Your primary email often controls password resets for many other services. Recover it before less important accounts, using a device and network you trust.

1. Open the provider yourself

Type the provider's known address or use its official app. Do not follow a recovery link from an unexpected message or search advertisement.

If you still have access, change the password to a unique, long password. If you are locked out, use the provider's official account-recovery flow and record any case number.

2. Review security changes

After regaining access, check:

  • recovery email addresses and phone numbers;
  • active sessions and trusted devices;
  • authenticator methods, security keys, and backup codes;
  • application passwords and connected applications;
  • inbox forwarding, filters, rules, delegates, and automatic replies.

Remove anything you do not recognise. Regenerate backup codes if a copy might have been exposed.

3. Secure the recovery routes

Protect the recovery email and mobile account with unique passwords and multi-factor authentication. A recovered inbox is still vulnerable if an attacker controls one of its reset routes.

4. Protect connected accounts

Prioritise banking, cloud storage, social platforms, shopping, and work accounts. Change any reused password, review sessions, and check whether the email address or recovery details changed.

5. Preserve a factual timeline

Record when you noticed the issue, provider alerts, unfamiliar sessions, security changes, and the steps you completed. Keep original screenshots private and create redacted copies before sharing.

6. Monitor after recovery

Watch for new password-reset messages, forwarding rules, unexpected sign-ins, and messages in sent or deleted folders. Continue monitoring connected financial and social accounts.

Recovery is not complete until the inbox, its recovery routes, active sessions, and important connected accounts are all checked.