What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
If you can still sign in, secure the device you’re using, change your email password to a unique one, and remove unfamiliar account settings. If you’re locked out, start with your email provider’s official recovery page—not a link in an unexpected message. Then check for attacker-added access, protect accounts that rely on this address, and warn contacts if suspicious messages were sent.
Signs your email account may be compromised
Possible warning signs include being unable to sign in, messages you didn’t write, unfamiliar sign-ins or security events, changes to your account information, missing mail, or forwarding and filtering settings you don’t recognize. Google also identifies unfamiliar Gmail labels, filters, or forwarding as settings to check; Microsoft’s guidance for work mailboxes calls out suspicious rules and unexplained changes to sent or deleted mail.
One symptom alone doesn’t prove an account was taken over. Check account activity through your provider’s own security settings, and don’t treat an email or phone call claiming to be support as proof. Microsoft says it will not ask for your password by email.
Recover access through your email provider
If you can’t sign in, use the provider’s official recovery route. Recovery steps and verification requirements differ by provider, and access is not guaranteed.
#1 Best Overall
- Google: Use Google Account recovery and answer the questions as best you can.
- Microsoft or Outlook.com: Start with Microsoft’s hacked or compromised account guidance, which directs users to its sign-in helper and available self-help or support options.
- Another provider: Go to the provider’s official help center and find its account recovery instructions. Don’t assume Google or Microsoft’s process applies to another service.
Use a device and network you trust when entering account details. Don’t give your password or verification codes to someone who contacts you unexpectedly. Official support routes still require you to meet the provider’s verification rules.
Secure the account after you regain access
Check the device before changing your password
If the device may contain malware, clean it up before entering a new password. Microsoft specifically recommends updating antivirus software and running a full scan before changing the password on a hacked account. The FTC also advises updating or installing reputable security software, scanning the device, and removing suspicious items. A scan is a useful step, not proof that a device is completely clean.
Rank #2
Set a new, unique password
Change the email password to one you haven’t used for another account. If you reused the old password elsewhere, change it on those services too—especially important accounts such as banking. The FTC recommends unique passwords for important accounts and notes that password-management software can help create and keep track of strong passwords.
Remove settings or access you don’t recognize
Review recent security activity and account information, then remove or correct unfamiliar entries. Check for:
Recommended Free Tools
- Recovery email addresses, phone numbers, and other security methods.
- Forwarding addresses, filters, labels, or rules you didn’t create.
- Connected accounts, automatic replies, or changes to your signature.
- Unexpected sent or deleted messages, which may show what the attacker did.
Google’s compromised-account guidance specifically calls out Gmail forwarding, labels, and filters. Microsoft’s consumer guidance includes connected accounts, forwarding, and automatic replies. For a Microsoft 365 work mailbox, suspicious inbox rules, external forwarding, contact changes, and sent or deleted items may require organization-level investigation; contact your IT or security team rather than relying only on consumer recovery steps.
Turn on multifactor authentication
Enable multifactor authentication (MFA), sometimes called two-step or two-factor verification, wherever your provider offers it. CISA recommends MFA for email and describes phishing-resistant MFA as stronger. The methods available vary by provider and account type. A FIDO2 security key can be an option if the provider supports it, but check compatibility first: a key is not an account-recovery tool and does not guarantee protection from every attack. Store recovery codes securely if your provider offers them.
Rank #4
Protect contacts and accounts tied to your email
If the account sent messages you didn’t write, tell contacts that the messages may be fraudulent. Ask them not to open unexpected links or act on unusual requests, and to verify anything important through a separate channel. The FTC recommends letting friends and family know when an email account has been hacked.
Your email address may be used to reset passwords on other services. Review important accounts that rely on it, look for unexpected changes or activity, and replace any reused passwords. This is a practical precaution because access to an inbox can expose password-reset messages; it is not a provider-specific recovery requirement.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →For messages claiming to come from Microsoft or Outlook.com, Microsoft Support says: “Microsoft will never ask for your password in email, so never reply to any email asking for any personal information, even if it claims to be from Outlook.com or Microsoft.” This warning is about Microsoft’s service; use your own provider’s official guidance for other accounts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If this is a Microsoft 365 work mailbox
A work mailbox managed by an organization may need administrator action in addition to the user’s password reset. Notify your IT or security team promptly so they can investigate mailbox rules and forwarding, sent and deleted mail, contact changes, and associated services. Microsoft’s Microsoft 365 compromised email account guidance is written for organizational response, not as a substitute for consumer support.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

