If you suspect your account has been taken over: immediate steps

Act quickly from a trusted device and network you control.

1) Secure your email first
- Change the password for the email address you use to sign in to your account.
- Enable two-factor authentication (2FA) on your email. If your email remains compromised, attackers can undo any recovery steps.

2) Reset your account password
- Go to the Sign In page and select Forgot password.
- Send the reset link to the registered email address on file for the account.
- Create a strong, unique password (at least 12-16 characters). Do not reuse passwords from other services.

3) Rotate your 2FA
- If you use an authenticator app, remove existing authenticators and re-enroll to generate a new secret key.
- Generate and securely store new backup codes.
- If you used SMS 2FA, consider switching to an authenticator app for stronger protection.

4) End all active sessions
- From your security settings, sign out of all devices/browsers to invalidate any stolen sessions.

5) Review and revert changes
- Check recent logins and activity for unfamiliar devices, IPs, or times.
- Review account email, phone, recovery options, and authorized users; revert any unauthorized changes.
- If you manage domains, verify contact data, nameservers, DNS records, transfer locks, and auth codes. Reinstate locks and correct DNS if altered.

6) Scan your devices
- Run a reputable antivirus/malware scan on computers and phones you use to access the account.

7) Report the incident to Support
- If you see suspicious activity or cannot secure the account fully, contact Support immediately (see the reporting steps below). We can place a temporary security hold on critical actions while ownership is verified."