Someone Is Sending Email From Your Address. Was It Hacked?

Matthew Leo · Published October 9, 2026 · Guides

A woman checks account activity on a laptop while speaking on the phone at a kitchen table.

A friend says you sent a strange invoice. Then delivery-failure notices start arriving for messages you never wrote. The first instinct is that someone broke into your email account.

That is possible, but it is not the only explanation. A scammer can also forge your address in the visible sender field without knowing your password. That is email spoofing.

The response depends on which problem you have, so check before assuming.

Signs your address may only be spoofed

According to Google’s Gmail guidance, spoofing can produce replies or bounce messages for mail that looks as though it came from you even though it was created outside Gmail.

Spoofing is more likely when:

The visible “From” line is not proof of where a message originated. Email systems use authentication results and message headers to determine whether the sending server was allowed to use a domain.

Signs someone may have entered the account

Treat the account as compromised if you find an unfamiliar login, a message in Sent that you did not write, a forwarding rule you did not create or changes to recovery information.

Other warning signs include password-reset messages for unrelated services, missing mail, contacts added without permission or security alerts that were marked as read.

A sophisticated intruder may delete sent messages and create a forwarding rule to copy future mail. A clean Sent folder is useful evidence, but it is not enough by itself.

Run the account checks in this order

  1. Open the provider directly. Use its normal app or type the website yourself. Do not sign in through a link in the suspicious message.
  2. Review recent sign-ins and devices. Look for locations, browsers and devices you do not recognize.
  3. Check Sent, Trash and forwarding rules. Remove rules, delegates or connected applications you did not add.
  4. Confirm recovery details. Make sure the recovery phone and email still belong to you.
  5. Change the password if anything is wrong. Use a new, unique password and sign out other sessions.
  6. Turn on two-step verification. An authenticator app, passkey or security key is preferable to relying only on a password.

The US Federal Trade Commission recommends changing the password, signing out all devices, enabling two-factor authentication and checking recovery information after an account takeover. It also recommends inspecting forwarding rules and sent or deleted messages.

If there is no evidence of access, changing the password will not stop someone from forging the visible address. It can still be a reasonable precaution if the password was reused or exposed elsewhere.

What personal Gmail or Outlook users can do

A personal mailbox owner cannot control every server on the internet. Google says it cannot stop outside systems from putting a Gmail address in a forged From field.

You can still limit the damage:

Mapletechie’s guide to checking whether an email address appeared in a breach explains what breach-search results can and cannot tell you.

Custom-domain owners have more control

If you own the domain after the @ symbol, configure SPF, DKIM and DMARC through your mail provider and DNS host.

Google Workspace recommends using SPF with DKIM and DMARC. Every legitimate service that sends mail for the domain—such as a newsletter, billing platform or support system—must be accounted for.

Do not jump immediately to a strict reject policy without checking legitimate senders. Start with provider guidance and reporting, correct failures, then strengthen enforcement. A poorly configured policy can block your own receipts, newsletters or password-reset mail.

Warn people without causing more confusion

If the account was compromised, tell contacts plainly that someone accessed it and that they should ignore recent links or money requests. Use another trusted channel if possible.

If the address was only spoofed, say that messages were forged and that you found no evidence of mailbox access. Avoid claiming you were hacked when the evidence does not show that.

Canadians who lost money or disclosed sensitive information can report the incident through the Canadian Anti-Fraud Centre. Contact local police promptly when there is a financial loss, threat or identity crime.

The key distinction is simple: spoofing copies the address; account takeover gives someone access to the mailbox. Check the account first, then respond to the problem the evidence actually supports.

Tags: email spoofing, account takeover, Gmail, DMARC, phishing

Read on Mapletechie