1. Check your email at haveibeenpwned.com
Go to haveibeenpwned.com, a reliable and free website that shows whether your email address has appeared in any known data breach. Enter your email and click the search button: if it shows up in any listing, it means that at some point that address (and possibly its password) was exposed and it's worth taking extra precautions.
2. Review recent activity and connected devices
In your email provider's security settings, look for the "account activity" or "devices where you're signed in" option. Go through the list and check that you recognize every device and location shown. If you see access from a place you haven't been to or a device that isn't yours, it's a clear sign that someone else has gotten into your account.
3. Look for sent emails you didn't write
Open your sent folder and go through the most recent messages. If you find emails you don't remember writing, especially if they're addressed to your contacts with strange links or attachments, it's very likely your account is compromised and being used to spread the attack.
4. Check for unauthorized automatic forwarding rules
Some attackers set up silent forwarding of your emails to another address so they can keep reading your messages even after you change your password. Go into your email settings and check the "forwarding", "filters" or "rules" sections to make sure there's no rule you didn't create yourself, and remove it if you find one.
5. If you confirm the hack
If after these checks it's clear your account has been compromised, act as soon as possible:
- Change the password immediately from a trusted device.
- Turn on two-step verification so that, even if someone knows your password, they can't get in without the code from your phone.
- Check connected devices and forwarding rules again to make sure the attacker's access has been shut down.