firefox Monitor provides ongoing alerts when new breaches include your email address.
Prevention — what changes after a compromise
Understanding how to check if your email was hacked is most useful combined with the practices that make future compromise much harder. The two changes that address the most common attack vectors simultaneously:
- A strong unique password used nowhere else: eliminates automated credential stuffing attacks — the email has a unique password not found in breach databases
- Two-factor authentication using an authenticator app (not SMS): eliminates phished-password attacks — the attacker needs the second factor they don’t have
Email alias services provide an additional layer of protection. Services like SimpleLogin, AnonAddy, and Apple’s Hide My Email create unique per-service email addresses that forward to your real inbox. If a service is breached, only that alias is exposed rather than your primary email address. You can disable the compromised alias without affecting the primary inbox. This significantly reduces the value of your email address as a target, because the real address is never directly exposed to the services being breached.
Making account security checks a regular habit
Checking if your email was hacked shouldn’t be a reactive exercise only when something feels wrong — a quarterly active review catches compromise at every stage from initial breach to active exploitation.
| Check | Where to do it | Time required |
| Activity log review | Google: Account → Security → Recent security events; Microsoft: account.microsoft.com/security | 2 minutes |
| Connected apps audit | myaccount.google.com/security → Third-party apps | 5 minutes |
| Forwarding rules check | Gmail: Settings → All settings → Forwarding and POP/IMAP | 2 minutes |
| Breach database check | haveibeenpwned.com | 1 minute |
| Full security checkup | myaccount.google.com/security-checkup | 5 minutes |
The 15-minute quarterly habit that completes this table once provides more security visibility than most users achieve in a year of reactive incident response. Setting up security alert notifications (Google Account → Security → email alerts for new device sign-ins) provides real-time awareness of unusual access rather than discovering it weeks later during a manual audit.
What if someone is reading your emails without changing your password?
Stealth access — enabled by forwarding rules, OAuth app access, or a device that remained logged in after a compromise — is the most insidious form because nothing on the surface suggests a problem. The inbox works, the password works, no lockout occurred. The attacker’s goal is monitoring rather than takeover.
Detecting this requires the active review of connected apps and forwarding rules described earlier, combined with checking the “Last account activity” link at the bottom of the Gmail inbox. An entry showing “IMAP access from IP: [unfamiliar address]” indicates an external email client is pulling your emails — either a legitimate app you set up, or an attacker using IMAP access.
Revoking all app passwords and device access from the Google security settings, then re-adding only the apps you actually use, closes this surveillance vector without necessarily requiring a password change if you’re not yet certain the account is compromised. For accounts that you’re not sure about, performing the full connected-app audit first and then deciding whether to change the password based on what’s found avoids the disruption of a password change when it might not be needed — while still ensuring any persistent access is revoked.
Email security is ultimately about visibility — knowing who has access at every level: login history, connected applications, forwarding rules, and breach databases. Each channel is a potential path for unauthorised access, and understanding all four means no compromise vector goes undetected for months while damage accumulates.
Helping someone else check their email
If you’re helping an elderly relative or a colleague who received complaints from their contacts about unusual emails: start with the activity log check and the Have I Been Pwned query before touching any settings. These two steps take under three minutes and immediately confirm or rule out compromise without making any changes that might complicate subsequent response if compromise is confirmed.
Only after confirming whether the account was accessed do the remediation steps — password change, 2FA setup, connected app review — make sense as a sequence. Starting with remediation before confirming the fact of compromise leads to either over-responding to a false alarm or under-responding by not completing the full necessary response because the scope wasn’t understood from the beginning. Confirm first; respond based on what the activity log shows.
Dark web monitoring — going further than Have I Been Pwned
Have I Been Pwned covers public breach databases — data that has been leaked publicly. Dark web monitoring services go further, scanning private criminal marketplaces and forums where stolen credentials are sold before they make it into public databases. This provides early warning — discovering that credentials are circulating in criminal channels before they’re tested against accounts gives time to change passwords proactively.
Options worth knowing:
- Firefox Monitor (monitor.mozilla.org) — free, ongoing alerts when new breaches include your email
- Google’s Password Checkup (passwords.google.com) — scans saved credentials against breached databases
- Dashlane, 1Password dark web monitoring — included in premium subscriptions, checks credentials against dark web sources
- Credit monitoring services (Experian, Equifax) — include dark web monitoring as part of identity protection packages
The practical value is time — catching compromised credentials before they’ve been tested against your accounts is significantly better than discovering the compromise after the fact. For accounts containing sensitive financial or personal data, the premium monitoring services are worth their cost. For most other accounts, Have I Been Pwned plus Google/Microsoft’s own security checkup tools cover the majority of breach scenarios without additional cost. See also Email Security Best Practices for a related case.
Knowing how to check if your email was hacked is ultimately about maintaining the habit of active security visibility rather than reactive incident response. The checks described in this guide take less than 15 minutes quarterly and provide comprehensive coverage across every path through which email compromise can occur — from obvious lockout events to silent forwarding rules that take months to discover without deliberate review. You might also run into Incident Response Plan.







