Why Your Email Account Is a High-Value Target
Your email inbox is more than a place for messages — it's the master key to your digital life. Attackers who gain access to your email can reset passwords for your bank, social media, and shopping accounts, often without triggering any obvious alarms. That's what makes email compromise both common and consequential.
Account takeovers don't always look dramatic. In many cases, an attacker gains quiet access and uses your account slowly and carefully to avoid detection. Knowing what to look for is your first line of defense. The warning signs below cover the most reliable indicators that something may be wrong — and what to do about each one.
Common entry points include phishing emails and social engineering attacks as well as everyday security habits that quietly create vulnerabilities.
Emails in your Sent folder you didn't write
This is one of the clearest red flags. If your Sent folder contains messages you don't remember writing — especially ones with links, requests for money, or unusual attachments — an unauthorized user may have sent them through your account. Attackers often use compromised accounts to spread phishing messages to the victim's contacts, exploiting existing trust relationships.
Check your Sent folder regularly, even if you're not expecting anything unusual. Some attackers delete sent messages after the fact, so an inexplicably empty Sent folder can also be suspicious.
Messages you didn't write appearing in your Sent folder are one of the clearest signs of account compromise.
Login activity from unfamiliar locations or devices
Most major email providers maintain a login history that shows the approximate location, device type, and time of each sign-in. If you see access from a city you've never visited, a device you don't own, or logins at hours when you were asleep, that warrants immediate attention.
To find this information, look for a link labeled something like "Last account activity," "Security events," or "Active sessions" in your account settings. If anything looks out of place, sign out all active sessions and change your password right away.
Login activity from places you've never been is a reliable indicator that someone else has your credentials.
Password reset emails you didn't request
Receiving a reset email for a service you didn't try to log into is a sign that someone may be attempting to use your inbox to take over other accounts. Email is the standard recovery method for most online services, so an attacker with inbox access can trigger resets and intercept the links before you even notice.
If you receive unsolicited reset emails, don't ignore them. Change your email password immediately and check whether the targeted account has been altered. This pattern is a sign that your inbox may already be accessible to someone else.
Unsolicited password reset emails for other accounts suggest your inbox is being actively used as a takeover tool.
Changes to account settings you didn't make
Attackers sometimes modify account settings to make ongoing access easier or to intercept information without your knowledge. Watch for changes such as: a new email forwarding address routing copies of your mail elsewhere, an unfamiliar recovery phone number or email, or a new app listed under connected account permissions.
Review your account settings periodically — not just when something feels wrong. Many providers allow you to set up alerts for security-related changes, which is worth enabling.
A new forwarding address or altered recovery details in your settings can mean someone has quietly edited your account.
Friends or contacts report strange messages from you
If people in your contact list reach out to say they received a suspicious link, an unusual request, or a message that doesn't sound like you, that's a strong signal that your account has been used without your knowledge. Attackers favor this approach because recipients are more likely to engage with messages from a known sender.
Take these reports seriously even if you can't find evidence in your own Sent folder — some attackers clean up after themselves. This kind of feedback from others is often how compromises first come to light. Understanding how scam tactics work can help you explain the situation to affected contacts.
Reports from contacts about strange messages from your address often surface a compromise before you spot it yourself.
You're suddenly locked out of your own account
If your password no longer works and you didn't change it, an attacker may have changed it to lock you out — a sign that the intrusion has moved from quiet surveillance to outright account takeover. This is the most urgent scenario and requires immediate action through your provider's account recovery process.
Use a secondary email address or phone number linked to the account to verify your identity and regain access. If recovery options have also been changed, contact your email provider's support team directly. The sooner you act, the less opportunity an attacker has to use your account as a springboard into other services.
Being locked out with a password you didn't change is the most urgent sign of a full account takeover.
What to Do If You Spot These Signs
If several of the signs above feel familiar, don't wait. Start by changing your email password immediately to something long and unique — a passphrase made of four or more unrelated words works well. Then enable two-factor authentication (2FA), which requires a second verification step even if someone has your password.
Set Up Login Alerts Now — Not Later
Most email providers allow you to receive a notification whenever your account is accessed from a new device or location. Enabling this takes only a minute and means you don't have to manually monitor login history to catch unusual activity. Look for this option under your account's security or notification settings.
Next, review the list of apps and services that have permission to access your email account. Most providers offer this under account settings — revoke anything you don't recognize or no longer use. Finally, check whether the same password was used on other sites. If so, change those too, since a breach in one place often leads to attempts elsewhere. You can learn more about what happens to credentials after a breach in our article on what happens to your data when a website gets hacked.
Periodic account checkups — reviewing login history, connected apps, and forwarding rules every few months — can catch problems before they escalate.
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.

