Email Security
How to Check for Email Forwarding Rules After Suspicious Activity
Hidden forwarding rules can copy your email to another inbox even after you change your password. Review forwarding, filters, delegates, app access, recovery settings, and active sessions inside your email provider's official security settings.
Why forwarding rules are important
Email controls password resets for many services. If a forwarding rule sends messages to someone else, they may see reset links, invoices, security alerts, and personal information.
A suspicious rule does not prove every message was read, but it should be removed and investigated quickly.
- Forwarding address
- Mailbox delegate
- Automatic filter
- Connected mail app
Where should you look?
Check forwarding settings, filters, rules, delegates, aliases, app passwords, third-party access, and recovery options. Different providers use different names, so use the provider's official settings and help pages.
- Rules and filters
- Delegates
- Connected apps
- Recovery methods
What should remain private?
Never paste your mailbox content, current password, authentication codes, or recovery codes into a general checker or support chat.
Remove unknown rules
Delete forwarding rules, filters, delegates, or connected apps you did not create. If you may need evidence, take screenshots before removing them.
- Remove unknown forwarding.
- Delete suspicious filters.
- Revoke app access.
Change account credentials
Change the email password, sign out other sessions, enable multifactor authentication, and review backup codes. Prioritize email because it can recover many other accounts.
- Change password.
- Sign out sessions.
- Enable MFA.
Check connected accounts
Review banking, shopping, cloud, social, and work accounts for resets or changes during the suspicious period. Change reused passwords immediately.
- Review high-value accounts.
- Check recent resets.
- Replace reused passwords.
Use exposure checks as one signal
If the email appears in known exposure sources, that may explain increased phishing or credential attacks. A negative 4safer result does not guarantee that no exposure happened.
Frequently asked questions
Can someone keep access after I change my password?
Yes, if forwarding rules, app access, or active sessions remain. Review those settings too.
Should I delete suspicious rules immediately?
Remove them quickly, but save private evidence first if you may need to report the issue.
Does an exposure result prove forwarding was added by an attacker?
No. It provides context, not proof of who changed account settings.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
