For more than twenty years, your Gmail address was a life sentence. Whatever name you picked back in 2004 — embarrassing nickname, ex-partner’s surname, random string of numbers — you were stuck with it unless you wanted to abandon your entire Google account and start from scratch.

That just changed. As of March 31, 2026, Google is rolling out the ability to change your primary @gmail.com address while keeping your inbox, your Drive files, your YouTube history, and everything else attached to your account. On paper, it’s one of the most requested Gmail features of all time. In practice, security researchers are already raising red flags — and if you have a Google account, those warnings are worth a few minutes of your attention.

What Exactly Changed in Gmail?

The new feature is simple to describe. Eligible users can now go into their Google Account settings and pick a new @gmail.com username. Your old address doesn’t disappear; it stays attached to your account as an alias, which means messages sent to it still land in the same inbox. You can sign in to Google services like Maps, YouTube, and Drive with either address, and your account history, contacts, and files all stay exactly where they were.

There are limits. The change only works between @gmail.com addresses — you can’t swap your primary address to an Outlook, Proton, or custom-domain email. The rollout has also been gradual, appearing region by region rather than landing for everyone at once, so you may not see the option in your settings yet.

Google’s own messaging has leaned into the fun side of the update. The pitch, essentially: you shouldn’t be stuck with the address you made as a teenager. And honestly, for millions of people walking around with “xX_sk8erboi_Xx@gmail.com” on their CV, that’s a fair point.

So why are security professionals uneasy?

The Security Concerns, Explained

  1. Old addresses never really die — and that’s the problem

Here’s the detail that worries researchers most: when you change your Gmail address, the old one keeps working forever as an alias. That sounds convenient, and it is. But it also means that one person can now operate under multiple live @gmail.com identities tied to a single account.

Jake Moore, a security advisor at ESET, summed up the shift bluntly, noting that an email address used to be a permanent fixture of your online identity and is now editable like a social media username. His concern is that keeping old addresses alive as aliases potentially makes impersonation and phishing easier, not harder.

Think about it from a scammer’s perspective. Email addresses have long served as a kind of informal identity check. If you’ve corresponded with someone at one address for years, you trust messages from it. A system where addresses can be swapped, retired, and resurrected muddies that trust — and confusion is the raw material every phishing campaign is built from.

  1. Renaming an account can wipe the slate clean for spammers

The security publication Security Boulevard raised a different but equally practical worry: the rename feature may undermine the spam and phishing blocking that ordinary users rely on every day.

Here’s how that works. Email providers filter junk using reputation systems — they track which addresses send spam and block them accordingly. On top of that, individual users build their own personal block lists over time. You get a scam email, you hit block, and that sender can never reach you again. It’s the last line of defense after the automated filters.

But what happens when a blocked sender can simply rename their account? As Security Boulevard’s analysis put it, <a href=”https://securityboulevard.com/2026/04/gmails-new-rename-feature-could-add-spam-and-phishing-to-your-inbox/”>”renaming the account is like starting fresh.”</a> A spammer whose address has been blocked by thousands of recipients — or flagged by reputation systems — could potentially shed that baggage with a new username while keeping the same underlying account. Gmail accounts are already a favorite tool for spammers and fraudsters precisely because they’re free and carry the credibility of the gmail.com domain. Giving bad actors an easy identity refresh raises obvious questions about whether existing blocks and filters will hold up.

To be fair, Google’s reputation systems look at far more than the address string — behavioral signals, sending patterns, and infrastructure all factor in. A renamed account isn’t invisible to Google. But your personal block list? That’s keyed to an address. And that’s the layer this change weakens.

  1. The feature itself is perfect phishing bait

There’s a third risk that has nothing to do with how the feature works and everything to do with the fact that it exists: cybercriminals love new features.

Whenever Google rolls out a major account change, scammers race to exploit the confusion. Expect a wave of emails that look like this:

  • “Action required: Confirm your new Gmail address”
  • “Your address change request is pending — verify now”
  • “Someone changed your primary email. Click here to undo this change”

Every one of those is a credential trap. Because the Gmail rename feature is genuinely new and most users only half-understand it, these fake alerts will feel plausible in a way they wouldn’t have a year ago. Analysts covering the rollout warned about exactly this dynamic: a change that touches your login credentials across every Google service is an irresistible phishing lure, and users should treat any message urging them to “confirm” or “update” their address with deep suspicion.

The rule is simple and worth repeating: Google does not ask you to make account changes through links in unsolicited emails. If you want to change your address — or check whether something changed — go directly to myaccount.google.com yourself. Never through a link.

  1. Knock-on effects across the wider internet

There’s also a quieter, structural concern. Your email address isn’t just an inbox — it’s the key that unlocks your banking, shopping, social media, and password-reset flows across the entire web. Decades of online infrastructure were built on the assumption that an email address is a stable identifier.

Email deliverability experts have pointed out that businesses, mailing lists, and customer databases will now have to grapple with users whose “identity” splits across an old and new address. Google itself recommends backing up your data before making the change, and advises users to make the switch only inside their own account settings — never via an emailed link. When the company shipping the feature tells you to brace for phishing attempts built around it, that tells you something.

Is This Change Actually Bad? A Balanced Take

Let’s be clear: this isn’t a security disaster, and the feature solves a real problem. People change names after marriage or divorce. People escape harassment by shedding an identifiable address. People simply grow out of the username they invented at fifteen. Until now, all of those people faced an awful choice — keep the unwanted address or torch twenty years of digital history. Other providers like Outlook have offered alias flexibility for years, and Google Workspace customers already had similar options. Standard Gmail was the outlier.

The concern isn’t the idea. It’s the side effects: aliases that never expire, block lists that can be sidestepped, and a fresh wave of feature-themed phishing landing in billions of inboxes. Gmail serves roughly 2.5 billion users, which means even a small crack in the trust model gets exploited at enormous scale.

How to Protect Your Google Account Right Now

You don’t need to panic, but you should tighten things up. Here’s a practical checklist:

Switch to passkeys or enable two-factor authentication. Google has been pushing users away from passwords for a while now, and for good reason — a phished password is useless to an attacker if your account requires a passkey or a second factor. Set this up at myaccount.google.com under Security.

Never act on address-change emails. Treat any message about confirming, updating, or reverting a Gmail address change as hostile until proven otherwise. Navigate to your account settings manually instead of clicking.

Run a Google Security Checkup. It takes two minutes and shows you every device, app, and third-party service with access to your account. Revoke anything you don’t recognize.

Verify senders, not just names. With addresses now changeable, pay closer attention to whether a message’s actual sending address meetings who it claims to be from — and remember that even a familiar address deserves scrutiny if the message asks for credentials, payments, or urgency.

If you change your own address, do it carefully. Back up your data first, update your address with banks and critical services deliberately, and warn close contacts directly so they don’t fall for an impersonator exploiting the transition.

FAQs

Can I change my Gmail address now? The feature began rolling out around March 31, 2026, gradually and by region. If you don’t see the option in your Google Account settings yet, it may not have reached you.

Will my old Gmail address stop working? No — it remains attached to your account as an alias. Mail sent to it still arrives in your inbox, and you can sign in with either address.

Can scammers steal my old address after I change it? Based on how the feature works, your old address stays tied to your account rather than returning to the public pool, which prevents direct takeover. The bigger risks are phishing emails themed around the feature and confusion among your contacts.

Did Gmail get hacked? No. This story is about a feature change, not a breach. Separate breach rumors circulating online have been publicly disputed by Google.

The Bottom Line

Gmail’s new address-change feature is genuinely useful and long overdue — but it quietly rewrites one of the oldest assumptions on the internet: that an email address is forever. Security experts aren’t wrong to worry about impersonation, weakened block lists, and the inevitable phishing campaigns dressed up in this feature’s clothing.

The good news is that the defense hasn’t changed: strong sign-in protection, healthy suspicion of unsolicited emails, and the habit of going directly to your account settings rather than clicking links. Do those three things, and Gmail’s biggest change in two decades becomes what it should be — a convenience, not a vulnerability.

About The Author