Someone Is Sending Email From Your Address. Was It Hacked?
Matthew Leo · Published October 9, 2026 · Guides
A friend says you sent a strange invoice. Then delivery-failure notices start arriving for messages you never wrote. The first instinct is that someone broke into your email account.
That is possible, but it is not the only explanation. A scammer can also forge your address in the visible sender field without knowing your password. That is email spoofing.
The response depends on which problem you have, so check before assuming.
Signs your address may only be spoofed
According to Google’s Gmail guidance, spoofing can produce replies or bounce messages for mail that looks as though it came from you even though it was created outside Gmail.
Spoofing is more likely when:
- The suspicious messages do not appear in Sent, Trash or account activity.
- Your provider shows no unfamiliar sign-ins or connected devices.
- Your password, recovery email and recovery phone have not changed.
- The full message headers show that another mail server sent the message.
- You receive many delivery failures for random addresses you do not recognize.
The visible “From” line is not proof of where a message originated. Email systems use authentication results and message headers to determine whether the sending server was allowed to use a domain.
Signs someone may have entered the account
Treat the account as compromised if you find an unfamiliar login, a message in Sent that you did not write, a forwarding rule you did not create or changes to recovery information.
Other warning signs include password-reset messages for unrelated services, missing mail, contacts added without permission or security alerts that were marked as read.
A sophisticated intruder may delete sent messages and create a forwarding rule to copy future mail. A clean Sent folder is useful evidence, but it is not enough by itself.
Run the account checks in this order
- Open the provider directly. Use its normal app or type the website yourself. Do not sign in through a link in the suspicious message.
- Review recent sign-ins and devices. Look for locations, browsers and devices you do not recognize.
- Check Sent, Trash and forwarding rules. Remove rules, delegates or connected applications you did not add.
- Confirm recovery details. Make sure the recovery phone and email still belong to you.
- Change the password if anything is wrong. Use a new, unique password and sign out other sessions.
- Turn on two-step verification. An authenticator app, passkey or security key is preferable to relying only on a password.
The US Federal Trade Commission recommends changing the password, signing out all devices, enabling two-factor authentication and checking recovery information after an account takeover. It also recommends inspecting forwarding rules and sent or deleted messages.
If there is no evidence of access, changing the password will not stop someone from forging the visible address. It can still be a reasonable precaution if the password was reused or exposed elsewhere.
What personal Gmail or Outlook users can do
A personal mailbox owner cannot control every server on the internet. Google says it cannot stop outside systems from putting a Gmail address in a forged From field.
You can still limit the damage:
- Report the forged messages as spam or phishing.
- Tell contacts not to trust unexpected payment, password or document requests, especially if the scam targets people who know you.
- Ask a recipient to preserve the original message and full headers if the attack caused financial loss or impersonated your business.
- Check whether the address appeared in a known breach, while remembering that an exposed address alone does not prove mailbox access.
Mapletechie’s guide to checking whether an email address appeared in a breach explains what breach-search results can and cannot tell you.
Custom-domain owners have more control
If you own the domain after the @ symbol, configure SPF, DKIM and DMARC through your mail provider and DNS host.
- SPF lists the servers allowed to send mail for the domain.
- DKIM adds a cryptographic signature that receiving systems can verify.
- DMARC tells receivers how to handle messages that fail authentication and can send reports about abuse.
Google Workspace recommends using SPF with DKIM and DMARC. Every legitimate service that sends mail for the domain—such as a newsletter, billing platform or support system—must be accounted for.
Do not jump immediately to a strict reject policy without checking legitimate senders. Start with provider guidance and reporting, correct failures, then strengthen enforcement. A poorly configured policy can block your own receipts, newsletters or password-reset mail.
Warn people without causing more confusion
If the account was compromised, tell contacts plainly that someone accessed it and that they should ignore recent links or money requests. Use another trusted channel if possible.
If the address was only spoofed, say that messages were forged and that you found no evidence of mailbox access. Avoid claiming you were hacked when the evidence does not show that.
Canadians who lost money or disclosed sensitive information can report the incident through the Canadian Anti-Fraud Centre. Contact local police promptly when there is a financial loss, threat or identity crime.
The key distinction is simple: spoofing copies the address; account takeover gives someone access to the mailbox. Check the account first, then respond to the problem the evidence actually supports.
Tags: email spoofing, account takeover, Gmail, DMARC, phishing