Why this matters
Data breaches expose millions of email addresses and passwords every year. If your details are in a breach, or someone has quietly accessed your mailbox, you want to know quickly so you can lock things down before it is used for fraud or invoice scams.
What you'll need
- Your email address
- Access to your email account settings
Step-by-step instructions
Step 1
Check for known breaches
Visit haveibeenpwned.com and enter your email address. It lists public breaches your address has appeared in. Change the password on any affected service, and anywhere you reused it.
Step 2
Look for messages you did not send
Check your Sent Items and Deleted Items for emails you do not recognise, particularly invoices or payment requests.
Step 3
Check inbox rules and forwarding
Attackers often create rules that hide or forward emails. In Outlook on the web, go to Settings, Mail, then Rules and Forwarding. Remove anything you did not create.
Step 4
Review recent sign-in activity
For Microsoft accounts, visit mysignins.microsoft.com and open "Recent activity". For Gmail, scroll to the bottom of your inbox and select "Details". Look for unfamiliar locations or devices.
Step 5
Check recovery details and MFA methods
Make sure the recovery phone, backup email and MFA methods are all yours.
Step 6
Secure the account
If anything looks wrong, change the password from a trusted device, sign out of all sessions, and turn on MFA.
Summary
A breach check plus a quick look at rules, forwarding and sign-ins will tell you whether your email is safe. If in doubt, follow our recovery guide.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.