Getting locked out of email is uniquely stressful because email is how you reset everything else. The first hour matters: the right recovery path is usually still open, and the wrong one (guessing passwords, creating a lookalike address, arguing with a chatbot) can close it.

Do these steps in order before you assume the account is gone.

1. Stop Guessing the Password

Most providers lock you out after repeated failures, then treat more attempts as a takeover. Use the official "Forgot password" flow — not a third-party "unlock" site, and not a new account with a similar name.

If you still have a session open on another device or app (phone mail app, browser tab), don't sign out. That session is often the fastest way to change the password and review security events.

2. Use the Recovery Channels You Already Set

Check, in this order:

If the recovery phone number is an old SIM, try the number anyway — some providers still accept it for a short window, or let you verify via the authenticator you enrolled years ago.

Do This First

Write down the exact error ("account disabled", "unusual activity", "too many attempts") and the time it started. Support forms ask for this, and it tells you whether this is a password lock, a hijack, or a policy disable.

3. Provider-Specific Paths

Gmail / Google: Start at Google's account recovery page while signed out. Answer when you last remembered the password and which devices you used. If the account is disabled for ToS, recovery is a different form — password reset will not help.

Outlook / Microsoft: Use account.live.com / Microsoft account recovery, not your company's Microsoft 365 admin portal unless this is a work mailbox. Work accounts must go through the tenant admin; consumer @outlook.com / @hotmail.com use Microsoft's personal recovery.

Yahoo: Yahoo's recovery is slow if you never added a mobile number. Have the year you created the account and recent subjects you sent, if the form asks for them.

Don't use a VPN on the recovery attempt if you don't normally use one. A sudden country change is a hijack signal.

4. If You Suspect a Hijack

Assume the attacker still has a session:

If you have no remaining session, complete recovery first, then do the same cleanup immediately. A recovered account that still has a forward to the attacker is not recovered.

5. When Recovery Fails

You've hit a wall if:

At that point, stop cycling the same form. Document what you tried, gather proof of ownership you actually have (invoices, domain WHOIS if you own the domain, device receipts), and use the provider's identity-verification path if they offer one.

Work mail is usually faster: an admin can reset MFA and restore the mailbox. Personal mail is harder — there is no magic "pay to unlock" channel that is legitimate.

After You're Back In

Turn on 2FA (passkey or app, not SMS-only), add a current recovery phone and a recovery email you still control, and store backup codes somewhere that isn't the mailbox itself.

If the lockout was a takeover of a domain mailbox (Google Workspace, Microsoft 365, a host's webmail), the DNS and billing owner can still win even when the mailbox password is lost. That's a case we handle — don't hand the domain to a random "recovery service."