PanicStation.org
uk Technology & digital loss

What to do if…
your email provider warns it will block outgoing mail due to unusual activity

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Stop sending for the moment. Sign in through your provider’s official app or website, not the alert link, then check for forwarding or rules you did not set, change your password, and sign out other sessions.

Do not do these things

  • Don’t keep retrying sends until it works; repeated attempts can make the block last longer or hide what changed.
  • Don’t click fix, unblock, or verify links in the warning email unless you reached the provider by typing the address yourself or using the official app.
  • Don’t change random settings before checking the basics: forwarding, inbox rules, recent sign-ins, connected apps, and recovery details.
  • Don’t ignore it if this email is used for password resets, banking, work, or shopping accounts.

What to do now

  1. Pause outgoing mail and get into the account safely.
    Close mail apps for a minute. Open the provider’s official app or type the provider’s web address yourself, then sign in.

  2. Use the provider’s own security or unblock flow from inside the account.
    If the account asks you to confirm it is you, complete that inside the official app or website. Do not use a link from the warning email unless you are certain it is genuine.

  3. Check for hidden mailbox changes before sending again.
    In settings, remove anything you did not set up:

    • Forwarding addresses
    • Inbox rules or filters that auto-forward, auto-delete, archive, or mark mail as read
    • Auto-replies you did not write
    • Delegated access or shared mailbox permissions you do not recognise
  4. Change the email password to a new unique one.
    Do this after checking forwarding and rules, or as soon as your provider’s security flow requires it. Do not reuse a password from another account.

  5. Sign out other sessions and remove unknown devices.
    Check recent sign-ins or security events. If the option exists, sign out of all devices, then sign back in only on your own devices.

  6. Revoke access that can keep sending mail.
    In account security or connected apps, remove:

    • Unknown apps, browser extensions, or mail clients
    • Mail access permissions you do not need
    • App passwords you do not recognise or no longer use
  7. Turn on two-step verification and check recovery details.
    Enable two-step verification if available. Confirm that your recovery email and phone number are yours, then save backup codes somewhere safe.

  8. Check the device you use for email.
    Update the device and browser or mail app. Run a scan with built-in or trusted security tools. If you think the device itself may be compromised, do the account recovery steps from another trusted device.

  9. If the warning email might be fake, report it without clicking it.
    Forward the suspicious email to [email protected]. Do not click links, open attachments, or reply to the message.

  10. If spam may have gone out, warn key contacts once the account is stable.
    A short message is enough: “Please ignore any unexpected emails or links from me recently. I have secured my account.”

  11. If this is a work or organisation email, tell your IT or admin team now.
    Ask them to check sign-in logs, sending spikes, forwarding rules, and whether other accounts may be affected.

  12. If money was lost or sensitive details were shared, use official reporting routes.
    Contact your bank or payment provider directly if money may be at risk. In England, Wales, or Northern Ireland, report cyber crime or fraud to Report Fraud. In Scotland, report fraud to Police Scotland by calling 101.

What can wait

  • You do not need to write a long explanation to everyone now.
  • You do not need to change every password at once; start with this email account and any important accounts that reset through it.
  • You do not need to fix SPF, DKIM, DMARC, or other mail-delivery settings unless your provider or IT admin says the account itself is already secure and those settings are relevant.
  • You do not need to decide whether to abandon the account unless the provider says recovery is not possible.

Important reassurance

A sending block or warning does not automatically mean you have lost the account permanently. Providers can flag accounts for suspicious sending, new sign-ins, reused passwords, forwarding changes, or attempted abuse. Working through the account-security checks calmly gives you the best chance of stopping misuse and restoring normal sending.

Scope note

These are first steps to regain control, reduce further misuse, and buy time. Later decisions may need help from your email provider, workplace IT team, cyber security support, bank, or official reporting routes.

Important note

This is general information, not legal, financial, technical, or professional advice. Use official provider channels and trusted UK reporting routes, especially if money, work systems, or sensitive information may be involved.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us