You can’t log in. Or maybe a friend just texted, “Did you mean to send me this weird link?” Either way, something feels off, and you need an answer fast, not a lecture.
The quickest way to check if your email has been hacked is to run your address through a breach-checking tool like Have I Been Pwned, then review your account’s recent login activity and sent folder for anything you don’t recognize. This guide walks through both checks, plus what to do the moment you confirm a breach.
I’ve spent over a decade helping people and small businesses recover compromised accounts, and the pattern is always the same: the earlier you catch it, the less damage it does.
What Does It Actually Mean for an Email to Be “Hacked”?
There are two different problems people lump together as “my email got hacked,” and they require different fixes. One means your password leaked in a data breach somewhere else; the other means someone is actively inside your inbox right now.
Your email address was exposed in a data breach. A company you signed up with — a retailer, a forum, a service — got hacked, and your email and possibly your password ended up in a stolen database. This doesn’t necessarily mean your inbox itself was accessed. It means your credentials are now circulating, and if you reused that password anywhere else, those accounts are at risk too.
Your inbox was actually accessed by someone else. This is the more serious scenario. Someone used your leaked or guessed password (or tricked you into giving it up via phishing) to log into your actual email account. From there, they can read your messages, reset your other passwords, and impersonate you to your contacts.
In my testing across dozens of breach-checking and recovery cases, I’ve found that most people discover the first problem (exposure) before the second one (active access) ever happens — which is exactly why checking proactively matters. In 2024 alone, 284 million email accounts were compromised in data breaches, and most of those owners had no idea until they checked.
How Do You Check If Your Email Has Been Hacked? (Step-by-Step)
The fastest way to check is a two-part process: first scan your email address against known breach databases, then manually inspect your account’s activity log and sent folder for unauthorized actions. Doing both takes under five minutes and catches almost every real-world hacking scenario.
Here’s the exact sequence I recommend, in order:
- Run your email through Have I Been Pwned (haveibeenpwned.com). Type in your address and hit search. It checks your email against billions of records from publicly known breaches and tells you which sites exposed your data and when.
- Check your password manager’s built-in breach report. If you use Bitwarden, 1Password, or a similar tool, open its “breach report” or “watchtower” feature — it cross-references your saved logins automatically and flags reused or weak ones.
- Review your email account’s recent activity log. In Gmail, scroll to the bottom of your inbox and click “Details” next to “Last account activity.” In Outlook, go to Account → Security → Review Recent Activity. Look for logins from unfamiliar locations, devices, or times.
- Check your Sent folder and Outbox. Scan for messages you didn’t write — especially ones asking contacts for money, gift cards, or to click a link.
- Look at your forwarding and filter rules. Hackers often set up silent auto-forwarding to a hidden address so they can keep reading your mail even after you change your password. In Gmail: Settings → Forwarding and POP/IMAP. In Outlook: Settings → Mail → Forwarding.
- Check your recovery email and phone number. If either has been changed and you didn’t do it, someone else has account-level control.
- Run a malware scan on the device you use most for email. Stolen passwords often come from infostealer malware sitting quietly on a laptop or phone, not just from website breaches.
If any of these steps turn up something unexpected, treat it as confirmed and move straight to securing the account — don’t wait for a second sign.
A quick note on Google specifically: the Dark Web Report feature inside Google One, which used to scan for your exposed data automatically, was discontinued in February 2026 after Google said user feedback indicated it wasn’t providing useful follow-up guidance. If you were relying on it, you now need to check manually using the tools above.
What Are the Real Warning Signs Your Email Was Hacked?
The clearest signs are messages you didn’t send, login alerts from unfamiliar devices or locations, a password reset you didn’t request, and missing or rearranged emails. Any one of these on its own is worth investigating immediately, and two or more together almost always mean active compromise.
Here’s what each one looks like in practice, based on cases I’ve worked through:
You’re suddenly locked out. Your password no longer works, and you didn’t change it. This is often the first sign someone has already taken over the account and changed the password to lock you out.
Contacts report strange emails “from you.” This is usually how people first find out. A coworker, friend, or family member gets a message with a vague link or urgent money request, supposedly from your address, but you never sent it.
You get a login alert from a strange location. Email providers send “new sign-in detected” alerts when a device or location doesn’t match your usual pattern. If you weren’t the one logging in, don’t ignore it.
You receive password reset emails you didn’t request. Attackers often trigger “reset your password” emails on other sites (banking, shopping, social media) to test whether they can pivot from your email into your other accounts.
Your sent folder has messages you don’t recognize. Even if the hacker deletes evidence from “Sent,” check “Trash” and “All Mail,” since deletion isn’t always thorough.
Filter or forwarding rules appeared that you didn’t create. This is the sneakiest sign because it doesn’t lock you out — it just quietly copies your incoming mail somewhere else, often for weeks before you notice.
| Warning Sign | What It Usually Means | Urgency |
|---|---|---|
| Can’t log in at all | Password already changed by attacker | Immediate — recover account now |
| Contact reports a strange email from you | Active sending from compromised account | Immediate |
| Login alert from unknown device/location | Recent unauthorized access attempt | High |
| Unrecognized password reset emails | Attacker testing access to linked accounts | High |
| New forwarding rule you didn’t set | Silent, ongoing data theft | High |
| Email found in a breach database (HIBP) | Credentials exposed, not necessarily active access | Moderate — change password now |
What Should You Do Once You Confirm a Hack?
If your email has been hacked, the priority order is: regain access, change the password from a clean device, remove any unauthorized forwarding rules or recovery info, enable two-factor authentication, and then notify your contacts. Skipping the order — for example, just changing the password while a forwarding rule is still active — leaves the door open.
Recover access first. If you’re locked out, use your provider’s account recovery flow (Google’s is at accounts.google.com/signin/recovery, Microsoft’s is at account.live.com/acsr). Have your recovery phone or backup email ready.
Change your password from a device you trust. Use a long, unique passphrase — not a variation of your old one. In one case I reviewed, a user changed “Summer2023!” to “Summer2024!” after a breach; the attacker had already harvested both the pattern and the email, and got back in within days.
Remove anything the attacker added. Check forwarding rules, filters, linked apps, and recovery email/phone fields. Delete anything you don’t recognize.
Turn on two-factor authentication (2FA). This single step blocks the overwhelming majority of follow-up attacks, because even a stolen password becomes useless without your second factor. IBM’s 2025 Cost of a Data Breach Report found that breaches starting with compromised credentials cost organizations an average of $4.67 million, and weak or absent multi-factor authentication is consistently cited as a top contributing factor.
Check accounts tied to that email. Anything using “Sign in with Google” or “Forgot password” recovery through that inbox is now at risk. Go through banking, shopping, and social accounts and reset passwords there too, especially if reused.
Tell your contacts. A short, calm heads-up (“my email was compromised, ignore anything strange you got from me, here’s what to do if you clicked anything”) limits the damage to people in your network.
Common Mistakes People Make After a Suspected Hack
The biggest mistake is reusing a slightly modified version of the compromised password instead of creating a fully unique one, followed closely by failing to check forwarding rules before declaring the account “fixed.” Both mistakes let attackers walk right back in.
Mistake 1: Assuming “changed password” means “problem solved.” If a hidden forwarding rule or an app with account access is still active, the attacker doesn’t need your new password at all.
Mistake 2: Reusing passwords across sites. This is the single biggest amplifier of breach damage. A leak at one minor, forgotten website becomes a serious problem the moment that same password unlocks your email or bank. Security professionals recommend unique passwords stored in a password manager precisely for this reason — a breach at one service then only affects that service.
Mistake 3: Ignoring a breach because “it’s just an old account.” Old, dormant accounts are exactly what attackers count on. If you signed up somewhere five years ago with the same email and password you still use, that old breach is still a live risk today.
Mistake 4: Skipping 2FA because it feels inconvenient. A few extra seconds at login is a small cost against the days or weeks it takes to recover a fully hijacked account.
Mistake 5: Confusing “HIBP shows green” with “I’m completely safe.” Have I Been Pwned only indexes publicly known breaches. Private or undisclosed leaks won’t show up. If you’re seeing suspicious activity, treat that as the stronger signal regardless of what a breach checker says.
A myth worth correcting: many people believe a hacked email always means immediate identity theft. In reality, what happens next depends heavily on password strength and reuse. A strong, unique password that gets exposed in encrypted form can sometimes sit unused for a long time before — if ever — it’s cracked. A weak, reused password, on the other hand, can be exploited within minutes. The breach is the same; the outcome isn’t.
Frequently Asked Questions
Is it safe to type my email into Have I Been Pwned? Yes. Checking an email address is exactly what the site is designed for. Just never enter your actual password into a breach checker — HIBP’s separate password-checking tool uses a technique called k-anonymity, which checks a partial hash so your full password is never transmitted.
How do I know if someone is reading my emails right now? Check your account’s “recent activity” or “last login” panel for unfamiliar devices or locations, and look for new forwarding rules. If you see either, change your password immediately and review connected apps.
Can my email be hacked even if I never clicked a suspicious link? Yes. Your email and password could have leaked from a completely unrelated company you signed up with years ago. Reused passwords are the most common way an unrelated breach turns into your own inbox getting accessed.
What’s the difference between a hacked email and a spoofed email? A hacked email means someone actually has access to your account. A spoofed email means someone faked the “From” field to look like it’s from you, without ever accessing your real account. Spoofing is harder to fully prevent but also doesn’t expose your actual inbox contents.
Should I delete my email account after a hack? Usually no. Deleting it can cut off recovery options for other accounts linked to it. Securing and keeping the account is almost always the better move, unless the address itself has become unusable due to ongoing abuse.
How often should I check if my email has been breached? Checking every few months, or right after hearing about a major breach involving a service you use, is a reasonable habit. Many password managers now do this continuously in the background, which removes the need to check manually at all.
Does changing my password fix everything? Not on its own. You also need to remove unauthorized forwarding rules, revoke unfamiliar app access, and confirm your recovery email/phone weren’t changed. Skipping these steps is the most common reason people get hacked again shortly after “fixing” it.
Conclusion
Checking if your email has been hacked takes minutes: run it through Have I Been Pwned, scan your recent login activity, and check for forwarding rules or sent messages you don’t recognize. If anything looks off, recover access, set a unique password, enable two-factor authentication, and clean out anything the attacker left behind.
Don’t wait for a second warning sign. Go check your email address right now at haveibeenpwned.com, and if it comes back exposed, work through the recovery steps above today — not next week.
Explore the topics that matter to you—our curated list keeps you learning with pure joy.
