Privacy & security

Was Your Email Hacked? The Evidence Inside Your Own Inbox

By TheTruthSpy Editor · Founder and editorPublished September 10, 20269 min read

How do you tell if your email was hacked rather than just acting strangely? Look for evidence the account keeps about itself. Check the sign-in history for devices and places that aren’t yours, messages in Sent you never wrote, and forwarding or filters you never set up. Any one of these is strong evidence. Spam “from you” on its own is not.

The good news is that Gmail, Outlook.com and Yahoo all record enough to settle the question in about fifteen minutes. The checks below go from the fastest and most conclusive to the slower ones. Do them from a device you trust, and open each settings page directly rather than through a link in an email.

How to tell if email was hacked: where the evidence is

Grid of six places to check when working out how to tell if email was hacked: sign-in history, Sent and Trash, forwarding, filters, security alerts and recovery details
The first three are the most conclusive. Two positive findings are enough to treat the account as compromised.

Most “was I hacked?” articles give a list of symptoms: slow mail, strange spam, friends asking questions. Symptoms are a reason to look, but they are not proof. The proof lives in six places inside the account. There’s the record of sign-ins, the Sent and Trash folders, forwarding settings, filters, the security alerts your provider sent you, and the recovery phone and email on file.

Yahoo’s own help page on hacked accounts lists four signs that line up with these. You stop receiving email. Your account sends spam to your contacts. Your activity history shows sign-ins you don’t recognise. Or your account info or mail settings changed without your knowledge. Each of those can be confirmed or ruled out in the places below.

1. Read your sign-in history

Gmail Activity on this account page showing a Firefox browser and an IMAP connection from another country alongside normal UK sign-ins
Gmail’s Details link shows the last 10 IP addresses that accessed your mail, with the access type. An IMAP connection you never set up is a strong sign.

This is the most conclusive check, so do it first. In Gmail on a computer, scroll to the bottom of your inbox and click Details in the bottom-right corner. The “Activity on this account” page shows whether Gmail is open elsewhere right now. It also shows the access type (browser, mobile, or a mail protocol such as POP or IMAP) and the last 10 IP addresses with approximate locations. If Google flagged something suspicious, up to three more addresses appear.

Read it carefully before you panic. Google itself notes that mobile networks and mail apps can show locations far from where you are. What matters is an access type you never use, or a browser you don’t own, especially at 3 a.m. For the full picture, open your Google Account and go to Security & sign-in. The device list there covers phones and apps as well as Gmail.

Microsoft account recent activity list showing a successful sign-in and security info added from another country among normal sign-ins
On Microsoft accounts, “Security info added” from a place you have never been is the strongest single sign.

For Outlook, Hotmail and Live accounts, Microsoft keeps a recent activity page at account.live.com/activity. It lists successful sign-ins and security challenges, with location and device. Pay most attention to two kinds of entry. A successful sign-in you don’t recognise means someone had your password. Security info added or changed means someone was preparing to lock you out. A run of unsuccessful sign-ins is different: someone is trying, but your password held. For Yahoo, the equivalent is Recent activity in your account info.

2. Check Sent and Trash for messages you never wrote

Sent folder mockup showing a message sent to 214 recipients and an invoice bank-details email at 3 a.m. that the owner did not write
Hijacked accounts leave copies in Sent. If friends received spam from you but nothing is here, your address was probably spoofed instead.

When an attacker uses your account to send spam or scams, the messages usually go through your provider, and a copy lands in your Sent folder. Look for anything sent at odd hours, to large numbers of people, or with subjects you’d never write. Watch especially for messages about invoices or changed bank details. Those are attempts to divert payments, and the recipient needs a phone call from you today.

Then open Trash. Careful attackers delete what they sent, and the replies from confused friends, and the “message undeliverable” bounces. Trash often catches what Sent doesn’t.

Scenario

Three friends say they got a strange link from you

You check Sent: nothing unusual. Trash: nothing. Sign-in history on Gmail’s Details page shows only your laptop and phone. One friend forwards the message, and the sender’s address looks right, but the “reply-to” is an address you’ve never seen.

Outcome: this is spoofing, not a hack. Someone forged your address in the “From” line without touching your account. There’s nothing to recover. Warn your contacts, and keep your password strong so it stays that way.

3. Look for forwarding, filters and delegates

This is the check most people skip, and it matters most. An attacker who wants to keep reading your mail after you change the password doesn’t need the password. They need one of these settings, and all three survive a password change.

Gmail Forwarding and POP/IMAP settings tab with forwarding turned on to an unknown address and set to delete Gmail's copy
Forwarding set to delete Gmail’s copy sends your mail to the attacker without it ever appearing in your inbox.

Forwarding. In Gmail, go to Settings › See all settings › Forwarding and POP/IMAP. If a forwarding address is set that you don’t recognise, that’s close to conclusive. Gmail shows a notice for the first week after forwarding is turned on, so an unexpected banner about forwarding is itself worth taking seriously. In Outlook.com the setting is under Settings › Mail › Forwarding. In Yahoo it’s under Mailboxes in the mail settings.

Delegates. Still in Gmail settings, open the Accounts tab and look at “Grant access to your account”. A delegate listed there can read, send and delete your email. Unless you added one on purpose, it should be empty.

Gmail filter list with a filter that deletes messages mentioning security, password or the bank, and another that deletes bounce messages
Filters that match “security”, “password”, your bank or mailer-daemon, with the action “Delete it”, exist to hide evidence.

Filters and rules. Open Gmail’s Filters and Blocked Addresses tab, or Outlook.com’s Settings › Mail › Rules. Look for anything that matches words like “security”, “password” or “sign-in”, or your bank or email provider, and then deletes, archives or forwards the message. A filter that deletes mail from “mailer-daemon” hides the bounce notices you’d get if your account were sending spam. Delete the filter, then search Trash and All Mail for what it caught.

Found one of these? Don’t just delete it and move on. Its existence means someone was in your account. Go straight to our guide to recovering and locking down a hacked email account and work through the whole lockdown in order.

4. Separate real security alerts from fake ones

Side-by-side comparison of a genuine Google new sign-in security alert and a phishing email with a 24-hour suspension threat and a lookalike sender
The safe test works for both: don’t click, open the account yourself, and see whether the same event is listed there.

Providers email you when something important changes, such as a new sign-in, a password change or a new recovery phone. A genuine alert you didn’t cause is strong evidence. But fake alerts are among the most common phishing emails, precisely because they cause the panic that makes people click.

Don’t try to judge the email itself. Close it, open your account the way you normally would, and look at the security activity. If the event is listed there, the alert was real. If there is no matching event, the email was the attack. Deadlines (“suspended in 24 hours”), threats to close the account, and requests for your password are the marks of a fake. Google, Microsoft and Yahoo don’t ask for your password by email.

5. Check the recovery phone and email

Last, open your account’s security page and read the recovery phone number and recovery email. An attacker who plans to keep the account swaps these first. Then, when you finally change the password, they reset it again from their own phone. A number or address you don’t recognise, or yours with one digit changed, is conclusive.

On Microsoft accounts, a newly added security method also shows up in recent activity. On Google accounts, changes to recovery details appear in recent security activity with a date and device.

Hacked, spoofed or breached: which one is it?

Three cards contrasting a hacked email account, a spoofed email address and an address found in a data breach, with a test and fix for each
Three problems that feel similar and need different responses.

Three situations get called “hacked”, and they need different responses:

  • Hacked: someone signed in. The evidence is in the sign-in history, Sent folder or settings. You need to recover and lock down.
  • Spoofed: someone forged your address in the From line of their own mail. Your account is untouched. Sent is clean, the sign-in history is normal, and you may get a flood of bounce messages for mail you never sent. There’s nothing to recover.
  • Breached: your address, and perhaps a password, leaked from another website. Your inbox may be fine, but any password you reused from that site is now in circulation.
Breach checker results page showing an email address found in three data breaches, with notes on what the result does and does not show
A breach result shows where your details leaked. It does not mean your inbox was entered.

To check for breaches, Have I Been Pwned is the best-known free service. Enter your address and it lists the known breaches that included it and what kinds of data leaked. It never displays passwords. It also says openly that it holds only a subset of all breached records, so a clean result isn’t a guarantee. If a breach included passwords and you used that password on your email, change it now, even if nothing else looks wrong. Our guide to passwords you can actually remember shows how to replace it with one that is long and unique.

What these checks cannot tell you

These checks are good at catching someone who signed in to your account. They have limits:

  • They won’t show what was read. Sign-in history shows access, not which messages were opened. If someone was in, assume they read anything they wanted.
  • History is short. Gmail’s Details page shows the last 10 addresses. An intrusion weeks ago may have scrolled off.
  • They can’t see your device. If malware or a monitoring app on your phone or computer reads your mail on the device itself, the provider sees your own device signing in. Nothing looks wrong. That needs a check of the device, not the account.
  • Location is approximate. A VPN, mobile network or mail app can make your own sign-ins look foreign, and an attacker’s look local.

If the account checks come back clean but you still have a specific reason for concern, such as someone quoting your private emails back to you, the device is the next place to look.

How this page was put together

Each check was compared in September 2026 against Google’s Gmail and Account Help pages (recent activity, forwarding and delegation), Microsoft’s Outlook.com security guidance and recent activity page, Yahoo Help’s page on recognising a hacked account, and Have I Been Pwned’s own FAQ. Menu names are quoted as those pages give them. Providers rename settings often, so search the settings page if a label has moved.

The scenarios and screens are illustrations, not real accounts, and the breach names in the example are placeholders. You can read how we check and correct our guides.

Common questions

Can someone access my email without me knowing?

Yes, for a while. Forwarding, filters and delegates are designed to work silently, which is why checking them matters more than waiting for symptoms. Sign-in history and security alerts are what usually give it away.

My friends got spam from my email address. Was I hacked?

Not necessarily. If the messages are in your Sent folder, yes. If Sent is clean and your sign-in history is normal, your address was most likely spoofed, meaning forged by someone who never had access to your account.

How can I see who has logged into my Gmail?

Click Details at the bottom right of Gmail on a computer to see recent access by type, IP address and approximate location. For every device signed in to your Google Account, go to Security & sign-in and open your devices list.

Does being in a data breach mean my email was hacked?

No. It means your address, and possibly a password, leaked from another service. It becomes a risk to your email if you used the same password there. Change any reused password.

Will changing my password stop a hacker?

Not on its own. Forwarding addresses, filters, delegates, app passwords and a swapped recovery phone all survive a password change. Remove those as well, and sign out other sessions.

Why do I get “undeliverable” messages for emails I never sent?

Usually because someone spoofed your address and some of their spam bounced back to you. Check your Sent folder. If those messages aren’t there, your account wasn’t used to send them.

Using a monitoring app for this? TheTruthSpy is a free parental control app for Android that stays visible on the child's phone. If it fits your family, see the Facebook & Messenger monitoring feature.

Free parental control app for Android

GPS tracking, screen time limits, web filtering, SMS and call monitoring — visible on your child's phone. Pair a phone in about ten minutes.

Android · Free to set up · Visible on your child's phone