Quick answer: Do not click confirmation links you did not request, secure the mailbox, inspect forwarding and sessions, and report or ignore the signup through the service’s official site.
Unknown signup messages may be a typo, email bombing, or someone testing your address; they do not automatically mean your mailbox is hacked. Work through one test at a time so the result identifies the layer that is failing.
Why this happens
The best clue is the boundary of the problem: one file or every file, one device or several, one network or every network. Note when it began and any update, hardware change, permission prompt, or account alert that happened just before it.
- Another person mistyped their address.
- A bot is creating accounts to test deliverability.
- A flood of signups is hiding a real purchase or security alert.
- An attacker already has mailbox access and is creating services.
Fix it in the safest order
- Search the inbox for purchase, password, forwarding, and login alerts around the same time.
- Open mailbox security settings directly and review sessions, recovery methods, forwarding, filters, and app passwords.
- Change a reused password and enable strong MFA if any activity is unknown.
- Do not confirm the new account; contact the service through its official help route if removal is needed.
- Preserve headers and timestamps if the messages are part of harassment or fraud.
Repeat the same small test after each change. Keep a note of the original setting so you can restore it if the change does not help.
How to confirm the fix
The mailbox should show only trusted sessions and no unauthorized rule, purchase, or recovery change.
Common mistakes to avoid
- Do not click unsubscribe in an obviously fraudulent email.
- Do not delete hundreds of messages before checking for a hidden transaction alert.
- Do not take over or use the unknown account.
FAQ
Should I reset the password on the unknown account?
No. Avoid establishing control over an account you did not create; secure your email and use the service’s official report or removal process.
Should I reset or reinstall everything?
No. A factory reset destroys useful evidence and is rarely the first step. Back up important data, test a second file, account, network, or device, and use the narrowest reset that matches the confirmed cause.
Related PHWhy help
Browse more Cybersecurity guides or search PHWhy for the exact error message and device model.



