You got a password reset email you didn't request
A password reset email you didn't ask for is a smaller signal than a verification code, and a more ambiguous one. It can mean two very different things, and they need different responses.
Either someone entered your email address on that site's "forgot password" page, which requires knowing your address and nothing else. Or the email is fake, and the point is to get you to click.
Work out which before you do anything.
Is it real or is it phishing?
Check the sender's full address, not the display name. Then hover the link and read where it actually goes. A reset link should point to the service's own domain, not a lookalike with an extra word or a different ending.
The reliable move is to skip the question entirely: don't use the link. Go to the site by typing the address yourself, sign in normally, and see whether anything is wrong. A real reset request expires on its own if you ignore it.
Two things to notice. Real reset emails address the specific account and don't threaten consequences for inaction. Phishing versions tend to include urgency, telling you the account will be locked or deleted unless you act now. And a reset email for an account you don't have is phishing by definition.
If it's real
Someone typed your email address into that login page. That's all it proves, and by itself it isn't an emergency. But it's often the opening move.
Don't click the reset link. Ignoring it lets the token expire. Clicking it, even without completing the reset, sometimes invalidates your current session for no benefit.
Sign in directly and check the account. Look at recent login activity, the email address and phone number on file, and any connected apps. You're checking whether this was an isolated attempt or the visible part of something already underway.
Change the password anyway if you reused it. The reason someone tried a reset on this account is usually that they know your email address from a breach. If the password on this account also guards others, rotate it.
Turn on two-factor authentication if it isn't on. A reset attempt is a reasonable prompt to add the step that stops the next one.
Watch for the follow-up. The reset email is sometimes the setup: it arrives, then someone calls or emails claiming to be support, offering to help you "secure" the account. That's the actual attack. No support team needs a code or a password from you.
If it's phishing
Don't click, don't reply, don't unsubscribe. Report it as phishing in your mail client, which helps the filter and creates a record. Then delete it.
If you did click and enter a password, change that password immediately on the real site, and change it anywhere else you used it. Then check the account for forwarding rules, filters, or connected apps that were added.
When to treat it as urgent
Escalate if any of these apply:
- The reset email is for your email account itself. Email is the recovery root for everything else, so a reset attempt there is the highest-stakes version.
- You get several reset emails from different services in a short window. That's the same pattern as a burst of unrequested 2FA codes: one email address being run against a list.
- A reset email arrives alongside a call or text about the account. That combination is a coordinated attempt, not a coincidence.
- You get a notice that your email address or phone number was changed on an account. That means someone got in. Most services include a revert link in that notice, and it's time-limited.
Why they have your address
Email addresses are the easiest identifier to get. Breaches leak them in bulk, and data brokers and people-search sites publish them next to full names, phone numbers, and home addresses, compiled from public records and commercial sources and sold to anyone who pays.
That pairing is what makes the follow-up work. An attacker who knows your email address can trigger a reset. One who also knows your address, your phone number, and where you've lived can write a support message you'd believe, or answer a recovery question about you.
Delist finds those listings, files the removals, and re-checks them, because brokers commonly repost a profile after it comes down. Run a free scan to see where your details are published.
Frequently asked questions
Does an unrequested reset email mean I've been hacked?
No. It usually means someone typed your email address into a login page. That's worth noticing, not panicking about. It becomes serious if it repeats, targets your email account, or arrives with a call.
Should I click the link to see if it's real?
No. Sign in by typing the address yourself instead. An unused reset link expires harmlessly.
I clicked and entered my password. What now?
Change that password on the real site immediately, and change it anywhere you reused it. Then check the account for added forwarding rules, filters, or connected apps, since those persist after a password change.
Why do I keep getting reset emails for the same account?
Someone is repeatedly attempting it, either automated or trying to provoke you into responding. Turn on two-factor authentication, and check whether the service lets you restrict reset requests. Most rate-limit them on their own after a while.
Can someone reset my password without access to my email?
Not through the normal flow, which is why your email account is the thing to protect hardest. The exceptions are services with weak recovery, like security questions whose answers are findable, or SMS recovery vulnerable to a SIM swap.
Find out what data brokers know about you
Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.
Start your free scan →