Look beyond the password
Someone with mailbox access may create forwarding or filters that continue to move information after the original sign-in. Rules can copy invoices elsewhere, hide security notices or archive replies that would reveal a problem. Ordinary useful filters can look similar, so compare each rule with its intended purpose.
Work from a trusted device through the genuine provider. If the account is actively compromised, secure it using the provider's recovery process while preserving relevant evidence for your administrator.
Inspect the delivery controls
- Open mailbox settings and locate automatic forwarding. In Gmail, review the forwarding controls and any listed destination. Record unexplained settings privately before removing them.
- Review message filters and blocked addresses. Look especially for actions that forward, delete, skip the inbox or mark important messages as read. A harmless rule name does not describe its full behaviour.
- Compare destinations and conditions with the account owner's known workflows. Verify a shared or supplier mailbox through an established contact, not through the suspicious rule itself.
- Remove unauthorised forwarding or filters through the supported controls. Review account sessions, connected apps and recovery details too; mailbox rules are only one possible persistence route.
Verify with a controlled message
Send a harmless test message that matches the affected condition and check its arrival and location. Also verify that an expected security notification or business message is no longer hidden. Avoid including genuine customer or financial data in the test.
Disabling automatic forwarding does not necessarily remove filter-based forwarding. Inspect both mechanisms, and remember that an organisation administrator may have additional mail-routing rules outside the user's settings.
Understand what removal cannot undo
Deleting a rule stops future handling through that rule. It does not retrieve copies already delivered to another mailbox or erase an attacker's downloaded messages. Assess the possible exposure using the rule conditions, time period and available account evidence.
Record the outcome
Keep the relevant rule details, observed dates, changes made and test results in a private incident record. Report financial redirection or sensitive-data exposure through the organisation's response process. A password change followed by a clean-looking inbox is not enough evidence that every unauthorised mail route has been removed.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.