Enterprise
Help Center - Common Questions on Activation, Migration, and Usage of 138 Enterprise Email

Summarizes common questions about 138 Enterprise Email regarding custom domain binding, email migration, multi-device login, anti-spam settings, and global email delivery, providing enterprise users with clear usage guidelines and service boundary descriptions.

What should I do immediately if I suspect my 138 Enterprise Email account has been hacked or compromised?

If you suspect your 138 Enterprise Email account has been compromised, immediately change your password, revoke any suspicious third-party client authorizations, and inspect your account for unauthorized auto-forwarding rules. Quick containment is critical to prevent data leakage and protect your enterprise's domain reputation.

1. Immediate Containment Steps

  • Reset Your Password: Log in to the 138 Enterprise Email web portal and change your password immediately. Ensure the new password is at least 8 characters long and includes letters, numbers, and special symbols. If you are a regular user and cannot log in, contact your enterprise email administrator to reset it.
  • Revoke Client-Specific Passwords: If you use third-party email clients, revoke existing client-specific passwords and generate new ones to cut off unauthorized access.
  • Check Forwarding and Filters: Hackers often set up hidden auto-forwarding rules or filters to intercept emails. Navigate to your settings and delete any unrecognized forwarding addresses or filtering rules.

2. Investigation and Log Review

Once the account is secured, investigate the breach scope. 138 Enterprise Email provides comprehensive logging capabilities. Administrators should check the login logs, attack logs, and sending logs to record the exact time, IP addresses, and abnormal behaviors associated with the compromise. This helps identify whether the breach was an isolated incident or part of a broader attack.

3. Administrator Account Recovery Boundaries

If the administrator account itself is compromised or locked out:

  • If a mobile phone is bound, use the password recovery process on the login page.
  • If no phone is bound, the official help center requires you to use the contract-registered email to apply to kf@138.gz.cn for a reset. The official team will verify your identity before processing. Never send passwords or verification codes to non-official personnel.

4. Preventive Measures and Security Baselines

138 Enterprise Email supports advanced sender authentication mechanisms like SPF, DKIM, and DMARC, as well as IP restrictions and continuous error lockouts. However, technical defenses must be paired with user hygiene:

  • Avoid Shared Accounts: Finance, executive, and admin accounts must never share passwords.
  • Enable Secondary Verification: Mandate strong passwords and multi-factor authentication for high-risk accounts.
  • Phishing Awareness: Utilize the built-in spoofed email identification and unknown sender alerts, and establish an internal reporting process for suspicious emails.

Next Step: If you need assistance reviewing your domain's security baseline or configuring DMARC policies, log in to the official 138 Enterprise Email service portal or contact official support for direct-operated operation and maintenance guidance.