PanicStation.org
uk Technology & digital loss

What to do if…
your email account starts sending automatic replies you did not set up

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat this as a likely account compromise. From a trusted device, disable the automatic reply, remove unknown rules and forwarding, change the password, and sign out other sessions.

Do not do these things

  • Don’t reply from the affected account to explain what happened unless you are sure it is secure again.
  • Don’t click links in security-alert emails; open the provider’s app or website directly.
  • Don’t only change the password and stop there; hidden forwarding, delegates, connected apps, or mailbox rules may still expose your mail.
  • Don’t delete everything in panic; account settings, recent alerts, and suspicious messages may help recovery or reporting.
  • Don’t reuse an old password from another account.

What to do now

  1. Use a safer setup first. If possible, use a different device you trust and a trusted connection, such as home Wi-Fi or mobile data. If you think the device itself may be infected, secure the email account from another device.
  2. Sign in directly to your email provider. Type the provider’s address yourself or use its official app. Go to the account security and mail settings areas.
  3. Turn off the automatic reply. Disable any vacation responder, out-of-office message, or automatic replies you did not set up.
  4. Remove suspicious rules and filters. Check mail rules, filters, blocked senders, safe senders, and settings that auto-reply, hide messages, delete messages, archive messages, or mark mail as read. Remove anything you did not create.
  5. Remove hidden access paths. Check forwarding, redirect settings, “send a copy to”, delegate access, mailbox sharing, connected accounts, app passwords, and third-party app access. Remove anything you do not recognise.
  6. Change the password and end other sessions. Set a new, unique password. Then use the provider’s option to sign out of other devices, sign out everywhere, or revoke unknown devices and apps.
  7. Turn on 2-step verification and check recovery details. Enable 2-step verification where available. Check your recovery email address and phone number, and remove anything you did not add.
  8. Check the accounts this email can unlock. Start with banking, shopping, cloud storage, social media, and work accounts. Change passwords on any account that reused the same password or shows a new-device alert, password reset, or purchase you do not recognise.
  9. Warn close contacts using another route. Text, call, or message from another trusted account: “My email may have been compromised. Please do not trust recent replies or links from it.”
  10. Report suspicious emails that may have started this. Forward suspicious emails to [email protected], then delete the original.
  11. Use the UK reporting route if money was lost, fraud happened, or you need a formal report.
    • If you are in England, Wales, or Northern Ireland, report cyber crime or fraud to Report Fraud at reportfraud.police.uk or call 0300 123 2040.
    • If you live in Scotland, or the crime happened there, contact Police Scotland on 101.
    • Use 999 only if there is immediate danger or a crime is happening now and urgent help is needed.

What can wait

  • You do not need to work out exactly how it happened before stopping the automatic replies and removing hidden access.
  • You do not need to clean up every old email now.
  • You do not need to decide now whether to replace devices unless there are signs the device itself is infected.
  • You do not need to message every contact before you have warned the people most likely to trust recent emails from you.

Important reassurance

This is a common pattern in account takeovers: attackers may add automatic replies, forwarding, connected apps, or rules so they can keep seeing mail or trick other people. Removing those settings, changing the password, and ending other sessions usually stops the immediate behaviour.

Scope note

These are first steps to stop ongoing harm and regain control. If this is a work, school, or organisation account, contact the IT or admin team because they may be able to see server-side rules, sign-in logs, and forwarding settings that you cannot.

Important note

This guide is general information for urgent first steps. It is not legal, financial, technical, or professional advice.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us