Skip to content
All guides

Email Security

How to Check Your Email Forwarding Rules for Hackers

Unknown forwarding rules can quietly send copies of messages to another address. This guide explains why forwarding matters, how to check it safely, and what to do if you find a rule you did not create.

By the 4safer teamUpdated August 29, 20268 minutes read

Forwarding rules can expose future messages

To check email forwarding rules, open your email provider's official settings and review forwarding, filters, rules, delegates, connected accounts, send-as settings, and automatic replies. If you find a forwarding address or rule you did not create, remove it, change your password, enable MFA, and review account activity.

Unknown forwarding is serious because it can send future emails to another inbox. That may include password reset links, bank alerts, invoices, personal messages, travel confirmations, and security notices.

This does not prove who created the rule or how it happened. But you should treat an unknown forwarding rule as a strong account security signal.

Why attackers use forwarding and filters

A person with mailbox access may not want to lock you out immediately. Instead, they may create rules that quietly forward messages, hide security alerts, move replies to obscure folders, or delete warnings before you see them.

Microsoft lists suspicious inbox rules and external forwarding among common signs to investigate in compromised Microsoft 365 mailboxes. Gmail also warns that if you see a forwarding notice you did not set up, you should change your password and turn off forwarding.

For consumers, the key point is simple: changing a password is not enough if old rules and connected access remain active.

  • Forward password reset emails.
  • Hide security alerts.
  • Move bank messages out of the inbox.
  • Delete warnings automatically.
  • Copy invoices or account notices.
  • Keep visibility after a password change.

Where to look in common email accounts

Use the official provider app or website, not a link in a suspicious message. In Gmail, review Forwarding and POP/IMAP, Filters and Blocked Addresses, Accounts and Import, send-as settings, delegated access, signatures, and automatic replies. In Outlook or Microsoft accounts, review forwarding, rules, connected accounts, devices, recent activity, and recovery settings.

Business mailboxes may be managed by IT. If it is a work account, report suspicious rules instead of making unauthorized administrative changes. Your employer may need logs or a formal incident response process.

Check exposure before deciding urgency

If your email appeared in a data breach, unknown forwarding deserves faster attention because password reset messages and security alerts may be exposed going forward. Still, even with no known breach match, a strange forwarding rule should be removed and investigated.

Only check email addresses you own or are authorized to manage. Never enter a current password or authentication code into an exposure checker.

If you find an unknown forwarding rule

Remove the rule, then change the account password from the official provider site. Use a unique password you do not use anywhere else. Sign out of other sessions if the provider offers that option.

Then enable MFA or upgrade the MFA method if possible. CISA recommends MFA because it can stop many account takeovers that rely on passwords alone.

  • Take a screenshot for your records if safe.
  • Remove the forwarding rule.
  • Change the password.
  • Sign out of unknown sessions.
  • Enable MFA.
  • Review recovery settings.
  • Check sent and deleted mail.

Check related mailbox settings

Forwarding is only one place to look. Review filters, rules, delegates, connected apps, send-as aliases, signatures, automatic replies, POP or IMAP access, and app passwords if your provider supports them.

A malicious filter might not forward everything. It may forward only bank emails, password resets, invoices, or messages with specific keywords. Search your rules for terms like password, reset, bank, invoice, payment, security, and code.

Look for signs of account access

Review recent login activity, active devices, location history if available, and security alerts. The FTC recommends checking for signs that someone had access after taking back control of an account, including settings, sent messages, and recovery information.

If you see unfamiliar activity, secure important accounts that rely on this email. Your email inbox may have received reset links for those accounts.

Protect accounts that use this email for recovery

If forwarding may have exposed reset links, review your most important accounts. Start with banking, payment apps, cloud storage, social media, work tools, and any account that stores personal documents.

Change reused passwords and turn on MFA. Check whether recovery email or phone settings were changed.

Prevent forwarding surprises later

Set a recurring reminder to review email rules. This is especially useful after travel, device loss, suspicious login alerts, or a new exposure result. The review takes a few minutes once you know where settings live.

Keep your browser and devices updated, remove extensions you do not trust, and avoid granting email access to apps that do not need it.

Frequently asked questions

Does an unknown forwarding rule mean my email was hacked?

It is a strong warning sign, but you should verify account activity and settings before drawing conclusions. Remove it and secure the account.

Can changing my password stop forwarding?

Not always. You should remove unknown rules, revoke connected apps, sign out of sessions, and enable MFA in addition to changing the password.

Should I check forwarding after a breach?

Yes, especially if your email is used for password resets or financial alerts. Forwarding can expose future messages even after an old breach.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.