Skip to content

Home Topics Email Security Management Mailbox account takeover

Email Security Management · Mailbox account takeover

Email account takeover FAQ: 4 questions answered

Short answer

Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.

Account takeover (ATO) is unauthorized access to a legitimate mailbox, typically via phished credentials, password reuse, or OAuth consent phishing.

What are signs of a compromised email account?

Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.

Why does email account takeover matter for deliverability?

A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.

What is the first step to get started with email account takeover?

Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.

What is the most common email account takeover mistake?

SMS-based MFA for high-value accounts.

Keep reading on Mailbox account takeover