Why an email can say it is from your own address
Email was designed in 1982 and anyone can write anything in the From line.
Updated 2026-09-26
A common panic: an email arrives that appears to be from your own address, often claiming your account has been hacked and demanding payment.
In almost every case, nothing has been hacked. Here is why it is possible and how to tell the difference.
The reason it works
Email was designed in 1982 for a network where everyone trusted everyone. The From line is simply text the sender writes. Nothing in the original design checks it, exactly as nothing stops you writing any return address on an envelope.
Modern defences — SPF, DKIM and DMARC — let a domain publish rules about who may send on its behalf, and most large providers check them. That is why spoofing is far less effective than it was. But plenty of domains have not set them up, and plenty of filters let a message through with a warning you never see.
The "I hacked your account" email
You receive a message from your own address, saying they have access and have recorded you, demanding payment in cryptocurrency. It may include a real password of yours.
It is a bluff. The From line is forged. The password came from a data breach at some site you used years ago. There is no footage.
What to do: delete it. Do not reply, do not pay. If the password shown is one you still use anywhere, change it there — that part is real. There is more on this in sextortion and a company leaked your data.
How to tell if you were actually hacked
Signs of a genuine compromise, none of which is "an email that looks like it came from me":
- Sent items you did not send. The real tell.
- A forwarding rule or filter you did not create. Attackers add these to read your mail
quietly, and it is the most commonly missed sign.
- Sign-ins from places you have not been, in your account's security or activity page.
- Password reset emails for other services that you did not request.
- A changed recovery email or phone number.
Check the first two now. It takes a minute and it is the honest answer to the worry.
Reading who really sent it
The display name is decoration. The address matters, and even that can be forged, so the real evidence is in the headers.
- On a phone, tap the sender name to expand the actual address.
- In Gmail, the three dots, then "Show original". Look for
SPF: PASSandDKIM: PASSin the
summary at the top. A FAIL or SOFTFAIL on a message claiming to be from a bank is conclusive.
- In Outlook, File, Properties, Internet headers.
You do not need to read the whole thing. Those two lines answer the question.
If it really was compromised
1. Change the password from a device you trust. 2. Sign out all other sessions. 3. Delete any forwarding rule or filter you did not create. Do not skip this — it is how they come back. 4. Check and fix the recovery email and phone number. 5. Turn on two-factor, or replace it if they changed it. 6. Tell your contacts, because they are about to be targeted using your name.
Check a password Free, and it needs no account.