An unexpected password-reset email can mean someone typed your address, an old request arrived late, or another person is trying to reach your account. It does not prove they changed the password. Treat the message as a clue, not an instruction to click.
Check the sender again only after the account is secure. Even a genuine-looking email can be copied. Google's password-assistance explanation describes unsolicited reset mail. If you entered credentials on a page linked from the message, follow our phishing-page recovery guide instead of merely deleting the email.
Check without using the email
- Open the service's app or type its known address yourself. Do not use the reset button, phone number or reply address in the unexpected message.
- Check whether you can still sign in. Review recent activity, signed-in devices and security notices inside the account. A reset request is different from a successful sign-in or a changed recovery method.
- Inspect the recovery email and phone. If either changed without you, use the provider's official account-recovery route immediately.
- If you reused this password elsewhere, replace the reused passwords with unique ones. Turn on MFA and keep a recovery method you control.
Use the result
Only an email, with no account change? You may ignore the request after checking the account. A successful sign-in or security change you did not make? Change the password from a trusted device, end unfamiliar sessions and review connected apps. Locked out? Use the real provider's recovery flow; never pay a stranger to regain access.Check the sender again only after the account is secure. Even a genuine-looking email can be copied. Google's password-assistance explanation describes unsolicited reset mail. If you entered credentials on a page linked from the message, follow our phishing-page recovery guide instead of merely deleting the email.