Getting locked out of email is uniquely stressful because email is how you reset everything else. The first hour matters: the right recovery path is usually still open, and the wrong one (guessing passwords, creating a lookalike address, arguing with a chatbot) can close it.
Do these steps in order before you assume the account is gone.
1. Stop Guessing the Password
Most providers lock you out after repeated failures, then treat more attempts as a takeover. Use the official "Forgot password" flow — not a third-party "unlock" site, and not a new account with a similar name.
If you still have a session open on another device or app (phone mail app, browser tab), don't sign out. That session is often the fastest way to change the password and review security events.
2. Use the Recovery Channels You Already Set
Check, in this order:
- Recovery email (including old work or school addresses)
- Recovery phone (SMS or voice)
- Authenticator app / hardware key
- Passkeys
If the recovery phone number is an old SIM, try the number anyway — some providers still accept it for a short window, or let you verify via the authenticator you enrolled years ago.
Write down the exact error ("account disabled", "unusual activity", "too many attempts") and the time it started. Support forms ask for this, and it tells you whether this is a password lock, a hijack, or a policy disable.
3. Provider-Specific Paths
Gmail / Google: Start at Google's account recovery page while signed out. Answer when you last remembered the password and which devices you used. If the account is disabled for ToS, recovery is a different form — password reset will not help.
Outlook / Microsoft: Use account.live.com / Microsoft account recovery, not your company's Microsoft 365 admin portal unless this is a work mailbox. Work accounts must go through the tenant admin; consumer @outlook.com / @hotmail.com use Microsoft's personal recovery.
Yahoo: Yahoo's recovery is slow if you never added a mobile number. Have the year you created the account and recent subjects you sent, if the form asks for them.
Don't use a VPN on the recovery attempt if you don't normally use one. A sudden country change is a hijack signal.
4. If You Suspect a Hijack
Assume the attacker still has a session:
- From any remaining logged-in device, change the password and sign out all other sessions
- Remove forwarding rules, delegates, and app passwords
- Check "last account activity" / recent security events
- Alert people who got mail from you that it wasn't you
If you have no remaining session, complete recovery first, then do the same cleanup immediately. A recovered account that still has a forward to the attacker is not recovered.
5. When Recovery Fails
You've hit a wall if:
- You never added a phone or recovery address
- The attacker changed those and waited out the rollback window
- The account is a work mailbox and you aren't an admin
- Google/Microsoft disabled it for abuse and won't reverse
At that point, stop cycling the same form. Document what you tried, gather proof of ownership you actually have (invoices, domain WHOIS if you own the domain, device receipts), and use the provider's identity-verification path if they offer one.
Work mail is usually faster: an admin can reset MFA and restore the mailbox. Personal mail is harder — there is no magic "pay to unlock" channel that is legitimate.
After You're Back In
Turn on 2FA (passkey or app, not SMS-only), add a current recovery phone and a recovery email you still control, and store backup codes somewhere that isn't the mailbox itself.
If the lockout was a takeover of a domain mailbox (Google Workspace, Microsoft 365, a host's webmail), the DNS and billing owner can still win even when the mailbox password is lost. That's a case we handle — don't hand the domain to a random "recovery service."