Email Security
What to Do If Someone Added a Delegate to Your Mailbox
A mailbox delegate may be able to read, send, or manage messages depending on the provider and account type. If you find a delegate you do not recognize, remove it through official settings, secure the account, and review related access.
Unknown delegate access is a serious signal
If someone added a delegate to your mailbox and you did not approve it, treat it as a serious account security issue. Open your email provider's official settings, remove the delegate if possible, change your password, enable multifactor authentication, and review recent activity.
Delegation lets another account act on your mailbox in some way. Depending on the provider, a delegate may be able to read messages, send messages, manage calendar items, or respond as you. That makes unknown delegation more sensitive than an ordinary marketing email or spam message.
Do not assume who did it without evidence. In workplaces, administrators may configure mailbox access for legitimate reasons. In a personal account, however, unexplained delegation is unusual enough to investigate immediately.
What mailbox delegation can expose
Email contains password reset links, financial alerts, private conversations, travel plans, receipts, medical messages, and security notices. If another account can read or send from your mailbox, it may also affect services that rely on that email for recovery.
Delegates are especially important because access may persist even when you focus only on changing the password. Microsoft's guidance for compromised mailboxes specifically points administrators and users toward suspicious rules, forwarding, and access settings during review.
A delegate is not always malicious. Assistants, family members, shared business roles, and administrators may have legitimate access. The key question is whether you recognize it and whether it still needs access.
- Private messages may be visible.
- Password reset links may be exposed.
- Messages may be sent in your name.
- Security alerts may be hidden or ignored.
- Business or financial messages may be affected.
Verify through official account settings
Do not use a link from a suspicious alert to review delegation. Open your email provider directly. Look for delegation, account access, shared mailbox access, connected apps, forwarding, filters, rules, send-as addresses, and recent activity.
If this is a work or school mailbox, contact IT or security before removing access. They may need to preserve logs or explain a legitimate configuration.
If this is a personal mailbox and you cannot explain the delegate, remove it and continue with full account hardening.
Remove the delegate and secure sign-in
Remove unknown delegate access first, then change your password and turn on MFA. Use a unique password that is not used on any other account. CISA recommends MFA because it adds protection beyond the password.
If the provider offers a sign-out-everywhere option, use it after changing the password. Then review recent activity for unfamiliar devices or locations.
- Remove unknown delegates.
- Change reused passwords.
- Enable MFA.
- Sign out unknown sessions.
- Review recovery email and phone.
- Remove unknown connected apps.
Check for other hidden access
Delegation is one access path. Also review forwarding, filters, inbox rules, app passwords, POP or IMAP access, automatic replies, and send-as settings. A suspicious mailbox often has more than one persistence method.
Search for rules that target words like password, reset, code, bank, invoice, payroll, or security.
Review accounts that depend on this inbox
If someone may have read your email, review important accounts that send reset links there. Start with banking, payment apps, cloud storage, social media, phone carrier, and work tools.
Change reused passwords and check recovery settings on those accounts.
Check exposure as context, not proof
If your email appears in known exposure data, it may explain why the account was targeted. It does not prove delegation was malicious or that the mailbox was accessed.
Only check identifiers you own or are authorized to manage. A clean result means no known match was found in the searched sources.
Document what you found
Keep a short record of the delegate address, date found, settings changed, and suspicious events. This helps if you need provider support, employer security review, or official reporting later.
If fraud or financial loss occurred, use official reporting resources such as the FTC or FBI IC3.
Frequently asked questions
Is mailbox delegation always bad?
No. Delegation can be legitimate, especially at work. Unknown or unnecessary delegation should be removed and investigated.
Does changing my password remove a delegate?
Not necessarily. Review delegation and connected access separately.
Should I report an unknown delegate on work email?
Yes. Report it to IT or security before making changes that could affect workplace systems.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
