Account Security
Is My Email Compromised? How to Check and What to Do
An exposed email address and a compromised email account are not the same thing. Check for known exposure, then review login activity, sessions, recovery settings, and forwarding rules to determine whether someone may actually have accessed your inbox.
Exposure and account compromise are different
This distinction matters.
Email exposure means your address may have appeared in information obtained from a breach or another data exposure.
Email compromise means someone actually gained unauthorized access to your account.
An address can be exposed because you used it on a completely unrelated website.
For example, you might create an account with an online store using your primary email address. If the store later suffers a data exposure, your email could appear in that data even though your email provider itself was never compromised.
That is why a breach result alone cannot tell you whether someone is reading your inbox.
Signs your email may actually be compromised
Look inside the account itself.
Warning signs include:
The FTC recommends checking forwarding rules, sent messages, deleted messages, recovery information, and active devices after unauthorized access is suspected.
One suspicious notification does not always prove compromise, but several of these signs together deserve immediate action.
- A device you do not recognize
- A successful login you did not make
- Your password changing unexpectedly
- A recovery email you did not add
- A recovery phone number you do not recognize
- Messages in your Sent folder that you did not send
- Deleted messages you do not remember deleting
- New forwarding rules
- Unknown connected applications
- Losing access to your account
Review your login activity
Go directly to your email provider's official website or app.
Look for sections such as:
Pay attention to the combination of device, time, browser, and location.
Location alone can sometimes be misleading because mobile networks, VPNs, and internet providers can make legitimate activity appear to come from another place.
An unfamiliar device combined with activity at a time you know you were not logging in is more concerning.
- Recent activity
- Security activity
- Devices
- Active sessions
- Where you're signed in
Check for unauthorized forwarding
This is one of the easiest signs to miss.
Someone who gains access to your inbox may configure mail to automatically forward to another address.
That can allow them to continue receiving messages even after other security changes.
Delete anything you did not create.
The FTC specifically advises hacked-email victims to inspect forwarding settings because unauthorized rules can send copies of their messages elsewhere.
- Forwarding
- Filters
- Inbox rules
- Delegated access
- Connected accounts
Review recovery information
Check the recovery email address and phone number attached to your account.
Both should belong to you.
If someone changes recovery information, they may be able to regain control later even after you replace your password.
Also review trusted devices or authentication methods.
What should I do if my email is compromised?
If there is evidence of unauthorized access, secure the account immediately.
Change the password.
Use a completely new password.
Do not reuse it on another website.
NIST recommends password managers because they can generate and store unique credentials for different accounts.
Sign out other devices.
Use the provider's option to remove unfamiliar sessions.
If unauthorized access seems likely, signing out all other sessions can force anyone using an existing session to authenticate again.
The FTC recommends signing out of all devices after recovering a hacked account.
MFA adds another requirement beyond your password.
Even if someone obtains the password, the additional factor may prevent access.
NIST explains that MFA provides another layer of protection when a password is compromised.
Consider a passkey.
Where supported, passkeys can reduce reliance on reusable passwords.
NIST notes that passkeys use unique digital credentials and are substantially more resistant to phishing than ordinary passwords.
Why protecting email matters so much
Your email is often the recovery channel for other accounts.
Someone controlling your inbox may be able to request password resets for:
and receive the reset messages themselves.
The FTC specifically highlights this chain of risk when explaining why email accounts deserve strong protection.
Secure your primary email before less important accounts.
- Social accounts
- Shopping services
- Cloud storage
- Financial platforms
- Work accounts
What if my email was exposed but nobody logged in?
That is a much better situation.
If a checker indicates exposure but your account activity looks normal:
Exposure should be treated as information that helps you decide what to protect.
It is not automatic evidence of account takeover.
- Make sure your password is unique
- Replace it if it was involved in the exposure
- Enable MFA
- Consider a passkey
- Review recovery settings
- Be more alert for phishing
Review your email exposure
4safer is intended to help separate:
Those situations require different responses.
A positive exposure result does not prove unauthorized access.
Practical email security checklist
- [ ] Check your email for known exposure
- [ ] Review recent login activity
- [ ] Review signed-in devices
- [ ] Check recovery information
- [ ] Check forwarding rules
- [ ] Review Sent and Deleted folders
- [ ] Remove unknown connected applications
- [ ] Change compromised passwords
- [ ] Eliminate password reuse
- [ ] Enable MFA
- [ ] Consider a passkey
- [ ] Enable login alerts
- [ ] Secure your primary email first
- [ ] Never approve unexpected authentication requests
Frequently asked questions
How do I know if my email is compromised?
Review login activity, active sessions, recovery information, forwarding settings, and sent messages. These provide stronger evidence of account access than an email exposure result alone.
Does finding my email in a breach mean it was hacked?
No. Your email address can appear in an unrelated company's breach without anyone accessing your inbox.
Should I change my password?
Change it if it was exposed, reused elsewhere, entered into a suspicious website, or if you see evidence of unauthorized account access.
What are unauthorized forwarding rules?
They are settings that automatically send incoming email to another address. Someone with account access may create one to continue receiving your messages.
Should I enable MFA?
Yes. MFA adds another authentication requirement and can reduce the usefulness of a stolen password.
What if nothing suspicious appears?
That is reassuring, but continue using a unique password, MFA or passkeys, and account alerts. No exposure check or activity log can guarantee complete safety.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
