ServerNova · Docs
Emails

How To Check If Your Account Is Compromised

By Atticus Sondergaard·Updated July 30, 2026·4 min read

If something about your account feels off — a sign-in alert you don't recognize, emails you didn't send, a coworker asking why you sent them a strange link — trust that instinct. Catching a compromised account early is the difference between a quick reset and a real breach. This article covers the warning signs, what to do the moment you suspect something, and how to check your own account safely.

The Warning Signs

A compromised account usually leaves traces. You don't need all of these to be concerned — any single one is worth acting on.

In your sign-in activity

  • A sign-in alert or "new device" notification from a location, device, or time you don't recognize.

  • You're suddenly signed out, or your password no longer works even though you didn't change it.

  • MFA prompts you didn't start. If your phone asks you to approve a login and you weren't signing in, someone has your password.

  • New devices, apps, or connections listed in your account that you didn't add.

In your inbox

  • Sent mail you didn't write, or a Sent folder that's been emptied.

  • New forwarding or rules you didn't set up — especially ones that auto-forward, delete, or mark messages as read. This is how attackers quietly read your mail without you noticing.

  • Emails that are missing or already marked read when you never opened them.

From other people

  • Contacts tell you they received spam, odd links, or a payment request that looks like it came from you.

  • Coworkers report a phishing email appearing to be from your address.

An MFA approval prompt you didn't trigger is one of the clearest signs of all. It means someone already has your password and is trying to get past your second factor. Deny it and follow the steps below immediately.

What to Do Right Now

If you suspect your account is compromised, act in this order. Speed matters more than getting every step perfect.

  1. Change your password from a device you trust. Make it long and unique — don't reuse one you've used elsewhere.

  2. Sign out of all sessions. Microsoft 365 and Google both let you sign out everywhere from your account security settings. This kicks the attacker out of any active session.

  3. Contact the support team immediately. Tell us exactly what you saw. We'll revoke the attacker's access, check for hidden forwarding rules and connected apps, and confirm the account is clean — things you can't fully do on your own.

  4. Change the password anywhere you reused it. If the same password protected other accounts, assume those are exposed too.

Do not wait to "be sure." Report it now — even after hours, even on a hunch. A ten-minute head start is often the difference between a non-event and a serious breach. We would always rather investigate a false alarm than respond to a real one too late.

How to Check Your Recent Activity

You can review your own sign-in history without any special access. Look for logins from unfamiliar locations or devices.

Service

Where to look

Microsoft 365

Go to mysignins.microsoft.com and review Recent activity.

Google Workspace

Go to myaccount.google.com, open Security, and check Your devices and Recent security activity.

If you see a sign-in you can't explain, treat the account as compromised and follow the steps above.

Check for Hidden Inbox Rules

Creating a sneaky mail rule is one of the first things an attacker does, because it lets them keep reading your email even after you change your password. It's also one of the easiest signs to miss. In your mail settings, look under Rules and Forwarding for anything you didn't create — particularly rules that forward messages to an outside address, delete incoming mail, or move things to obscure folders.

If you find one, don't just delete it and move on. Tell the support team what it was doing — it tells us how the attacker was operating and what else to check.

What Happens After You Report It

Once you've reported a suspected compromise, here's what the support team handles on the back end:

  • Revoking active sessions and tokens, so a changed password can't be bypassed.

  • Reviewing connected apps and permissions for anything the attacker authorized to maintain access.

  • Auditing forwarding and rules across your mailbox.

  • Checking what was sent or accessed while the account was exposed, and notifying affected contacts if needed.

Your job is to report fast and answer a few questions. Ours is the cleanup.

Lower the Odds Next Time

Most account compromises trace back to a reused password or a phishing email. Three habits prevent the large majority of them:

  • Use MFA on every account that offers it, and never approve a prompt you didn't start.

  • Use a unique password for every account, ideally through a password manager so you don't have to remember them.

  • Report suspicious emails instead of engaging with them — most compromises start with a single click.

Set up sign-in alerts if your account offers them. Being notified the moment a new device logs in turns you into your own early-warning system — and early is exactly what matters.

Was this helpful?