ScamGuard+ guide

Someone Has My Email Address: What Can They Do?

An email address alone is not the same as access to your inbox, but it can be used for targeted phishing, password-reset attempts and searches for information linked to you. Your email account is worth protecting particularly well.

An email address alone is not the same as access to your inbox, but it can be used for targeted phishing, password-reset attempts and searches for information linked to you. Your email account is worth protecting particularly well.

Use the checks below to slow the situation down, verify the claim through a separate route and avoid giving a suspicious contact more information or control.

What an email address can enable

A scammer can send targeted phishing, try password-reset flows on common services, search for public information linked to the address or combine it with leaked data from other incidents.

Protect the email account itself

Your inbox can be the recovery route for many other accounts. Use a strong unique password, enable multi-factor authentication and check recovery addresses, phone numbers and active sessions where your provider offers those controls.

Expect password-reset phishing

A real or fake password-reset message may arrive after someone learns your email address. Do not approve a reset you did not start. Open the affected service independently rather than using a link in an unexpected message.

Do not reuse passwords

If the email address was exposed together with an old password, change any account where that password is still used. Password reuse can turn one old breach into access to several current accounts.

If you think the inbox was accessed

Change the email password from a trusted device, review sign-in activity, remove unknown recovery methods or forwarding rules, and then secure important accounts that depend on that inbox for recovery.

Practical checklist

Quick checklist

  • Use a unique password for your email account
  • Enable multi-factor authentication
  • Do not approve password resets you did not request
  • Review recovery details and forwarding rules
  • Change reused passwords if an old credential was exposed
  • Secure dependent accounts if the inbox was accessed

Official and primary guidance

Scam techniques, platform features and reporting routes change. These sources were checked when this guide was updated: