I think my mailbox has been compromised — what should I do? Print

  • 0

In short: If a mailbox sends messages you did not create, its password or a connected device or application may be compromised. Change the password immediately, update every legitimate device, check forwarding and filters, and contact support.

Contain the account

  1. Sign in to SiteWorx through a known address and change the mailbox password to a unique, strong value.
  2. Update the password on every legitimate phone, computer, website and mail application.
  3. Check mail aliases, forwarding addresses, groups, catch-all settings, autoresponders and filters for changes you do not recognise.
  4. Scan devices and websites that stored the old password.

If unexpected sending continues, contact support so we can help restrict the account while it is investigated.

Preserve useful evidence

Keep the approximate start time, examples of unexpected subjects, bounce messages, message IDs and sign-in alerts. Do not post passwords, private message content or two-factor codes in the ticket.

Check for wider impact

  • Change any other account that reused the same password.
  • Review recovery addresses and multi-factor authentication.
  • Check website contact forms or applications that send through the mailbox.
  • Tell us if customer or personal data may have been exposed so the incident can be assessed appropriately.

Delivery may recover gradually

Stopping the compromise does not instantly remove every provider reputation block. We may need to verify SPF, DKIM, DMARC and reverse DNS, clear queues and request delisting after the cause has been removed.

Further guidance


Was this answer helpful?

« Back