Open the account through a trusted route
Use the provider’s official app or type its known web address yourself. Do not begin from an unexpected security-alert link. If you suspect the device is infected or remotely controlled, switch to a trusted device before changing account settings.
Replace reused or exposed passwords
Use a password manager to create and store a unique password. NIST says the most important property of a password is length and recommends at least 15 characters when you must create one yourself.[1] Never reuse the new email password elsewhere.
Enable the strongest practical MFA option
Turn on multifactor authentication in the account’s security settings. MFA adds a second barrier when a password is compromised; NIST notes that some methods are more resistant to phishing than SMS or one-time codes.[2] Choose a phishing-resistant option if your provider offers one and you can use it reliably.
Secure recovery methods and backup codes
Confirm that every recovery email address and phone number belongs to you. Remove old or unfamiliar options. Generate new backup codes if prior codes may have been exposed, then store them somewhere separate from the email account.
Review active sessions and connected apps
Sign out devices or locations you do not recognize. Review third-party apps that can read mail, manage contacts, or access account data, and remove access you no longer need. Recheck the list after changing the password.
Check forwarding, filters, and delegates
An intruder may create a rule that forwards messages, hides security notices, or deletes replies. Review automatic forwarding addresses, inbox rules, filters, delegates, and send-as settings. Remove anything you did not configure and save screenshots if you need evidence.
Protect the accounts that email can reset
Prioritize banking, shopping, cloud storage, social media, and password-manager accounts. Change any reused credentials and enable MFA. If the compromise began with a deceptive message, the FTC advises contacting the company through a phone number or website you know is real—not through the message.[3]
Menu names differ by provider. Follow the current instructions in the official account settings and contact the provider’s support or fraud team if you cannot regain control.
