MYTHOSAI

Email and domains / PRACTICAL GUIDE

Check mailbox forwarding and filters after suspicious activity

Find rules that copy, hide or redirect messages without deleting useful evidence.

Before you start

Your own Gmail mailbox or permission to administer the affected mailbox.

Look beyond the password

Someone with mailbox access may create forwarding or filters that continue to move information after the original sign-in. Rules can copy invoices elsewhere, hide security notices or archive replies that would reveal a problem. Ordinary useful filters can look similar, so compare each rule with its intended purpose.

Work from a trusted device through the genuine provider. If the account is actively compromised, secure it using the provider's recovery process while preserving relevant evidence for your administrator.

Inspect the delivery controls

  1. Open mailbox settings and locate automatic forwarding. In Gmail, review the forwarding controls and any listed destination. Record unexplained settings privately before removing them.
  2. Review message filters and blocked addresses. Look especially for actions that forward, delete, skip the inbox or mark important messages as read. A harmless rule name does not describe its full behaviour.
  3. Compare destinations and conditions with the account owner's known workflows. Verify a shared or supplier mailbox through an established contact, not through the suspicious rule itself.
  4. Remove unauthorised forwarding or filters through the supported controls. Review account sessions, connected apps and recovery details too; mailbox rules are only one possible persistence route.

Verify with a controlled message

Send a harmless test message that matches the affected condition and check its arrival and location. Also verify that an expected security notification or business message is no longer hidden. Avoid including genuine customer or financial data in the test.

Disabling automatic forwarding does not necessarily remove filter-based forwarding. Inspect both mechanisms, and remember that an organisation administrator may have additional mail-routing rules outside the user's settings.

Understand what removal cannot undo

Deleting a rule stops future handling through that rule. It does not retrieve copies already delivered to another mailbox or erase an attacker's downloaded messages. Assess the possible exposure using the rule conditions, time period and available account evidence.

Record the outcome

Keep the relevant rule details, observed dates, changes made and test results in a private incident record. Report financial redirection or sensitive-data exposure through the organisation's response process. A password change followed by a clean-looking inbox is not enough evidence that every unauthorised mail route has been removed.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.