This is a practical guide for owners and small teams. The goal is to contain the mailbox quickly, stop any ongoing abuse (like forwarding rules), and then tighten the baseline so it doesn't happen again.
First 15 minutes
Contain the account before you investigate
If someone can still access the mailbox, any "investigation" will be overwritten. Containment first, then clean-up.
Reset the password
Change the mailbox password (and admin password if applicable). Do it from a known-clean device.
Revoke sessions
Sign out of all sessions / revoke refresh tokens, then sign in again. This breaks stolen cookies/tokens.
Check forwarding + rules
Remove any unexpected inbox rules, forwarding addresses, delegates, or "send as" permissions.
Turn on MFA
Enable MFA immediately. Prefer an authenticator app. Make sure two admins have recovery access.
Same-day checklist
Clean up the ways attackers persist
Most repeat compromises come from one of these: forwarding/rules, third-party app access, device compromise, or weak recovery options.
Mailbox access + delegation
Remove unknown delegates/shared-mailbox access. Confirm who can send as/for the account.
Third-party apps
Remove suspicious connected apps or OAuth grants. Disable legacy/app passwords if supported.
Device hygiene
Run updates and malware scans on the main machines. If compromise is suspected, isolate and rebuild.
Recovery methods
Confirm recovery email/phone is correct and controlled. Remove anything you don't fully own.
Platform notes
Microsoft 365 and Google Workspace specifics to check
The exact menu names differ by provider, but the same persistence tricks show up everywhere. If you have an IT provider, send them this short list.
Sign-in history
Review recent sign-ins and "unfamiliar device" prompts. Look for impossible travel and repeated failed attempts.
Forwarding and transport
Confirm there are no hidden forwards, auto-replies, or routing rules redirecting mail to external addresses.
App access
Remove unknown connected apps and review any admin consented applications. Disable legacy protocols where possible.
Admin roles
Confirm no unexpected admin accounts exist. Check role assignments and make sure you have at least two MFA-protected admins.
Provider evidence
Build a short packet before escalating
If you need help from Microsoft, Google, a domain host, an IT provider, a bank, or an insurer, a small evidence packet saves time. It also reduces the chance that someone repeats a password reset while missing the persistence that caused the repeat problem.
Timeline
Record when the first symptom appeared, when access was reset, when sessions were revoked, and when forwarding/rules were checked.
Mailbox controls
Capture the state of forwarding, inbox rules, delegates, shared mailbox access, send-as permissions, and suspicious app access before and after cleanup.
Message evidence
Keep bounce messages, suspicious sent mail, invoice-change messages, payment requests, email headers, and affected recipient domains.
Domain evidence
Record MX, SPF, DKIM, and DMARC records, the DNS host, the registrar, and any third-party sender such as a website form, CRM, booking tool, or newsletter platform.
Common misses
Do not stop at a password reset
A password reset is important, but it is not the whole recovery. The quiet persistence points are what keep mailbox incidents alive after the obvious account access has been changed.
- Check both user-level forwarding and admin-level transport/routing rules.
- Review filters that move messages to obscure folders, mark mail as read, delete messages, or hide payment-related replies.
- Remove unknown connected apps or OAuth grants, especially if the account was used through mobile or webmail.
- Check whether any password reset emails from banking, payroll, domain, accounting, or website accounts were intercepted.
- Confirm the recovery phone and recovery email are still controlled by the business.
- Watch the account for new rule creation, external forwarding, or unusual sign-ins after the first cleanup.
Business impact
Protect customers and cashflow
Mailbox compromise often leads to invoice redirection, fake payment details, or damaged trust. Don't wait to check the obvious.
Check sent items
Look for unexpected emails, changed bank details, or "please pay this new account" messages.
Warn the right people
If a compromised mailbox emailed clients/suppliers, warn them not to trust payment changes from that thread.
Bank follow-up
If any payments may have been redirected, contact your bank quickly and document timelines.
Preserve evidence
Export a copy of key messages and capture timestamps/screenshots before you delete anything.
Prevent repeat
Set a safer baseline in under an hour
These are the durable basics that reduce the chance of another incident and make recovery faster if one happens.
SPF/DKIM/DMARC
Publish email authentication records so spoofing is harder. Start monitoring before enforcing.
Admin redundancy
Ensure at least two admin accounts exist, both with MFA, and both with secure recovery methods.
Password manager
Move shared credentials into a password manager and remove the "everyone knows the password" pattern.
Monthly review
Schedule a monthly check of forwarding rules, suspicious sign-ins, and recovery methods.
Next support path
Choose the next page based on what the cleanup finds
After containment, the next step depends on the evidence. A mailbox incident can turn into Microsoft 365 recovery, domain/DNS work, deliverability cleanup, or a broader IT handover problem. Pick the narrowest page that matches the remaining issue so the follow-up work stays focused.
Microsoft 365 support NZ
Use this when the evidence points to MFA recovery, tenant admin ownership, mailbox rules, shared mailboxes, sign-in history, or Microsoft/provider escalation.
Microsoft 365 setup Christchurch
Use this when the incident reveals missing setup basics: backup admin access, MFA methods, mail DNS records, Teams/OneDrive structure, or handover notes.
Email deliverability support NZ
Use this when the aftermath includes bounces, spam-folder placement, spoofing symptoms, SPF/DKIM/DMARC questions, or third-party senders.
DNS and routing support
Use this when cleanup involves MX/TXT records, nameservers, TTL, propagation, website forms, provider routing, or partial reachability evidence.
Email security and recovery reading path
Use the hub when you need the wider recovery order: contain access, remove persistence, build evidence, check business impact, then harden calmly.
Remote IT support NZ
Use this when the work needs a structured remote session, screenshots, provider evidence, and plain handover notes before a provider or onsite visit.
IT support Christchurch
Use this when the incident reveals device, Wi-Fi, local handover, office setup, or onsite troubleshooting work alongside the mailbox cleanup.
Maintenance calendar
Use this after cleanup to schedule recurring checks for forwarding rules, sign-ins, MFA methods, backup admins, DNS records, and recovery details.
NZ SME tech checklist
Use this to connect email recovery with the wider SME baseline: accounts, devices, domains, backups, websites, and handover notes.
Official references
Where to cross-check the advice
Use official guidance when the mailbox incident involves payment fraud, admin compromise, or a provider support ticket.
- Own Your Online: protect your business against email compromise.
- NCSC NZ: multi-factor authentication and verification.
- Google Workspace Admin Help: identify and secure compromised accounts.
- Microsoft Support: recover a hacked or compromised Microsoft account.
- Microsoft Learn: use mailbox audit evidence to investigate compromised accounts.
Related reading: Microsoft 365 SME checklist, DNS and email checklist, domains, DNS, and email reading path, and IT support and Microsoft 365 reading path. For service navigation, start with the services hub, the maintenance calendar, or the NZ SME tech checklist.
For context on how I write these checklists, see About John Finnerty and the broader set of project notes.