Security Guides
Spam that appears to come from your own address is almost always a forged sender — check three places to know if you were hacked
Spam or extortion emails that show your own address as the sender are almost always a forged From field. Check your Sent folder, sign-in history and forwarding rules to tell forgery from a real account takeover.
For: anyone who received spam or an extortion email showing their own address as the sender and is worried they have been hacked. This article draws on warnings from Japan's IPA (Information-technology Promotion Agency) and JC3 (Japan Cybercrime Control Center). If you run your own domain and want to stop mail that impersonates it, see stopping spoofed mail from your own domain instead.
Why it looks like it came from you
The From field is something the sender fills in. At the moment of sending, nothing checks that the server actually sending the message matches the address written in From. Receiving services can check afterwards (SPF, DKIM and DMARC), but some messages still get through.
The attacker's server (the real sender)
Writes your address into From and sends
Your inbox
Shows: from you, to you → it looks like you emailed yourself
Your account
Never used → nothing in Sent, nothing in sign-in history
IPA describes cases where both sender and recipient were the recipient's own address, and says the likely aims are to get past spam filters and to make the recipient believe their mail account was hacked. In other words, "it came from my own address" is part of the act.
Takeover or forgery? Check three places
Just a forged sender (the usual case)
- Sent folder: neither that message nor anything else you didn't send
- Sign-in history: only your own devices and usual locations
- Forwarding and filter rules: only ones you created
- No friends asking about a strange email from you
Possibly a real takeover (act now)
- Your Sent folder holds messages you did not send
- Sign-in history shows countries, devices or times you don't recognise
- There is an unknown forwarding address, or rules that auto-delete or move incoming mail
- Friends say they got a suspicious email from you
The key point: a real takeover leaves traces inside the account. If someone logs in and sends mail, it shows up in Sent and in the sign-in history. Intruders also often plant forwarding or auto-delete rules quietly so you won't notice. If those three places are clean, your address was most likely just forged.
If you're flooded with 'undeliverable' bounces
Sometimes delivery-failure notices pour in for messages you never sent. That usually means someone is sending mass mail with your address forged as the sender, and the failed deliveries are bouncing back to you. Again, if those messages are not in your Sent folder, they did not come from your account.
What to do today
Don't reply, don't click, don't pay
Do not react to the threat. IPA and JC3 both advise ignoring these emails. Replying tells the sender the address is read, which brings more spam. Do not open links or attachments either.
Check the three places (five minutes)
In your mail service, look at (1) the Sent folder, (2) the sign-in history (usually in account settings, under names like "recent activity" or "sign-in activity"), and (3) forwarding settings and filter rules. If anything matches the right-hand column above, go to step 4.
If the email quotes a password you still use, change it today
These emails sometimes quote a password the recipient really used. IPA says it is thought to come from data leaked from some other service, and asks anyone still using it to change it. If you reuse that password elsewhere, change it everywhere. A password manager is the realistic way to stop reusing passwords.
If you find signs of a takeover: change the password AND sign out everywhere
If step 2 turned up something you don't recognise, don't just change the password — also sign out all other sessions (most services offer this) and delete any forwarding or filter rules you didn't create. A new password does not remove a forwarding rule that is already in place.
Turn on two-factor authentication
Make sure a known password alone is not enough to log in. Methods differ in strength; see which 2FA method is safest.
Ask for help if you're worried
If you actually paid, or the threats continue, contact your local police. In Japan, IPA's information security help desk takes these inquiries.
This site's view: 'it came from me' is not evidence of a break-in — it's stagecraft
What makes this trick work is that a single detail — "it came from my own address" — is enough to convince people they were hacked. Most of us naturally assume only we can use our own address.
But anyone can write the From field. If you really were breached, the evidence is not in the email's wording but inside your account — Sent, sign-in history, settings. So the place to check is your account, not the message. However specific the threat sounds, if your account is clean, it is only a threat.
There is one genuine clue, though: a password quoted in the email. It does not prove the sender knows anything about you; it is a notice that your password leaked somewhere in the past. Ignore the threat, take the notice, and change the password.
If you run your own domain
If you or your company run mail on your own domain, receiving mail that impersonates it may mean the domain lacks proper SPF, DKIM and DMARC. In that case you can stop it as the sender (the domain owner), not just as a recipient. How to read the headers and in what order to configure things is in stopping spoofed mail from your own domain; what the three mechanisms mean is in what are SPF, DKIM and DMARC.
Sources
- IPA (Information-technology Promotion Agency, Japan), information security help desk: warning on extortion spam threatening to spread sexual footage and demanding cryptocurrency (published 10 October 2018, updated 8 September 2021) — ipa.go.jp
- JC3 (Japan Cybercrime Control Center): extortion emails demanding cryptocurrency (Bitcoin) (21 April 2021) — jc3.or.jp
- IPA information security help desk — ipa.go.jp
Read next
- Fake warnings: "Your PC is infected" pop-ups and tech support scams
- For domain owners: Stopping spoofed mail from your own domain (SPF/DKIM/DMARC)
- Passwords: Are password managers safe? / Which 2FA method is safest
- Terms: What is phishing? / What are SPF, DKIM and DMARC?
FAQ
QWhy am I getting spam from my own email address?
In almost every case the sender (From) field has been forged. Email lets the sending side write whatever it likes in that field. Japan's IPA describes cases where both sender and recipient were the victim's own address, and says the likely aims are to slip past spam filters and to make the recipient believe their account was hacked.
QHow do I check whether my account was actually taken over?
Look in three places: (1) your Sent folder, for messages you did not send; (2) your provider's sign-in history (often called recent activity), for locations or devices you do not recognise; (3) your forwarding settings and filter rules, for anything you did not create. If all three are clean, your address was most likely just forged.
QThe email says it hacked my computer and recorded video of me. Is that true?
Both IPA and JC3 say the content of these emails is false and advise ignoring them. IPA says its help desk has not confirmed a single case of footage being released because someone refused to pay. Do not pay and do not reply.
QThe email contained my real password. What should I do?
If you still use that password, change it today. IPA says the passwords quoted are thought to come from data leaked from some other service. If you reuse it anywhere, change it everywhere and turn on two-factor authentication.
QI'm getting lots of 'undeliverable' bounces for emails I never sent.
Someone may be sending mass mail with your address forged as the sender, and the failed deliveries bounce back to you. If those messages are not in your Sent folder, they did not come from your account. Check the three places above and change your password for peace of mind.