What to do when my Private Email mailbox is compromised?

In this article, we will explain what to do if you receive the email shown below from Namecheap’s Customer Support team.

We understand that violations of the policy regarding the use of our services are not always due to user behavior, and you may not immediately know why it’s happened. That’s why we’d like to provide a detailed description of how to avoid email misuse and what to do if you encounter it.

The email from support

This is the email you’ll get if your account has violated our policy:

Subject: IMPORTANT: the Private Email Subscription DOMAIN [ USERNAME ] is suspended due to Email Misuse

Hello,
We are contacting you on behalf of the Namecheap Customer Support team regarding your "xUSERNAMEx" Namecheap account.

It has come to our attention that there is a high number of similar emails queued on the server from your Private Email subscription for the xDOMAINx domain.

We have blocked outgoing emails for the service in question to prevent further misuse.

It is likely that your mailbox/subscription has been compromised.

Therefore, please take the following steps immediately to improve your security: - scan your home PC and hosting account for viruses (if any);
- change password for the involved Private Email mailbox(-es) with the help of the following guide: https://www.namecheap.com/support/knowledgebase/article.aspx/1053/2215/how-to-change-namecheap-private-email-password/
- change password for your Namecheap account using the following guide: https://www.namecheap.com/support/knowledgebase/article.aspx/424/43/how-do-i-change-the-password-for-my-account/
- change password for the Primary email address assigned to your Namecheap account.

If you feel you received this notification in error, please reply to this email with more information as to why. We do apologize for any inconvenience this may cause you.

Thank you, and we look forward to hearing from you.

Compromised account

You may have received this email because your account is compromised due to hacker attacks or security vulnerabilities. If your account is compromised, this can lead to unauthorized activities, such as phishing attempts or the spreading of malware. It is essential to regularly monitor your account for any signs of suspicious activity.

There are several indicators that can help you determine if someone has access to your mailbox. You might notice emails in your Sent folder that you did not send or forwarding and filter rules that you did not set up. It is important to regularly check your mailbox settings, as well as to keep your security software up to date. Ensure that your device is running the latest antivirus software to protect against potential malware that could compromise your email account or devices. We recommend checking the article in our blog that explains how to protect your computer from malware.

Regularly review the active sessions in webmail to ensure that your email account is not being accessed from other browsers.This would help you stay informed about any potentially suspicious access:

How hackers gain access

Hackers can use several methods to gain access to your mailbox:

  • Phishing attacks — scammers send deceptive emails that appear legitimate and trick you into clicking on malicious links or entering your login credentials on a fake website.
  • Weak passwords — Weak or commonly-used passwords make it easier for attackers to gain access, as they can be cracked using automated tools or simple methods.
  • Keyloggers and malware — By downloading malware or spyware (affected files) accidentally, you can provide attackers with remote control over your device and accounts or expose your password.
  • Social engineering — You may be manipulated or tricked by hackers into revealing your credentials by pretending to be someone you know and trust.
  • Public Wi-Fi networks — Sometimes, public internet networks may not be encrypted, which could expose your login details to attackers.
These are just a few examples of how your login details can be obtained for unauthorized use.

How to protect your account from hackers

Always be cautious about who you share your email address with, including websites and individuals you communicate with via email. Avoid providing your email address on websites or publicly available platforms.

We also recommend that you avoid clicking on unfamiliar links or downloading attachments from unknown sources. Such actions not only confirm that your email address is active but can also infect your personal computer.

If you suspect that your mailbox has been compromised, it's crucial to act quickly to protect your data. Let's break down each step in more detail:


1. Make sure the computers are malware and virus free
2. Change your Private Email password
3. Set up Two-factor authentication and create application-specific passwords
4. Change the password for your Namecheap account
5. Change the password for your primary email address related to your Namecheap account

First, ensure that your computer is not infected with malware. We recommend running a full system scan using reliable antivirus software.

You can spot suspicious activity by monitoring any unusual behavior, such as slow performance, unexpected pop-ups, or unfamiliar programs.

Be aware of any attempts at unauthorized access to your accounts, unexpected changes to your settings, or unknown browser toolbars. There are many ways to lock your computer down when it comes to malware.

Once you have determined that your computer is not infected with any malware and can be used safely, we recommend that you change the password for your mailbox(es) to restrict unauthorized access.


Here are some tips for password creation:
  • Create a strong and unique password using a combination of at least 8 characters;
  • A minimum of 1 uppercase character, 1 lowercase character, and 1 number should be included;
  • The password must not contain spaces or the following characters: \, &, +, and '. Characters accepted are: [a-zA-Z0-9#!@$%^*()_=“?.,/;:<>`{|}~-[]]
  • Do not use the same passwords for multiple accounts or reuse passwords that have been used before.

Check this guide on how to change your Private Email password.

We recommend changing the password regularly (at least once a month) using a specialized password management tool such as Bitwarden or 1Password. These tools allow you to generate strong, unique passwords and store them securely while maintaining easy access to them.

Furthermore, a password manager helps protect against phishing attacks by automatically filling in credentials only on legitimate websites, reducing the risk of becoming a victim of fraudulent login pages. A password manager is not only secure but also convenient, eliminating the need to memorize several complex passwords.

When Two-Factor Authentication is enabled, your account cannot be accessed by unauthorized individuals, even if they have stolen your password because the second layer of verification provides another layer of security in the form of something you possess (usually a device with a code generator).

Setting up 2FA for your business email account is critical to prevent phishing attacks and protect your data. If you need further guidance, there are detailed instructions on how to set up 2FA for Private Email.

NOTE: Two-Factor Authentication is exclusively available for our web interface.

Set up application passwords

If you are using a mobile email client (like Outlook) that supports Exchange/ActiveSync connections, or linking the service with OX Drive (to check your files), CalDav (to sync events), and/or CardDav (to sync contacts) and have 2FA enabled, we recommend setting up Specific-application passwords as an additional layer of security for your account. Find out how to set up application passwords.

Additionally, disabling IMAP/POP/SMTP connections is possible for any mailbox individually. You may consider this option if you wish to eliminate access by third parties in email clients or prevent hackers from using SMTP connections to send emails from their own servers. By disabling these protocols, you can significantly increase the security of your email account by ensuring that only authorized devices can access or send emails from your account. For that, you can contact our Support Team.

To secure your domains, email accounts, hosting, and other services in your account with us, we strongly advise you to change the password for your Namecheap account (as well as Private Email specifically).

Use a unique password that you don’t use on other websites and that has not been previously used for any other accounts. Store it in a secure place, and don’t share it with anyone. Find out how to change your Namecheap account password.

To maximize the security of your Namecheap account, we recommend enabling Two-Factor authentication. When you rely on a second step of verification, such as a one-time code sent to your phone or email, you significantly reduce the risk of unauthorized access making it much harder for attackers to gain control of your account. Enable 2FA for your Namecheap account.

Stolen passwords can lead to hackers gaining access to your business email account and to your services with Namecheap or other providers.

Remember to change passwords not only for mailboxes and the Namecheap account itself but also for the personal mailbox linked to your Namecheap account. Updating this password is extremely important because it is likely that your business email account has been compromised due to unauthorized access to your personal email address.

If this email address is gaining access to an unauthorized user, attackers can easily compromise your Namecheap account and manage all of your services and products, including the email service.

Your Namecheap account's primary email is the one provided when you registered with us or the one it was later changed to. You can determine your primary email in the Profile section of your account by navigating to Personal Info >> Primary Email:

Follow the tips in this article to create a strong, unique password and store it in a safe place using a secure tool.

If you have any questions, feel free to contact our Support Team.

Updated
Viewed
32 times

Need help? We're always here for you.

notmyip