Skip to content
All guides

Email Security

Why Is My Email Sending Messages I Did Not Write?

Messages sent in your name may come from account compromise, a connected app, malware, or email spoofing. This guide helps consumers verify what happened and secure the mailbox without panic.

By the 4safer teamUpdated August 29, 20268 minutes read

There are two main possibilities

If your email is sending messages you did not write, either someone or something may be using your account, or a scammer may be spoofing your address so messages only look like they came from you. Check your Sent folder, recent login activity, forwarding rules, connected apps, and security alerts through your official email provider.

If the messages appear in your Sent folder, Drafts, Deleted Items, or account activity, treat it as possible account misuse. If contacts receive strange emails but nothing appears in your account, spoofing is possible. Spoofing is still frustrating, but it is different from someone being inside your mailbox.

Do not reply to suspicious messages, do not send anyone a one-time code, and do not enter your password into links sent by email.

How email spoofing differs from account access

Email was designed in a way that can allow senders to make messages appear to come from another address. Many providers use protections to reduce spoofing, but recipients may still see fake messages that use your name or address.

Account access means a person, malicious app, or stolen session can actually use your mailbox. That is more serious because they may read messages, send mail, reset passwords, or create forwarding rules.

The practical question is whether evidence exists inside your real account. Start there before assuming the worst.

  • Sent messages you do not recognize.
  • Deleted replies or warnings.
  • Unknown forwarding rules.
  • Unfamiliar devices or locations.
  • Connected apps you do not recognize.
  • Password or recovery changes you did not make.

Check your account without clicking strange links

Open your email account from the official app or by typing the provider's address yourself. Review recent activity, active sessions, mailbox rules, forwarding, filters, connected apps, recovery methods, signatures, and automatic replies.

The FTC lists messages sent from your account, unfamiliar logins, and password or username changes as signs that an account may have been hacked. Microsoft and Google also recommend reviewing mailbox rules and forwarding because those settings can hide activity.

If you use a work email, report the issue to IT or security. Do not investigate other accounts or download suspicious attachments to prove what happened.

Check whether your address is exposed

If your address appears in known exposure data, it may explain why scammers are using it in spoofing or phishing campaigns. A match does not prove they accessed your mailbox, but it increases the reason to secure the account and warn contacts if needed.

Only check email addresses you own or are authorized to manage. Never enter a current password, authentication code, or sensitive identity number into an exposure checker.

If messages are in your Sent folder

Change your password immediately through the official provider site. Use a unique password. Then sign out of other sessions, enable MFA, and review recovery settings.

Check sent mail, deleted mail, forwarding, filters, signatures, connected apps, and automatic replies. Remove anything you did not create. If your contacts received scam messages, send a short warning from a secured account or another trusted channel.

  • Change the password.
  • Enable MFA.
  • Sign out of unknown devices.
  • Remove unknown rules and apps.
  • Check recovery email and phone.
  • Warn contacts not to click prior links.

If nothing appears in your account

If there are no sent messages, no unfamiliar sessions, and no suspicious rules, spoofing is possible. You may not be able to stop every fake message using your address, but you can make sure your real account is protected.

Ask affected contacts to report the message as phishing or spam. They should avoid clicking links or opening attachments. You can also check whether your domain, if you own one, has email authentication records, but everyday consumers using large providers usually rely on provider protections.

Check your device and browser

If your account was actually sending messages, scan your device using trusted security software, update your operating system and browser, and remove suspicious browser extensions. Microsoft advises clearing malware before changing a password when recovering a compromised account.

This matters because a password change may not help if a malicious app or stolen browser session remains active.

Protect accounts connected to the mailbox

If someone may have had mailbox access, review important accounts that use this email for password resets. Start with financial accounts, cloud storage, social media, work tools, and payment apps.

Change reused passwords and enable MFA. If you see unfamiliar changes, use the provider's account recovery process.

Create a short incident record

Write down when contacts reported the messages, what the subject lines were, whether anything appeared in Sent, and what security steps you completed. This helps if you need support from the email provider, employer, bank, or law enforcement later.

If money was lost or fraud occurred, use official reporting channels such as the FTC or FBI IC3 as appropriate.

Frequently asked questions

Does email spoofing mean my account was hacked?

No. Spoofing can make a message look like it came from you without access to your mailbox. Check sent mail and account activity.

What if the messages are in my Sent folder?

Treat it as possible account misuse. Change the password, enable MFA, sign out of sessions, and remove unknown rules or connected apps.

Should I warn my contacts?

Yes, if they received suspicious messages. Tell them not to click links, open attachments, send money, or share codes.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.