A compromised address is a security incident, not a spam problem, and the order matters. Regain control before migrating anything โ if someone else has access, every reset you trigger goes to them too. Then secure the account, audit what depends on it, move the critical accounts, and keep the old address alive and monitored rather than deleting it. Deleting it early is the mistake that turns a bad week into a permanent loss.
First: is it actually compromised?
Distinguish two situations, because they call for very different responses:
- Compromised โ someone else has or had access. Signs: sent mail you didn't write, unfamiliar forwarding rules or filters, login alerts from places you've never been, password changes you didn't make, contacts receiving spam from you.
- Just noisy โ enormous spam volume, but no evidence of access. That's a different article, and migrating is usually the wrong answer. Why
Only the first justifies the sequence below.
Step 1 โ Regain control, before anything else
- Change the password from a device you trust.
- Sign out all other sessions. Most providers offer this; a password change alone doesn't always evict an active session.
- Check for forwarding rules and filters you didn't create. This is the step people skip, and it's how attackers keep reading your mail after you've changed the password โ a quiet rule copying everything elsewhere.
- Check recovery settings. An attacker often changes the recovery address or phone so they can re-take the account.
- Turn on two-factor authentication, ideally an authenticator app or hardware key rather than SMS.
Every password reset you trigger sends a link to the compromised mailbox. If someone else still has access, you're handing them each of your other accounts in turn.
Step 2 โ Contain the damage
- Change passwords anywhere you reused that one, starting with financial accounts.
- Check for account changes elsewhere โ shipping addresses, payment methods, linked devices.
- Warn your contacts if mail was sent from your account.
- Check breach records to see whether this traces to a known incident. How
Step 3 โ Audit before you move
You cannot migrate what you can't enumerate. Password manager, a search of your mail archive for signup phrases, breach records, and your sign-in-with providers. Expect several times more accounts than you'd guess. The four methods
Step 4 โ Migrate in priority order
- Financial and identity first โ bank, payment providers, tax, government.
- Then anything holding payment details โ retailers with cards on file.
- Then the rest of what you actively use.
- Leave the long tail. It'll migrate itself as those services email you.
Give each account its own alias on the new setup rather than handing out one new address. Otherwise you've done a painful migration and rebuilt the same single point of failure. Setting the new one up properly
Step 5 โ Keep the old address alive
Do not delete it. Three reasons:
- Something you forgot will surface in eighteen months, and you'll want to receive it.
- Deleting frees the address for someone else to register at some providers โ which hands your account-recovery route to a stranger.
- Continued monitoring tells you whether the compromise is still being exploited.
Keep it secured, forwarded somewhere you'll notice, and effectively retired rather than closed.
What not to do
- Don't migrate before regaining control. The whole sequence depends on this.
- Don't delete the old address.
- Don't reuse any password from before the incident.
- Don't rush it once the account is secure. After step 1 the urgency drops sharply โ a careful migration over two weeks beats a panicked one over two days.