What to do if…
your email account starts sending automatic replies you did not set up
Short answer
Treat the account as possibly compromised. From a trusted device, turn off the automatic reply, remove unknown rules and forwarding, change the password, and sign out of other sessions.
Do not do these things
- Don’t keep sending messages from the affected account to explain what happened; it may spread scam links or confirm the address is active.
- Don’t click links in security-warning emails; go to the provider by typing the address yourself or using the official app.
- Don’t stop after changing the password; unknown forwarding, filters, delegates, connected apps, or recovery details may still be in place.
- Don’t delete your inbox or sent messages immediately; they may help you see what was changed or what was sent.
- Don’t give anyone a verification code, password, or remote access because they claim they are helping with the account.
What to do now
- Use a trusted device and connection. If possible, use a device you believe is clean and a network you know. If you think your usual computer may have malware, update its security software and run a scan before relying on it for account recovery.
- Go to your provider directly. Open Gmail, Outlook, Yahoo, Apple Mail, or your provider’s official site or app. Do not use links from emails or pop-ups.
- Stop the automatic replies first.
- Turn off vacation responder, out of office, or automatic replies.
- Check rules and filters for anything you did not create.
- Remove rules that auto-reply, auto-forward, auto-delete, archive, hide, or move messages.
- Remove ways the attacker could stay connected.
- Check forwarding, redirect, send a copy to, delegates, mailbox sharing, connected accounts, and third-party app access where your provider shows them.
- Remove unknown forwarding addresses, unknown delegates, unknown connected accounts, unknown apps, and unknown devices.
- Change the account password and sign out other sessions.
- Create a new password that is unique to this email account.
- Use the provider’s option to sign out of other devices or revoke sessions and apps you do not recognize.
- Turn on multi-factor authentication and check recovery details.
- Turn on MFA or 2FA if it is available.
- Use an authenticator app or security key where available.
- Check the recovery email, recovery phone, backup codes, and security questions, and remove anything you did not add.
- Check what the account was used to unlock.
- Look for password reset emails, deleted security alerts, bank or payment alerts, shopping orders, and account-change notices.
- Prioritize banking, payment apps, shopping accounts, work accounts, school accounts, and any account where this email is the login or recovery address.
- Change passwords and turn on MFA for those accounts if they may have been reached through this email.
- Warn key people through another channel.
- Text or call close contacts, coworkers, or anyone likely to trust the automatic reply.
- Use a simple message such as: “My email may be compromised. Please do not trust recent automatic replies, links, or attachments from it.”
- Use official reporting routes if fraud or identity misuse is involved.
- If money was stolen, a financial account was accessed, or there was account takeover fraud, file an IC3 complaint.
- If a scammer used the account to contact people or trick someone, report it to the FTC.
- If personal information or accounts are being used in your name, use IdentityTheft.gov.
- If you cannot regain control, start official recovery.
- Use the provider’s official account recovery process.
- For a work or school account, contact IT or the account administrator from a separate channel.
- Move the most sensitive accounts to a secure email address only after you have protected those accounts from further password resets.
What can wait
- You do not need to identify exactly how the account was accessed right now.
- You do not need to notify every contact at once; start with people most likely to act on a scam link or attachment.
- You do not need to decide whether to replace devices immediately; first stop the automatic replies, remove access paths, and secure the password and MFA.
- You do not need to write a full incident history before taking the containment steps.
Important reassurance
Automatic replies you did not set up are a strong warning sign, but they are also a setting you can usually check and turn off. Removing unknown rules, forwarding, devices, apps, and recovery details often stops the immediate behavior while you work through recovery.
Scope note
These are first steps to reduce damage and regain control. Later decisions, especially for work, school, business, fraud, or identity theft situations, may need help from your email provider, IT administrator, bank, law enforcement portal, or a qualified security professional.
Important note
This guide is general information for urgent first steps. It is not legal, financial, technical, cybersecurity, or other professional advice.
Additional Resources
- Google — Secure a hacked or compromised Google Account
- Microsoft — How to recover a hacked or compromised Microsoft account
- Consumer Advice — How To Recover Your Hacked Email or Social Media Account
- Ic3 — Account Takeover Fraud (ATO)
- ReportFraud.ftc.gov — Report Fraud
- IdentityTheft.gov — Identitytheft
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.