Illustrated article hero image for What to Do If Your Business Email Gets Hacked (NZ Checklist).

Technical article

What to Do If Your Business Email Gets Hacked (NZ Checklist)

A first-day checklist to contain a compromised mailbox, stop forwarding/rules, reset access, and prevent repeat incidents.

This is a practical guide for owners and small teams. The goal is to contain the mailbox quickly, stop any ongoing abuse (like forwarding rules), and then tighten the baseline so it doesn't happen again.

First 15 minutes

Contain the account before you investigate

If someone can still access the mailbox, any "investigation" will be overwritten. Containment first, then clean-up.

Reset the password

Change the mailbox password (and admin password if applicable). Do it from a known-clean device.

Revoke sessions

Sign out of all sessions / revoke refresh tokens, then sign in again. This breaks stolen cookies/tokens.

Check forwarding + rules

Remove any unexpected inbox rules, forwarding addresses, delegates, or "send as" permissions.

Turn on MFA

Enable MFA immediately. Prefer an authenticator app. Make sure two admins have recovery access.

Same-day checklist

Clean up the ways attackers persist

Most repeat compromises come from one of these: forwarding/rules, third-party app access, device compromise, or weak recovery options.

Mailbox access + delegation

Remove unknown delegates/shared-mailbox access. Confirm who can send as/for the account.

Third-party apps

Remove suspicious connected apps or OAuth grants. Disable legacy/app passwords if supported.

Device hygiene

Run updates and malware scans on the main machines. If compromise is suspected, isolate and rebuild.

Recovery methods

Confirm recovery email/phone is correct and controlled. Remove anything you don't fully own.

Platform notes

Microsoft 365 and Google Workspace specifics to check

The exact menu names differ by provider, but the same persistence tricks show up everywhere. If you have an IT provider, send them this short list.

Sign-in history

Review recent sign-ins and "unfamiliar device" prompts. Look for impossible travel and repeated failed attempts.

Forwarding and transport

Confirm there are no hidden forwards, auto-replies, or routing rules redirecting mail to external addresses.

App access

Remove unknown connected apps and review any admin consented applications. Disable legacy protocols where possible.

Admin roles

Confirm no unexpected admin accounts exist. Check role assignments and make sure you have at least two MFA-protected admins.

Provider evidence

Build a short packet before escalating

If you need help from Microsoft, Google, a domain host, an IT provider, a bank, or an insurer, a small evidence packet saves time. It also reduces the chance that someone repeats a password reset while missing the persistence that caused the repeat problem.

Timeline

Record when the first symptom appeared, when access was reset, when sessions were revoked, and when forwarding/rules were checked.

Mailbox controls

Capture the state of forwarding, inbox rules, delegates, shared mailbox access, send-as permissions, and suspicious app access before and after cleanup.

Message evidence

Keep bounce messages, suspicious sent mail, invoice-change messages, payment requests, email headers, and affected recipient domains.

Domain evidence

Record MX, SPF, DKIM, and DMARC records, the DNS host, the registrar, and any third-party sender such as a website form, CRM, booking tool, or newsletter platform.

Common misses

Do not stop at a password reset

A password reset is important, but it is not the whole recovery. The quiet persistence points are what keep mailbox incidents alive after the obvious account access has been changed.

Business impact

Protect customers and cashflow

Mailbox compromise often leads to invoice redirection, fake payment details, or damaged trust. Don't wait to check the obvious.

Check sent items

Look for unexpected emails, changed bank details, or "please pay this new account" messages.

Warn the right people

If a compromised mailbox emailed clients/suppliers, warn them not to trust payment changes from that thread.

Bank follow-up

If any payments may have been redirected, contact your bank quickly and document timelines.

Preserve evidence

Export a copy of key messages and capture timestamps/screenshots before you delete anything.

Prevent repeat

Set a safer baseline in under an hour

These are the durable basics that reduce the chance of another incident and make recovery faster if one happens.

SPF/DKIM/DMARC

Publish email authentication records so spoofing is harder. Start monitoring before enforcing.

Admin redundancy

Ensure at least two admin accounts exist, both with MFA, and both with secure recovery methods.

Password manager

Move shared credentials into a password manager and remove the "everyone knows the password" pattern.

Monthly review

Schedule a monthly check of forwarding rules, suspicious sign-ins, and recovery methods.

Next support path

Choose the next page based on what the cleanup finds

After containment, the next step depends on the evidence. A mailbox incident can turn into Microsoft 365 recovery, domain/DNS work, deliverability cleanup, or a broader IT handover problem. Pick the narrowest page that matches the remaining issue so the follow-up work stays focused.

Microsoft 365 support NZ

Use this when the evidence points to MFA recovery, tenant admin ownership, mailbox rules, shared mailboxes, sign-in history, or Microsoft/provider escalation.

Microsoft 365 setup Christchurch

Use this when the incident reveals missing setup basics: backup admin access, MFA methods, mail DNS records, Teams/OneDrive structure, or handover notes.

Email deliverability support NZ

Use this when the aftermath includes bounces, spam-folder placement, spoofing symptoms, SPF/DKIM/DMARC questions, or third-party senders.

DNS and routing support

Use this when cleanup involves MX/TXT records, nameservers, TTL, propagation, website forms, provider routing, or partial reachability evidence.

Remote IT support NZ

Use this when the work needs a structured remote session, screenshots, provider evidence, and plain handover notes before a provider or onsite visit.

IT support Christchurch

Use this when the incident reveals device, Wi-Fi, local handover, office setup, or onsite troubleshooting work alongside the mailbox cleanup.

Maintenance calendar

Use this after cleanup to schedule recurring checks for forwarding rules, sign-ins, MFA methods, backup admins, DNS records, and recovery details.

NZ SME tech checklist

Use this to connect email recovery with the wider SME baseline: accounts, devices, domains, backups, websites, and handover notes.

Official references

Where to cross-check the advice

Use official guidance when the mailbox incident involves payment fraud, admin compromise, or a provider support ticket.

Related reading: Microsoft 365 SME checklist, DNS and email checklist, domains, DNS, and email reading path, and IT support and Microsoft 365 reading path. For service navigation, start with the services hub, the maintenance calendar, or the NZ SME tech checklist.

For context on how I write these checklists, see About John Finnerty and the broader set of project notes.