Email forwarding risk: how to find and remove rules a hacker left behind
Breach / exposure. Updated 2026-09-13. About 5 minutes to read.
After any suspected email compromise, check forwarding, filters or rules, delegated access and connected apps, because a new password does not remove any of them.
When criminals break into an email account, they often do not lock you out. They quietly add a forwarding address, a filter or a rule so copies of your mail go to them or warning emails vanish, and then they wait. Those settings keep working after you change your password.
In 2025 Microsoft described criminals who took over university staff mailboxes, created rules that deleted payroll notification emails and then redirected victims' salaries. Some of the rules were named with nothing but dots. This guide shows where to look in Gmail and Outlook, how to remove what you find and what else to lock down.
What attackers set up inside a hacked mailbox
Automatic forwarding of every incoming message to an outside address.
Filters or rules that forward only messages containing words like invoice, payment, bank, payroll or password.
Rules that delete, mark as read or move alerts from your bank, payroll system or the email provider into Archive or rarely opened folders such as RSS Feeds.
Delegated access that lets another account read and send your mail.
Extra send-as addresses so they can send mail that appears to come from you.
Blocked senders lists that quietly include your bank or the provider's security team.
Connected apps given permission to read your mail, and changed recovery email addresses or phone numbers.
A password change does not remove forwarding, rules, delegates or app permissions. Criminals rely on victims stopping at the password.
Check Gmail for forwarding, filters and delegates
On a computer, open Gmail, click the Settings gear at the top right, then See all settings.
Open the Forwarding and POP/IMAP tab. If a forwarding address is listed, click Disable forwarding, then Save Changes, and remove the address. Turn off POP if you do not use it.
Open the Filters and Blocked Addresses tab. Delete any filter you did not create, especially ones that Forward it, Delete it, Skip the Inbox or Mark as read. Check the blocked addresses list for your bank or Google.
Open the Accounts and Import tab. Under Grant access to your account, remove anyone you do not recognise. Under Send mail as, remove unknown addresses.
In your Google Account, open Security and review Your devices, the third-party apps and services connected to your account, and your recovery phone and email.
Back in Gmail, scroll to the bottom of the inbox, click Details next to the last account activity and sign out all other web sessions.
Google says Gmail shows a notice such as You are forwarding your email to an address for the first week after forwarding or a forwarding filter is set up. If you ever saw that banner and did not set it up, act now.
Check Outlook.com and the new Outlook
Open Outlook on the web or the new Outlook for Windows and select Settings.
Go to Mail, then Forwarding. If forwarding is on, turn it off and remove the address. Microsoft may ask you to sign in again before showing the Forwarding and IMAP page.
Go to Mail, then Rules. Delete any rule you did not create, especially ones that forward, redirect, delete or move messages into Archive, RSS Feeds or Conversation History.
Go to Mail, then Junk email, and check Blocked senders and domains for your bank or Microsoft.
In classic Outlook on a desktop, open File, then Manage Rules and Alerts, and check there too, since some rules run only on that computer.
At account.microsoft.com, open Security to review recent sign-in activity and sign-in methods, and remove apps you do not recognise from the apps with access to your account.
Work email: tell IT before you touch anything
If it is a work account on Microsoft 365 or Google Workspace, report it to IT or your security team first. They can see audit logs showing when rules were created and what was sent, which you may destroy by deleting things yourself.
Microsoft 365 administrators can list a mailbox's rules with the Get-InboxRule command and remove them with Remove-InboxRule, as described in Microsoft's guidance on rules injection attacks. Organisations should also block automatic forwarding to outside addresses unless there is a business need.
After you remove them: close the remaining gaps
Change your email password to a unique one and sign out of all sessions.
Add a passkey or authenticator app, and remove any sign-in method or recovery option you did not add.
Check your Sent, Deleted and Archive folders for messages the attacker sent or hid.
Warn contacts who may have received messages from you, especially anyone you pay or who pays you.
Call your bank if invoices or payment instructions passed through the account, and confirm any recent changes to bank details by phone.
Review accounts that use this email for password resets, starting with banking, shopping and social media.
Report it: ReportCyber at cyber.gov.au in Australia, Report Fraud in the UK at reportfraud.police.uk, and ic3.gov in the US, especially if money was lost.
Frequently asked questions
Can a hacker still read my email after I change my password?
Yes, if they set up forwarding, a forwarding rule, delegated access or a connected app. Remove all of those as well as changing the password.
How can I tell if my email is being forwarded?
Check the forwarding settings and your filters or rules directly, using the steps above. Other signs are replies to messages you never sent, missing emails you expected and alerts that never arrive.
Why would a hacker create a rule that deletes emails?
To hide warnings. Deleting alerts from a bank, payroll system or the email provider stops you noticing a changed password, a new payee or a redirected payment until it is too late.
Should I delete all my rules to be safe?
Take a screenshot of the list first, then delete anything you do not recognise. If you cannot tell which rules are yours, deleting them all and recreating the few you need is safer than leaving a hidden one.
Is POP or IMAP access a risk too?
Yes. With your password, a criminal can download mail into an email program over POP or IMAP. Changing the password stops that, but also turn off POP if you never use it and delete any app passwords you did not create.