CYBER WELFARE

Protect your Digital Privacy

Signs of messages you did not send: how to spot them and what to do

Usually you are not the one who notices. Someone else tells you: a friend asking “did you really send me that link?”, a colleague replying to an email you do not remember writing, a relative who has received a request for money with your name at the top.

This post brings together the signs of messages you did not send: the traces showing that your email, your messaging account or your social media profile may be in someone else’s hands and used to write to your contacts. For each sign you will find what it means, where you can see it and what to do when you come across it. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise).

It is the diagnostic deep dive on the recommendation on checking messages sent in your name.

What message indicators of compromise are

An indicator of compromise is an observable trace suggesting that something did not go the way it should have.

When it comes to messages sent in your name, there are four terms worth knowing:

  • linked device: a computer, a browser or a tablet on which your messaging or email account stays open, even when you are not using it;
  • verification code: the short number a service sends you by text message or notification to confirm that it really is you registering or linking the account;
  • forwarding rule: an email setting that automatically copies or moves certain messages, for example to another address or to the bin;
  • spoofing (sender forgery): a message that looks as though it came from you, but was actually sent from a different address or a different account.

A sign is not proof. It is a prompt to check: it may have a harmless explanation — a message sent in a hurry and forgotten, an app you authorised to post on your behalf — or it may mean that someone is using your account. The first question is always the same: did the message leave your account, or did someone simply borrow your name?

Why they matter more when your own account is doing the writing

A suspicious message from a stranger is relatively easy to spot. A suspicious message from someone you trust is not.

Whoever is using your account is not only after your data: they are after the trust your contacts place in you. A link that arrives from your number gets opened; a request for help signed with your name gets taken seriously.

And every contact who falls for it can become the starting point for the next round: the sooner you notice the sign, the shorter the chain stays. What the people receiving those messages risk is explained in the post on contacts scammed in your name.

Technical indicators

These are the ones services record and make available in their own security settings.

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
Messages in your “sent” folder that you do not rememberEmails you did not write have left your email accountIt is the most direct confirmation that the account was used, not just imitated“Sent items” folder, sometimes the bin as wellNote down recipients and times, change the password, sign out of all sessions
Unknown linked devices on your messaging appA browser or computer you do not recognise has access to your chatsFrom there, messages can be read and sent in real time, even while you are using your phone“Linked devices” section of the appUnlink the device, then turn on the app’s two-step verification
Forwarding rules or filters you did not createYour email is copied elsewhere, or some messages end up in the bin on their ownIt is used to read your email in secret or to hide the replies to the fake messagesEmail settings: forwarding, filters, rulesDelete the rule, change the password, check the active sessions
Apps or services authorised to send on your behalfAn outside service has permission to write or post in your nameIt can send messages without knowing your passwordConnected apps or permissions section of the accountRevoke any permissions you do not recognise
Recent sign-ins from unusual devices or placesThe account was opened from a context that is not yoursIt is often the step that comes before the messages are sentSign-in history, security notificationsCheck whether it was you; if not, change the password and sign out everywhere

How linked devices work, and which tools the apps offer, is explained in the post on linked devices on messaging apps. For outside apps authorised on social media profiles, there is the deep dive on the signs of suspicious connected apps.

Signs you can observe yourself

These do not require you to open any settings panel: you notice them in everyday use, or by talking to people.

SignalWhat it meansWhy it mattersHow you noticeWhat to do
Contacts telling you about strange messages from youSomeone has received links, requests or attachments with your name on themIt is the most common sign, and often the firstThey tell you in person, on the phone or in a chatAsk for a screenshot showing the sender and the time: it helps work out where the message came from
Replies to messages you never wrotePeople are answering something that carries your nameIn a chat it almost always means a real message was sent; in email it may also be down to spoofingReplies such as “ok, thanks”, “it won’t open” or “how much do you need?” arrive by email or in your chatsCheck your sent items, the bin and the forwarding rules; then secure the account
Verification codes you did not requestSomeone is trying to register or link your account on another deviceWhoever gets hold of that code can take control of the accountText messages or notifications with a code you did not ask forDo not share it with anyone, not even with a contact who asks you for it
Requests to “pass on” a code that arrived by mistakeA contact asks you for the code you have just receivedIt is the most widespread way to steal a messaging account, often using a contact who has already been compromisedA message from a friend, sometimes an urgent oneDo not send it; call that contact through a different channel to check
Being suddenly signed out of your messaging appYour account appears to be active on another phoneThe account may have been registered elsewhereThe app asks you to verify your number againReactivate the account with your own number and turn on two-step verification straight away
Chats read, archived or deleted that you do not rememberSomeone has used the account while trying not to leave tracesWhoever writes in your name often deletes what they sentConversations already marked as read, or missingCheck the linked devices, then change your credentials
Posts, stories or private messages appearing on your social media profileThe profile was used to post or to write to your contactsIt reaches many people at once, often with a linkComments, reactions or notifications about content you did not postDelete the content, change the password, review sessions and connected apps

Many of these signs arrive first as a notification: if you have not done it yet, turning on account login alerts lets you know the moment it happens, not days later.

A concrete example

Sarah works in a small practice. One Tuesday a client rings her: “I opened the invoice you sent me, but the file won’t display.” Sarah has not sent any invoice.

She opens her “sent” folder: there is no trace of that invoice. She thinks of someone forging her address, and that is a possible explanation. But one detail does not add up: the client says they had already replied to her by email two days earlier, and Sarah never saw that reply.

She finds it in the bin, together with three others. In her email settings there is a rule, created three days before, that moves every message containing the word “invoice” there; among the recent sign-ins, a browser she has never used.

Spoofing does not create rules in your inbox. The message really had left her account: whoever sent it had deleted it and hidden the replies. The decisive sign was not the empty “sent” folder, but the replies that had gone missing.

What to check right away

On your email

  • the “sent” folder and the bin, over the last few days;
  • forwarding rules, filters and the reply-to address (the one replies go back to);
  • recent sign-ins and active sessions;
  • apps and services authorised to use your mailbox.

On your messaging apps

  • the list of linked devices;
  • the status of the app’s two-step verification or PIN;
  • recent groups and conversations you do not recognise, including archived chats.

On your social media profiles

  • posts, stories and private messages from the last few days;
  • active sessions and devices;
  • connected apps with permission to post or write.

If you find a suspicious indicator

  1. Secure the account the messages are coming from. Change the password and sign out of all sessions and linked devices.
  2. Remove whatever the other person left behind: forwarding rules, filters, authorised apps, linked devices.
  3. Turn on two-step verification, or protect your account with a second factor (multi-factor authentication, MFA): an extra check on top of the password.
  4. Warn your contacts through a different channel: a phone call or a message from another account, telling them not to open the links and not to send money or codes.
  5. Check your other accounts that share the same password or that are recovered through that mailbox.

The full sequence, with the steps in the right order, is in the post on what to do if your account is sending messages. For the more general signs that apply to any account — unusual sign-ins, resets you never requested, passwords that stop working — there is the guide on how to tell if your account was hacked.

What is not an indicator

Telling the difference helps you avoid two opposite mistakes: getting alarmed over nothing, and getting used to ignoring the real signals.

SituationWhy it is usually not a sign about your account
An email “from you” whose real address is differentIt is spoofing: the display name is yours, but the message did not leave your mailbox, so on its own it does not point to access to your account
A social media profile with your photo and name that is not yoursIt is a cloned profile: someone copied what is public. It should be reported to the platform, but it does not point to access to your account
A message from an unknown number claiming to be youWhoever is writing is using your identity, not your account. Warn your contacts, but there is no need to change your password
Delivery failure notices for emails you never sentThey are often a side effect of spoofing: the fake message, once undelivered, bounces back to the address that was imitated. They only count together with other signs, such as unknown rules or sign-ins
A verification code that arrived while you were signing in yourselfThat is how the service normally works, not an attempt by someone else

Spoofing deserves attention too, because your contacts may fall into the trap. But the response is different: you warn people and report the message, without rebuilding the security of an account that is intact.

The rule of thumb: one isolated sign deserves a check; two signs together deserve action.

How often to check

You do not need a demanding routine. You just need one to exist.

FrequencyWhat to check
Whenever a contact tells you about a strange messageThe real sender, your “sent” folder, the linked devices: it is the most valuable information you will get
Whenever you receive a code you did not requestDo not share it; check that the app’s two-step verification is turned on
Every monthLinked devices on the messaging apps you use most
Every 2–3 monthsForwarding rules, filters and active sessions on your main email; recent posts and messages on social media
When you change phone or computerUnlink old devices from your apps and sign out of your services on the device you are giving up

Checking your linked devices takes less than a minute: it is worth tying it to something you already do every month.

Two important warnings

A clean “sent” folder is not a guarantee. Someone who uses an account to send messages in your name often deletes them straight afterwards, and sometimes sets up filters to hide the replies. If you find rules you did not create, replies that ended up in the bin or unknown devices, trust those signs more than the empty folder.

A sign is not proof, and it is not a fault either. Many reports turn out to be spoofing or cloned profiles, and your account is intact. When it really has been used, it is usually the result of a well-built deception — a code requested by a “friend”, a fake sign-in page — not of carelessness. Checking calmly is always the right choice.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsBeing able to tell a message that left your own account from one that only imitates the sender, and knowing where to look
AwarenessUnderstanding that an account writing in your name puts, above all, your contacts’ trust at stake
Secure BehaviourTaking your contacts’ reports seriously and checking linked devices regularly

Reference level: FL2 — Beginner. This is the level at which you learn to recognise a concrete sign and carry out the first essential checks, knowing when a deeper look is needed.

Conclusion

The signs of messages you did not send are not meant to make you suspicious of every notification. They are meant to help you know what to do when someone tells you “you sent me something strange”, instead of replying “it wasn’t me” and leaving it there.

What to do right now. Open the messaging app you use most and look for the linked devices section. If there is one you do not recognise, unlink it: you have just closed a door that was open onto your conversations. If everything looks fine, you now know that this check takes a minute and you can repeat it next month. To see where you stand on the other aspects of your digital security as well, you can take the digital resilience self-assessment.

Related resources

Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.