Local Tech Fix (626) 655-0020
All articles

You Got an Email From Your Own Address? How to Tell Spoofing From an Actual Hack

September 8, 2026

The email says it is from you. That fact, on its own, tells you almost nothing — anyone can type your address into the From line. What tells you something is your sign-in history, and it takes about a minute to read.

closeup of mail app icon on phone
Photo by Brett Jordan on Unsplash

It is one of the more unsettling things that happens to an ordinary email account. You open your inbox and there is a message sitting in it from your own address — your name, your address, sent to you — usually saying something ugly. Or the version that arrives second-hand: a friend, a customer or your sister-in-law calls to say they got a strange email from you with a link in it, and no, you did not send it.

The instinct in both cases is the same, and it is the wrong first move. People change their email password immediately, then spend the rest of the week jumpy. Changing the password is not harmful, but in the overwhelming majority of these cases it fixes nothing, because nothing was broken — and the panic it causes is out of all proportion to what actually happened. Meanwhile, in the small minority of cases where somebody genuinely is inside the account, changing the password alone is famously not enough either, for reasons we will get to.

So the useful question is not "am I hacked." It is "which of these two very different situations am I in," and there is a reliable order for answering it. This page is that order: four checks, cheapest and most decisive first, using pages that Google and Microsoft publish for exactly this purpose. Most people are finished after the third one, and most people finish it relieved.

The short answer, before you change a single password

An email arriving with your address in the From line is not evidence of anything. The From line is typed by whoever sends the message. It is not verified at the point of writing any more than the return address on a paper envelope is verified by the post office — a stranger can write your name and street on the back of an envelope and drop it in a mailbox, and the envelope will still be delivered. Email was designed in the same trusting spirit, and we have spent thirty years bolting checks onto the outside of it rather than fixing the inside.

What that means practically: the presence of your address proves nothing, and the absence of any other symptom proves quite a lot. If nobody is locked out, nothing has been sent from your Sent folder, no password-reset emails you did not ask for have arrived, and your sign-in history looks like your own life, then the odds are strongly that a spammer typed your address into a form field and pressed send. Nothing of yours was touched. There is no cleanup to do.

The three symptoms that genuinely move the needle, and that are worth checking before anything else, are these. One: you cannot sign in with a password you are certain of. Two: you received a real notice that your password, recovery phone or recovery email was changed, and you did not change it. Three: your sign-in history shows access you cannot account for. Any one of those and you should stop reading the diagnosis section and go straight to the cleanup, which we have written up separately in the email-hacked guide linked at the foot of this page — the order of operations there matters more than people expect.

Everything else — including a message from your own address, including contacts reporting junk in your name, including a threatening message that quotes a real password of yours — is ambiguous on its own. The rest of this page is how to disambiguate it.

Why an email can claim to be from you when it is not

There are two different "from" addresses in every email, which is the root of the whole mess. There is the address the sending server declares while it is delivering the message, and there is the address printed in the message itself — the one your mail app shows you. They do not have to match, they frequently do not match for perfectly legitimate reasons, and only the second one is on screen. A spammer who controls a server can put anything at all in that second one.

The industry response has been three overlapping checks, and it is worth knowing their names because you are about to see them: SPF, which publishes a list of the servers allowed to send mail for a domain; DKIM, which is a cryptographic signature the sending domain adds; and DMARC, which is the policy tying the two together and telling receiving servers what to do when they fail. Google describes the relationship plainly in its own sender guidance: "DMARC tells receiving servers what to do with your messages that don't pass SPF or DKIM," and to pass it, "the authenticating domain must be the same domain that appears in the message From: header."

That last clause is the important one for our purposes. DMARC is the mechanism that closes the "anyone can type your address" hole — but only for domains that have published a policy, and only where the receiving mail system enforces it. Enforcement got a lot better on 1 February 2024, when Google's bulk sender rules took effect. Google's own page states the threshold directly: "Starting February 1, 2024, email senders who send more than 5,000 messages per day to Gmail accounts must meet the requirements in this section" — and among those requirements is publishing a DMARC record. On the same page Google tells senders "Don't impersonate Gmail From: headers," noting that "Gmail will begin using a DMARC quarantine enforcement policy, and impersonating Gmail From: headers might impact your email delivery."

This is why the classic "spam literally from your own @gmail.com address, delivered to your Gmail inbox" is much rarer than it was five years ago, and why what people usually receive now is a near miss rather than a perfect forgery. Which leads directly to the first check.

Test one: look at the address, not the name — and do it on a computer

Nearly every one of these messages we are shown in the shop turns out to be display-name spoofing rather than address spoofing, and the reason people miss it is that their phone hid the evidence. Every email carries two separate pieces of sender identity: the display name, which is free text the sender chooses, and the actual address. Mail apps on phones show you the display name in large friendly letters and tuck the address away behind a tap, because on a small screen that is the sensible design. It is also exactly the wrong design for this particular question.

So the first check is to open the message on a computer, or tap the sender name on the phone to expand it, and read the address character by character. What people find, over and over, is that the display name says their own name or their own address, while the real address underneath is something like a random string at a domain they have never heard of. The message never claimed to be from them at all; it just wore their name as a costume.

Google treats this as a distinct category of abuse in its sender rules, listing "deceptive display name practices" and warning senders that "display names should never be used to attempt to deceive the recipient of the email." Two of the specific patterns it names are worth memorising because they show up constantly in the wild: "using the name of the recipient in the display name," and "using characters that imply the mail is part of threaded conversation, for example: User (2)." That second one is the trick behind messages that look like a reply to a conversation you were already having.

There is a business-flavoured variant of the same thing that is far more expensive, and it is the reason we mention this to every small-business client. Instead of your name, the costume is a supplier you actually use, and the address underneath is a lookalike domain — one character different, or a .co where the real one is .com — carrying an invoice with new bank details. Nothing about your systems has been broken into. Somebody simply learned who you buy from, and the whole attack lives in the gap between the display name and the address. Checking the address is not paranoia; it is the entire defence.

Test two: the Sent folder, and the reason it can lie

The second check is fast and mostly conclusive: open Sent, and look for messages you did not write. If your account is genuinely being used to send spam, the evidence is often sitting right there, and you can stop diagnosing and start cleaning up.

But an empty Sent folder is much weaker evidence than people take it for, and this is the point where a lot of well-meaning advice on the internet quietly misleads. Two things routinely keep intruder mail out of Sent. First, plenty of mail is not sent through your mailbox at all — if somebody has your address and nothing else, they are sending from their own server and your account has no record of anything because it was never involved. Second, and more seriously, someone who does have access will often delete the evidence as they go, or set up a filter that files and marks their traffic so it never appears anywhere you would look.

That second habit is worth understanding even if you never touch it, because it is the single most-skipped step in every hacked-account cleanup we do. An intruder who gets in for ten minutes will frequently create a mail rule — auto-forward everything to an outside address, or auto-delete anything containing the word "password" or the name of your bank — and then leave. Changing the password does not remove the rule. The rule survives the cleanup and keeps quietly copying your mail to them for months. So if the Sent folder is empty but the sign-in history in the next section is not clean, check the rules and filters before you relax. Our email-hacked guide walks through where they hide in Gmail, Outlook and the rest.

One more Sent-folder wrinkle that causes false alarms in the other direction: a wave of bounce messages from Mailer-Daemon or Postmaster about mail you never sent. This is the spillover from someone spoofing your address at scale — their forged messages hit dead addresses, and the bounces are addressed to the name in the From line, which is you. It is annoying, it can go on for days, and it is not a sign of compromise. It is the mail system doing exactly what it was told to do by a liar.

Test three, the one that actually settles it: your sign-in history

This is the check that ends the argument, it takes under a minute, and in our experience almost nobody knows it exists. Both Google and Microsoft keep a record of who has signed into your account and from where, and both publish it to you on a page built for precisely this moment.

On Gmail, on a computer, scroll to the very bottom right of the inbox and click Details. Google's help page describes what opens: you "can see your sign-in history, including the dates and times that your Gmail account was used," along with "the IP addresses which were used to access your account." Specifically, Google says, "you can see the last 10 IP addresses and approximate locations that accessed your Gmail account," and "if you got a warning about suspicious activity in your account, you might also see up to 3 additional IP addresses that have been labeled as suspicious." There is also a concurrent-session section that tells you whether you are signed in somewhere else right now, and an access-type column showing whether it was a browser, a device, or a mail program using POP or IMAP.

On a Microsoft account — Outlook.com, Hotmail, Live, or the account your Windows PC signs in with — the equivalent is the Recent activity page, reachable from the Security section of your account. Microsoft describes it as showing "when and where you've used your Microsoft account within the last 30 days," and you can expand any entry to see "the IP address of the device on which the activity occurred," a map, the device or operating system, and the browser or app. If Microsoft has flagged something, it appears in a separate Unusual activity section with "This was me" and "This wasn't me" buttons, and Microsoft is explicit that "these options are only in the Unusual activity section, so if you see them, we need your response."

Now the part that stops people frightening themselves, because it is the most common false alarm we get called about. A location in the list that is not where you live usually is not an intruder. Google warns that "if you use Gmail on a phone or tablet, your Internet service or mobile carrier's location may show up," that "this may be a location far from where you are," and that "as long as the name of the carrier matches yours, this isn't unusual." Microsoft says the same thing about its own page: "mobile phone services route activity through different locations, so it may look like you signed in from somewhere that's not your actual location." A customer in Palm Desert seeing a sign-in from Los Angeles or Phoenix is nearly always looking at their own phone, routed through their carrier. What is genuinely alarming is a different country, an access type you do not use, or a session running concurrently with yours.

And one honest limitation, because it cuts the other way. Microsoft states that "we don't show all account activity" — "you'll usually just see significant events that could impact your account security," and "if you use the same device in the same location several times in a row, you might only see the first time you signed in." A clean page is strong reassurance, not a certificate. If the clean page sits alongside a real symptom from the short-answer list above, believe the symptom.

Test four: open the headers and read the authentication result

If you want certainty about one specific message — and small-business owners often do, because the message is an invoice — the message carries its own verdict, and Gmail will show it to you. Open the message on a computer, click the three-dot menu next to Reply, and choose Show original. What opens is the raw message with a summary box at the top listing SPF, DKIM and DMARC and whether each passed.

Read it the way a bouncer reads an ID. A message that genuinely came from the domain it claims will normally show passes. A forgery of a domain that publishes a strict policy will usually not have been delivered to you at all — but if something slipped through, this is where it shows. Google also surfaces a lighter version of the same signal in the message list itself: its help page says "if you see a question mark next to the sender's name, the message isn't authenticated," and explains that "when an email isn't authenticated, that means Gmail doesn't know if the message is coming from the person who appears to be sending it. If you see this, be careful about replying or downloading any attachments." When a message is authenticated you will instead see a "Mailed by" header with the sending domain and a "Signed by" header.

Two caveats keep this from being a magic answer, and both come from Google's own page rather than from us being cautious. The first: "messages that aren't authenticated aren't necessarily spam. Sometimes authentication doesn't work for real organizations who send mail to big groups, like messages sent to mailing lists." A question mark on the newsletter from your HOA or your church is much more likely to be a badly configured mailing list than an attack. The second: forwarding breaks things. Google notes that where a forwarded message passes SPF or DKIM but the forwarding-chain record shows it previously failed, "Gmail treats the message as unauthenticated." If your mail is forwarded from an old work address or an alumni address, expect noise here.

For anything more than a quick look — and this is genuinely useful when you are trying to explain to a client why their invoice email is suspect — Google publishes a free header parser, the Admin Toolbox Messageheader tool, that takes a pasted header and lays out the delivery path and authentication results in a readable table. Every mail provider has a way to view the full header; Google maintains a list covering Outlook, Yahoo, AOL and the rest.

The blackmail version: "I recorded you through your webcam, and here is your password"

One specific flavour of this deserves its own section, because it frightens people badly and because the frightening part is deliberately designed to be the one true thing in an otherwise entirely false message. It arrives from your own address, or claims to. It says the sender installed software on your computer, watched you through the webcam while you were on adult websites, and will send the recording to your contacts within twenty-four or forty-eight hours unless you pay in Bitcoin. And to prove it, the message quotes one of your actual passwords.

The FTC's consumer alert on this — published in April 2020 and still on consumer.ftc.gov, because the scam has never gone away — is about as blunt as federal consumer advice gets. The emails, it says, "say they hacked into your computer and recorded you visiting adult websites. They threaten to distribute the video to your friends and family within hours, unless you pay into their Bitcoin account. Stop. Don't pay anything. Delete the message. It's a scam."

The password is the part worth explaining, because it is the reason people pay. The FTC explains where it comes from: "you may get one of these messages because your email was exposed in a recent data breach. The scammers may say they have access to your computer or webcam, or installed clever software to defeat you. That's all talk. But they may really know one of your old — or recent — passwords, and they include it in the message to prove it." In other words the password is real, and it proves a breach happened at some company you once had an account with. It does not prove anything at all about your computer, your webcam, or your email account. Nobody watched you. The list they bought had your address and a password on the same line, and a script pasted both into a template.

What to do is short. Do not pay, do not reply, and do not click anything in it. Then answer one question honestly: do you still use that password anywhere? If yes, that is the actual emergency in this email, and it has nothing to do with the threat — it means that password is circulating in credential-stuffing lists and every account still using it is exposed. The FTC's advice is to change it "on that account, and consider updating other passwords, too." If you do not recognise the password at all, it is an old one from a long-dead account and you can delete the message and get on with your day.

If you want to know which breach it came from, Have I Been Pwned will tell you which known breaches include your address, for free and without asking for your password. We have written separately about what a "your password appeared in a data leak" warning actually means, which is the same underlying situation arriving through a much politer channel.

"My friends are getting spam from me" — the version where your account is fine

The second-hand report is harder to dismiss than the message in your own inbox, because it comes from a person you trust and it feels like proof. It usually is not. There are three ordinary explanations that do not involve your account at all, and they cover most of what we see.

The first is plain spoofing, as above: someone typed your address into the From line of a message they sent to a list they bought, and your friend is one of the addresses on that list. Nothing of yours is involved. The second is more interesting and more common than people realise: the spammer has both your address and your friend's address because they were on the same list, or in the same stolen address book, and forging one to the other makes the message more convincing. That stolen address book is very often not yours — it belongs to a third person who has you both in their contacts and whose account or phone actually was compromised. When two or three people who all know each other start reporting spam "from" each other in the same week, that shared contact is usually the real story.

The third is the lookalike: your friend did not check the address either, and the message came from your name at a free mail account somebody opened this morning. This one you can actually do something about — ask the person who received it to look at the real address and send it to you. Thirty seconds of their time settles the question, and if it turns out to be a lookalike account trading on your name, that is worth knowing in its own right, particularly if you run a business.

When it is not one of these three, the tells are consistent and they line up with the checks above. Genuine account misuse tends to show up as a burst rather than a trickle, aimed at your real contact list rather than at strangers, in your Sent folder, and alongside an unfamiliar entry in the sign-in history. If your friend got one odd email and everything else looks normal, ask them to check the sender address before you tear the account apart.

If it really is your account, the order matters

Suppose the checks came back badly: an unfamiliar sign-in, or mail in Sent you did not write, or you are locked out. Then the situation is genuinely urgent, and it is urgent for a reason people underestimate. Your email is not one account among many — it is the reset mechanism for almost all of the others. Whoever holds the inbox can request a password reset at your bank, your Apple or Google account, your payroll portal, and collect the link themselves.

The full cleanup is a separate page and we would rather you followed it there than a summary here, because the order genuinely matters and the steps that get skipped are the ones that let the intruder back in. But three things are worth stating here because they are the ones most often done wrong. Scan the computer before you change the password, not after — if there is a password-stealer on the machine, the new password is captured the moment you type it, and you have handed over the new key while cutting the old one. Sign out of all sessions after the change, because a password change on its own does not always evict an existing logged-in session. And check the forwarding rules and filters, which survive everything else and are the single most common reason an account gets "re-hacked" a month later.

After that, close the back doors rather than just the front one: the recovery phone number and recovery email address, which an intruder will often have quietly changed to their own so they can reset the password back; connected apps and app passwords, which keep working after a password change by design; and then two-factor authentication or a passkey so the same thing cannot happen again with a stolen password alone.

And do the timeline honestly. If the intruder had the mailbox for a week, assume they read it. Anything in there worth acting on — a bank statement, a document with a Social Security number, a saved password sent to you years ago in plain text by some website — should be treated as seen by a stranger, and dealt with on that basis rather than hoped about.

The uncomfortable truth: you cannot stop someone spoofing your address — unless you own the domain

This is the part of the conversation nobody enjoys. If you use a free consumer address at gmail.com, outlook.com, yahoo.com or your internet provider's domain, there is no setting anywhere that stops a stranger typing that address into a From line. The address is not a possession you can lock. The protections that exist are published by the domain owner — Google, Microsoft, Yahoo — and they are already about as strict as they get, which is precisely why the forgeries you receive are usually near-misses rather than perfect copies. Changing your password does nothing to spoofing, because spoofing never involved your password.

What you can do is limited and worth doing anyway. Report the message as phishing rather than merely deleting it, which feeds the filter that keeps the next one out — in Gmail the option is in the three-dot menu on the message. Do not reply, not even to tell them off, because a reply confirms a live human reads that mailbox and moves your address up the value chain. And accept that a spoofing wave burns itself out; the list gets stale, the campaign moves on, and it stops on its own.

If you own a domain — anything@yourbusiness.com — the situation is completely different, and this is the one case where you have real control. Publishing SPF and DKIM correctly and then setting a DMARC policy that tells receiving servers to reject unauthenticated mail claiming to be from your domain is exactly the mechanism that makes forging your business address fail at the far end. Google recommends going further and turning on DMARC reporting, "so you can monitor email sent from your domain, or appears to have been sent from your domain," adding that the reports "help you identify senders that may be impersonating your domain." For a small business that invoices customers, that is not an abstract benefit; it is the difference between a supplier-impersonation invoice landing in your customer's inbox and never being delivered.

The catch is that the same records that stop forgery will also stop your own mail if something in your setup is sending as an address it is not authorised to send as — a website contact form, a quoting tool, a booking system configured years ago. That is the same fault that lands legitimate small-business mail in everyone's spam folder, and we have written the whole diagnosis up separately. Get the authentication right first, then tighten the policy. In that order, it is a good afternoon's work. In the other order, it is an outage.

What this looks like when we get the call

The calls come in two shapes and they need almost opposite responses, which is the whole reason for this page. The first is someone who has already changed three passwords, disconnected the router, and not slept, over a message that turns out to have been sent from a domain in another hemisphere with their name pasted into the display field. The work there is not technical. It is showing them the Details link at the bottom of the inbox, reading the last ten sign-ins together, and letting them see that their account was never touched. That is a ten-minute conversation and it is worth every minute of it.

The second shape is quieter and more serious: someone not especially worried, mentioning in passing that a customer said something odd about an invoice, or that they have been getting bounce messages, or that Outlook asked for the password again last week. Those are the ones where we find the forwarding rule. The rule is always the tell — it is the step that a password change does not undo, and it is why "I already changed my password" is not the reassurance people think it is.

If you are somewhere in between and not sure which one you are, the ordering in this page is the cheap way to find out: read the actual address, look in Sent, and then read the sign-in history. Three checks, a few minutes, no software to install and nothing to buy. If those come back clean, you can genuinely stop thinking about it. If any of them come back wrong, do not improvise — work the cleanup in order, because the order is the part that makes it stick.

And if you would rather have someone sit with you while you look, that is a normal reason to call us. We work across Los Angeles, Orange County, the Inland Empire and the Coachella Valley, remotely or in person, and this particular question is one where a second pair of eyes on the header is usually all that is needed.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →