How to Tell If Your Email Has Been Hacked (2026) — EmailLeaked
Guides

How to Tell If Your Email Has Been Hacked (2026)

Think your email was hacked? Here are the warning signs, how to check for free in seconds, and the exact steps to lock your account back down and stay safe.

On this page

The clearest signs your email has been hacked are messages you did not send, login or password-reset alerts you did not request, contacts reporting spam from you, and settings you did not change — like a new recovery phone or a forwarding rule. The fastest way to check is to see whether your email appears in a known data breach, because a leaked, reused password is how most accounts get taken over. If you spot the signs, change your password and turn on two-factor authentication straight away.

If you have a nagging feeling your email account has been broken into, this guide gives you a clear way to tell — the warning signs, a free way to check in seconds, and the exact order to lock things back down. No jargon.

Start with the fastest useful step: find out whether a password tied to your email has already leaked.

Check in two seconds: See if your email is in a known breach → — free, no signup, nothing stored.

What are the signs your email has been hacked?

Email hacks usually leave traces. If several of these are true, treat the account as compromised and act.

  • Sent messages you did not write. Check your Sent folder — attackers use hacked accounts to spam your contacts.
  • Login or password-reset alerts you did not request. A notification about a sign-in from an unfamiliar place or device is a strong signal.
  • Contacts asking about strange emails from you. Often the first sign, because the spam goes out to your address book.
  • Emails missing, or marked read when you never opened them. Attackers delete password-reset emails so you do not notice other accounts being taken over.
  • Your password suddenly does not work. If you are locked out and did not change it, someone else may have.
  • Changed settings. A new recovery email or phone number, a forwarding rule sending copies of your mail elsewhere, or new filters. These are how attackers keep access.
  • Your email shows up in a data breach. Not proof of a hack on its own, but if a password leaked, it is the most likely way in.

One sign might be a glitch. Several together mean act now.

How do I check if my email has been hacked?

Work through these in order. The first two take seconds and tell you the most.

1. Check if your email is in a known breach. A leaked, reused password is the number one cause of email hacks. Enter your address in a breach checker to see if it appears in any known breach and what was exposed. If a password was leaked, that is your likely entry point.

2. Review your account’s recent activity. Most email providers show recent sign-ins with the location and device. Anything you do not recognise is a red flag. Our step-by-step guides cover this for Gmail, Facebook and other major accounts.

3. Check your Sent, Trash and Archive folders. Messages you did not send, or deletions you did not make, confirm someone else has been active.

4. Check your recovery and forwarding settings. A recovery phone or email you do not recognise, or a forwarding rule you did not create, is the clearest proof of a takeover — and the thing you most need to undo.

What should I do first if my email is hacked?

Order matters. Do these steps in this sequence.

  1. Change your email password now — from a device you trust, and make it long and unique. This is the step that actually locks the attacker out.
  2. Turn on two-factor authentication. A stolen password becomes useless without the second step. Start with your email, since it is the key to resetting everything else. Use the 2FA and passkeys after a data breach playbook for order (password first, then the second factor).
  3. Undo the attacker’s changes. Reset your recovery email and phone, delete any forwarding rules and filters you did not create, and remove connected apps you do not recognise. Skipping this lets them back in even after a password change.
  4. Change that password everywhere you reused it. If the same password protected other accounts, they are exposed too. A password manager after a data breach keeps replacements unique so one hack never spreads.
  5. Warn your contacts if spam went out from your account, so they do not click anything.

For the complete version, follow our what to do after a data breach. Then work the password reuse change checklist and turn on 2FA and passkeys after a data breach — the steps are the same whether the trigger was a breach or a hack.

Can someone hack my email without my password?

Mostly they still need it — which is why leaked passwords are the central risk — but there are a few routes worth knowing.

  • Reused passwords from a breach. Your password leaks from one site, and because you used it elsewhere, attackers try it on your email. This is the most common route by far.
  • Phishing. A fake login page captures your password when you type it in. Always check the address bar before entering a password.
  • Malware. Software on your device copies saved passwords and active logins. If you suspect this, run a malware scan and sign out of all sessions.
  • Recovery-account takeover. If the account used to recover your email is itself weak or hacked, attackers can reset their way in.

Two-factor authentication stops most of these, because a stolen password alone is no longer enough. It is not absolute — sophisticated phishing pages and some malware can work around it — so pair it with the habits below, and prefer an authenticator app over SMS.

How do hackers get into email accounts in the first place?

Almost every route leads back to one thing: your password. Understanding that tells you exactly where to defend.

Across the breaches we track, about two in three (66%, as of 2026) exposed passwords — and in almost all of those, the password sat right next to the email address it belonged to. That pairing is the raw material for a hack. For scale, the FBI’s 2024 Internet Crime Report logged 64,882 personal data breach complaints in a single year, the third most-reported category.

The chain usually runs: a company you used gets breached, your email and password are exposed, that pair gets sold or bundled into a list, and attackers feed it into automated tools that try it across many sites — a technique called credential stuffing. If you reused that password, one of the accounts it unlocks is your email. You can browse the breaches we track to see what has been exposed and where.

This is why two habits remove most of the risk:

  • A unique password for every account, so one leak never cascades. A password manager makes this effortless.
  • Two-factor authentication on your email, so a leaked password is not enough on its own.

You can also check whether a specific password has leaked without ever sending the password itself.

How do I keep my email from being hacked again?

Once you have regained control, a short checklist keeps it that way.

  • Use a unique, long password for your email — and every other account. Let a password manager remember them.
  • Keep two-factor authentication on, ideally with an authenticator app rather than SMS.
  • Recheck for leaks periodically. New breaches surface constantly, so a clean result today is only a snapshot. Re-check after any service you use announces a breach.
  • Be sceptical of urgent emails and links. Attackers who have some of your real details send convincing fakes.
  • Keep your recovery details current and locked down, since that is the back door attackers aim for.

What’s the quick recap if your email is hacked?

  • Signs of a hacked email: messages you did not send, unrequested login or reset alerts, contacts getting spam from you, missing mail, and changed recovery or forwarding settings.
  • The fastest check is whether your email appears in a known breach — a leaked, reused password is the usual way in.
  • If hacked: change your password, turn on two-factor authentication, undo the attacker’s setting changes, and change that password everywhere you reused it.
  • Prevent a repeat with a unique password per account and two-factor authentication on your email.

Not sure where you stand right now? Check if your email is in a breach in a couple of seconds, then work down the steps above.

Frequently asked questions

How do I know if my email has been hacked?
The clearest signs are: sent messages you did not write, password-reset or login alerts you did not request, contacts saying they got spam from you, missing or read emails you never opened, and changed account settings like your recovery phone or forwarding address. The fastest first step is to check whether your email address appears in a known data breach, because a leaked password is the most common way accounts get hacked.
What is the first thing to do if my email is hacked?
Change your email password immediately, and make the new one long and unique. If you can still log in, do it from a device you trust. Then turn on two-factor authentication so a stolen password alone is not enough to get back in. After that, check your account's recovery settings and forwarding rules, because attackers often change those to keep access.
Can someone hack my email without my password?
Usually they need your password, which is why leaked passwords from data breaches are the main risk. But attackers can also get in through phishing (tricking you into entering your login on a fake page), malware that steals saved passwords, or by taking over an account you used the same password on. Two-factor authentication blocks most of these even if your password is known.
How can I check if my email was hacked for free?
Enter your email address in a breach checker to see if it appears in any known data breach. It is free, takes a couple of seconds, and tells you what data was exposed. If a password was leaked, that is the most likely route into your account — change it everywhere you used it.
Will changing my password stop a hacker?
It is the single most important step, but only if you also undo any changes the attacker made. Check your recovery email and phone number, any forwarding or filter rules, and connected apps — attackers set these up so they can get back in even after you change the password. Change the password, turn on two-factor authentication, and review those settings together.
How do hackers get into email accounts?
Most commonly through a password exposed in a data breach and then reused, phishing pages that capture your login, or malware that copies saved passwords from your device. The common thread is your password. Using a unique password for every account and turning on two-factor authentication removes almost all of these routes.
Should I be worried if my email is in a data breach but I see no hacking signs?
It is a warning, not proof you were hacked. It means a password or details linked to your email are circulating. If a password was exposed, change it everywhere before it gets used. If only your email address leaked, expect more spam and phishing rather than a break-in, but staying alert is still worth it.

Founder and editor of EmailLeaked. A software and web developer, he built the site's breach checker and its no-storage privacy model, and writes its plain-English guides for people who need a straight answer about a leak — not a data dump. LinkedIn

Our editorial standards →
Breach education

Read the data breach guide

Learn how breaches happen, how stolen data is used, and how to check your exposure.

Open the hub

Get monthly breach alerts — free

One email per month. Biggest breaches, what was exposed, what to do. No spam.

No spam · Unsubscribe anytime · Your email is never shared

Find out where you stand.

Check which breaches include your email — free, instant, never stored.

Check my email — free
No signup · Under 2 seconds · Never stored