How Do I Know if My Email Is Hacked? Check These Four Things
To find out whether your email is hacked, check four things: your recent sign-in activity (look for logins from places you’ve never been), your inbox rules and forwarding settings (attackers hide there), your Sent and Deleted folders (messages you didn’t write), and whether your password has already appeared in a data breach. Any one of those turning up something you don’t recognize means it’s time to act.
The old signs — friends getting spam from you, obvious lockouts — still happen, but a modern email compromise is usually quiet. The attacker’s goal is to sit in your mailbox unnoticed, read invoices and payment threads, and eventually redirect a real payment. That means the evidence lives in settings most people never open. Here’s where to look, in order.
1. Check your sign-in activity
Both Microsoft and Google keep a log of every sign-in. For a Microsoft account, open your account security page and view recent activity; for Microsoft 365 business accounts, an admin can see far more detail in Entra ID sign-in logs. What you’re looking for:
- Successful sign-ins from countries or cities you’ve never been to.
- "Impossible travel" — a sign-in from Tennessee at 9:00 a.m. and another from overseas twenty minutes later. No airline is that fast; two people are using the account.
- Unfamiliar devices, browsers, or apps — especially older protocols like IMAP or POP if you don’t use them.
One caution: VPNs and mobile carriers can make legitimate sign-ins look geographically odd. A single weird-looking failed attempt is normal internet background noise. A successful sign-in from somewhere you’ve never been is not.
2. Inbox rules — the attacker’s favorite hiding spot
This is the check most people skip and the one that matters most. When attackers take over a mailbox, they almost always create rules so you don’t notice them working:
- Rules that delete or move security alerts and password-reset emails before you see them.
- Rules that forward messages containing words like "invoice," "payment," or "wire" to an outside address.
- Rules that shove replies into obscure folders like RSS Feeds or Conversation History — folders nobody checks — so you don’t see customers responding to fraudulent messages sent in your name.
In Outlook, open Settings → Mail → Rules, and also check Settings → Mail → Forwarding. If you find a rule you didn’t create, your account is compromised — no further evidence needed.
3. Sent items and deleted items
Scan your Sent folder for messages you didn’t write — especially replies inside real conversations with customers or vendors, which is how payment fraud gets done. Check Deleted Items too; attackers often send from your account and then delete both the sent copy and the replies. An unusually empty Sent or Deleted folder can itself be a sign someone cleaned up after themselves.
4. Find out if your password is already exposed
Many email takeovers don’t involve any hacking of you at all — the password was leaked in some other company’s breach and reused. If you’ve ever used your email password on another site, assume it’s in circulation. We run a free cyber scan that checks whether your business domain’s credentials appear in known breach data — it takes a minute and the answer is frequently eye-opening.
Recovery steps for Microsoft 365
If any of the checks above turned up trouble, do these in order — and do them from a device you trust:
- Reset the password. Make it long, unique, and never reused.
- Revoke all active sessions. This is the step people miss. Attackers hold session tokens that keep working after a password change. In Microsoft 365, use "Sign out everywhere" or have an admin revoke sessions in Entra ID.
- Review MFA methods. Attackers register their own phone or authenticator app to keep a back door. Remove anything you don’t recognize, then re-enable MFA properly.
- Delete malicious inbox rules and forwarding found in step 2.
- Review connected apps. Check for third-party app permissions (OAuth grants) you didn’t approve — these survive password resets too.
- Have an admin check the audit log to see what was read, sent, and exported, and whether other mailboxes show the same sign-in patterns. One compromised account is often the first of several.
- Warn the right people. If fraudulent messages went to customers or your bookkeeper, a quick honest heads-up now prevents a wire transfer later.
Keeping it from happening again
The durable fixes are unglamorous: MFA on every account with no exceptions, unique passwords from a password manager, and — for businesses — conditional access policies that block sign-ins from countries you don’t operate in, plus monitoring that flags impossible travel automatically instead of waiting for you to go looking.
Equal Tech Solutions sets up and monitors exactly those protections as part of our managed cybersecurity services for businesses in Cleveland, Chattanooga, and across the Southeast US. If you’ve found something suspicious in your mailbox today — or you’d rather have a professional do this checkup — contact us and we’ll take a look.
