Is my account still secure?
If we notice suspicious activity, we’ll block access immediately. If your email settings change, we’ll display a banner message.
If you think your account has been compromised and access hasn’t been blocked, run an antivirus scan before changing your password. You should then follow the steps in the Recommended security checks section of this article to ensure that your account is secure.
How will I know if my account has been protected?
If you use webmail or the BT Email app, you will get an error message telling you that we have prevented access to your account. If you use a mobile device or email application (such as Outlook), you’ll get repeated login failures or password errors.
Now that my account has been protected, how do I get back in?
First, run an antivirus scan on all devices you use to access your email. It's important to do this before changing your password.
If you have BT Virus Protect as part of your broadband package, run it. If you use a mobile device, consider downloading antivirus software from your app store. If you've got it as part of your broadband package, you should run it. If you use a mobile device, you may want to consider installing antivirus software from your app store.
To change your password, you’ll then need to go to bt.com and log in to Email by selecting the email link as shown, far right, below.

Once you've changed your password, it's important to follow the security advice offered.
If you don't already have a BT ID, you'll be asked to create one and provide some additional security information. Just follow the steps and, when prompted, change your password. Choose a strong password, then update all devices you use to access your email.
Recommended security checks
Once you’ve changed your password, you'll be advised to follow some important checks needed to maintain the security of your account. These include checking:
- From the Contacts tab, check that no new contacts have been added. Delete any you don't recognise.
- Check the Contacts Trash folder for any contacts that may have been deleted and drag and drop them back to your Contacts folder. Deleted contacts will remain in the Trash folder for 30 days.
If any of your contacts have disappeared, we may be able to recover them, but please get in touch with us as soon as possible.
- Log in to My BT with your BT ID username and new password.
- Select the Your Products link, then scroll down and click the Manage option on the Email tile.
- From here, you’ll be able to view all of the email addresses linked to your BT ID and can delete any you don’t recognise.
- Go to the drop-down arrow under your username in the top right-hand corner of your email account.
- Select Settings.
- Select Mail.
- Select Rules.
- Select Enable Rules.
- Now you need to check the rules listed and select those you want to reactivate, and click on the Add button.
- Then select any you don’t recognise and click on the Delete button. Sometimes a bogus rule appears as a single dot.
- Remember to Save your changes.
An auto-reply may have been set up so that any emails sent to your inbox receive an automatic reply.
- From the drop-down arrow under your username in the top right-hand corner of your email account, select the Settings link.
- Now select Mail and then the Auto reply option.
- Check the rules that exist and delete any you don’t recognise.
- Remember to save your changes.
To protect you and your email identity, any auto-forward rules you had in place have been suspended.
Hackers may add a new email address to reset your password. Check that your account isn’t linked to any address you don’t recognise.
- From the drop-down arrow under your username in the top right-hand corner of your email account, select the Settings link.
- Select Mail and then Auto forward.
- Any auto-forward rule set up against your account will be shown.
- To re-enable the auto-forward rule, select Enable Auto-Forward.
- Remember to save your changes.
An alternative email address can help you reset your password, so it's important to check that your account hasn't been linked to an address you don't recognise.
- From the drop-down arrow under your username in the top right-hand corner of your email account, select the Settings link.
- Select Mail.
- Select Accounts.
- Delete any email addresses you don't recognise.
- Confirm deletion.
- Click Save.
- Log in to My BT with your BT ID username and new password.
- Hover over the My BT link and select Personal details from the drop-down menu.
- Check your details are correct and use the links on the right-hand side to update as necessary. We’d strongly advise you to change your security question and answer.
What can I do to keep my email account secure?
- Make sure you have BT Virus Protect and BT Web Protect installed and regularly run an anti-virus check on your computer.
- Never reply to emails asking for personal details, such as account numbers or passwords. They’re likely phishing attempts.
- Make sure the connection you’re using is safe—email accounts are regularly compromised when people use smartphones or tablets on unsecured public Wi-Fi networks.
- When using a public or shared computer, remember to log out completely by clicking the Sign Out link.
- Avoid using the same username and password across multiple sites that require login details.
- When creating a password, try to make it difficult for others to guess.