A message saying your account will be deleted in an hour is designed to make you act before checking it. The display name and sender address in an email can be imitated, and a real-looking login page can capture your password and one-time code. Meta says Instagram does not send account-security warnings by direct message and points people to its in-app Emails from Instagram record for authentic account communications. Treat that record and the account's actual state as evidence, not the email's logo or its countdown.
Before you start
Do not click a link, scan a QR code or call a number in the message. Open the Instagram app yourself on a device where you are already signed in, or type the known website address into a fresh browser tab. If you have already entered a password or code, move immediately to the account-containment steps below; merely closing the tab does not revoke what you submitted.Do it step by step
- Open your profile and the settings menu, then find Accounts Center or the security area and its recent Emails from Instagram history. Interface labels can move; search within settings if necessary. Compare the subject, time and destination address with the suspicious email.
- If there is no matching in-app record, do not use the message's action button. Report the email as phishing in your mail provider and remove it from the inbox. If it arrived as a DM, report and block the sending account; Meta says Instagram will not contact you about account security in a DM.
- If there is a matching record, still open the relevant security setting from the app instead of the email. Check whether your email address, phone number, password or two-factor method was changed. A genuine notice may describe a real change you did not authorize.
- In Accounts Center, review Password and security and Where you're logged in. Sign out sessions you cannot explain, starting with unfamiliar devices. A rough location alone can be inaccurate, so compare device type, timing and your own travel before deciding.
- Change the Instagram password to a unique one if access may have been exposed. Secure the recovery email account too, because an attacker who controls it can request another reset. Turn on two-factor authentication and store recovery codes away from the phone.
- Review your profile, outgoing messages, recent posts and connected accounts for changes you did not make. Tell contacts through a separate channel if your account sent scam messages; do not forward the suspicious link as a warning.