Fixing Malicious Email Forwarding Rules Discovered After a Breach

If your account was recently breached and you’ve found email forwarding you didn’t set up, act quickly. Malicious forwarding rules can quietly copy sensitive messages—password resets, bank alerts, tax information—to an attacker even after you regain access. This guide walks you through immediate containment, how to find and remove rogue rules across popular email providers, what to check afterward, and how to prevent this from happening again.

Why Malicious Email Forwarding Matters

Forwarding rules are legitimate features that automatically send copies of your messages to another address or move them into folders. Attackers abuse them to:

  • Exfiltrate sensitive mail without triggering obvious login alerts.
  • Intercept password resets and maintain access to other accounts.
  • Hide your messages by moving them to obscure folders, making it harder for you to notice suspicious activity.

Because many forwarding rules run server-side, they work even if you don’t have your email app open. That’s why removing them is as important as changing your password.

First: Contain the Breach

Before you start deleting rules, contain the situation so the attacker can’t keep making changes.

  1. Use a trusted device and network. If possible, switch to a device you control and a secure network (e.g., your home Wi‑Fi). Avoid public Wi‑Fi while recovering your account.
  2. Change your email password to a strong, unique passphrase you haven’t used anywhere else.
  3. Turn on multi-factor authentication (MFA) for your email account. Use an authenticator app or security key if available.
  4. Sign out other sessions and revoke access tokens. Most providers let you force a sign-out of all active sessions and connected apps. Do this now.

How to Find and Remove Malicious Forwarding Rules

Follow the steps for your provider. If you use multiple accounts or email apps, check them all—rules can exist both in the server account and in your desktop or mobile client.

Gmail (Personal)

  1. Check Forwarding: Settings (gear) > See all settings > Forwarding and POP/IMAP. Look for any forwarding addresses you don’t recognize. Remove them.
  2. Check Filters: Settings > Filters and Blocked Addresses. Delete suspicious filters that forward, delete, or skip the inbox, or that move mail to labels you didn’t create.
  3. Review Delegation: Settings > Accounts and Import > Grant access to your account. Remove any unknown delegates.
  4. Review Connected Apps: Google Account > Security > Third-party access. Remove anything you don’t trust.
  5. End Sessions: Gmail inbox bottom-right > Details (Last account activity) > Sign out of all other web sessions.

Google Workspace (Work/School)

  1. Follow the Gmail steps above.
  2. If you have admin help, ask your admin to check for organizational-level routing rules, suspicious app authorizations, and OAuth grants in the Admin console.
  3. Admins can review audit logs and disable auto-forwarding organization-wide if needed.

Outlook.com (Microsoft Consumer)

  1. Check Forwarding: Settings (gear) > Mail > Forwarding. Remove unknown addresses.
  2. Check Rules: Settings > Mail > Rules. Delete rules that forward, redirect, or move mail to unexpected folders.
  3. Check Connected Accounts and Permissions: Settings > Sync email and Privacy > Apps and services. Remove unknown connections and apps.
  4. Sign Out Everywhere: Microsoft Account > Security > Advanced security options > Sign out everywhere; also revoke any suspicious sessions or recovery methods.

Microsoft 365 / Exchange Online (Work/School)

  1. Outlook on the web: Settings > Mail > Forwarding and Rules. Remove anything suspicious.
  2. Check Inbox and Sweep rules in Outlook desktop and web.
  3. Admins: Use Exchange Admin Center or PowerShell to audit mailbox rules:
    • Look for rules with “forward,” “redirect,” “Bcc,” or “delete” actions, and odd conditions (e.g., common words or external domains).
    • Disable auto-forwarding to external domains if not required.
    • Reset user sign-in sessions and invalidate OAuth tokens from Azure AD.

Yahoo Mail

  1. Check Forwarding: Settings > More Settings > Mailboxes > Forwarding. Remove unknown addresses.
  2. Check Filters: Settings > More Settings > Filters. Delete suspicious filters.
  3. Security: Account Info > Recent activity. Sign out of other sessions and change your password; add or confirm MFA.

Apple iCloud Mail

  1. Check Rules: iCloud.com > Mail > Settings > Rules. Remove suspicious rules that forward or move mail.
  2. Security: appleid.apple.com > Sign-In and Security. Change password, enable two-factor authentication, and review devices.

Other Providers and Email Clients

  • Server-side rules: Always check your webmail portal; these rules run even when your computer is off.
  • Local client rules: Check Outlook, Thunderbird, Apple Mail, or mobile apps for rules, filters, or auto-forward settings.
  • Aliases and forwarding services: If you use domain email, check your domain host or email routing panel for forwarding or catch-all rules.

What Suspicious Rules Look Like

Attackers often use subtle, generic, or misnamed rules to avoid detection. Red flags include:

  • Forwarding or redirecting to unfamiliar addresses, especially free or lookalike domains.
  • Rules that apply to “all mail,” “bank,” “invoice,” “verification,” or “security” keywords.
  • Rules that move messages to seldom-used folders (e.g., Archive, Notes, RSS, or a new folder with a bland name like “System” or “Receipts”).
  • Rules that delete or mark messages as read immediately.
  • Filters that skip the inbox, hide from search, or only trigger on external senders.

After Removal: Verify No Backdoors Remain

Once you’ve deleted malicious rules and forwarding addresses, complete this checklist:

  1. Recheck rules and forwarding after a few hours and again in 24–48 hours to ensure nothing reappears.
  2. Reset passwords for high-value accounts (banking, brokerage, payroll, taxes, shopping, social media) that may have had password-reset emails intercepted.
  3. Review account recovery options: Verify your phone number, backup email, and security questions. Remove unknown recovery methods.
  4. Revoke third-party access: Remove unfamiliar apps and OAuth tokens from your email, cloud storage, and calendar services.
  5. Scan devices: Run an up-to-date antivirus/anti-malware scan on your primary devices to rule out keyloggers or trojans.
  6. Check sent items, trash, and archive for messages you didn’t send or rules you didn’t create.
  7. Enable security alerts for new logins, forwarding changes, and password changes where available.

Strengthen Your Email Security Going Forward

  • Use strong, unique passwords for email and never reuse them across sites. A reputable password manager can help.
  • Prefer app-based MFA or security keys over SMS where possible.
  • Disable or restrict auto-forwarding if you don’t need it. In business environments, ask IT to block external forwarding.
  • Review rules monthly as part of a quick security checkup.
  • Watch for lookalike domains in rules and messages (e.g., “gma1l.com” vs “gmail.com”).
  • Keep devices updated and uninstall unneeded email clients or plugins.

If You Suspect Ongoing Identity or Financial Risk

When attackers have monitored your email, they may target your financial accounts or impersonate you. Consider these steps:

  • Monitor your credit and identity signals: Set up alerts for new accounts, inquiries, and changes to your profile.
  • Enable account notifications at your bank, credit card, and payment apps for logins, transfers, and changes.
  • Freeze your credit with the major bureaus if you believe your Social Security number or personal details were exposed.
  • Document everything: Keep timestamps, screenshots of rules, and any suspicious emails to assist with support or law enforcement if necessary.

If you want a single place to track credit and identity activity after a breach, you can use a dedicated monitoring service. Many readers use resources like SmartCredit for privacy, credit monitoring, and identity protection to watch for unusual changes and get alerts.

Quick Reference: Provider-Specific Pathways

  • Gmail: Settings > Forwarding and POP/IMAP; Filters and Blocked Addresses; Accounts and Import (delegation).
  • Outlook.com: Settings > Mail > Forwarding; Rules; Apps and services.
  • Microsoft 365: Outlook on the web > Settings > Mail > Forwarding; Rules; Admin review for transport rules and external forwarding policies.
  • Yahoo: More Settings > Mailboxes > Forwarding; Filters; Recent activity.
  • iCloud: iCloud Mail > Settings > Rules; Apple ID security for devices and 2FA.

Frequently Asked Questions

Do I still need to change my password if I removed the rule?

Yes. If the attacker created a rule, they had access. Change your password and enable MFA, then remove rules and revoke sessions in that order.

What if the forwarding address looks like my own?

Attackers often create lookalike addresses (e.g., missing a letter) or new addresses at similar domains. If you don’t recognize it, remove it.

Could a desktop rule keep forwarding even if I fixed webmail?

Yes. Check both server-side and local client rules. Disable or delete suspicious rules in Outlook, Apple Mail, Thunderbird, and mobile apps.

How do I know if rules are back?

Recheck settings in a day or two and enable provider security alerts. If rules reappear, your device may be compromised or an app token still has access—revoke tokens and rescan devices.

Post-Breach Recovery Checklist

  1. Contain: New password, MFA on, revoke sessions and app tokens.
  2. Remove: Delete forwarding addresses, filters, and rules in webmail and local clients.
  3. Verify: Recheck rules later; confirm recovery methods; scan devices.
  4. Restore: Reset passwords for high-value accounts and set alerts.
  5. Monitor: Keep an eye on credit and identity signals and consider a centralized monitoring tool.

Conclusion

Malicious forwarding rules are a quiet but powerful way attackers maintain access after an email breach. By containing the incident, methodically removing rogue rules across your provider and apps, and closing other backdoors like app tokens, you can cut off ongoing exposure. Follow with password resets on critical accounts, enable stronger authentication, and monitor for identity or financial warning signs. A short routine—monthly rule reviews and alert checks—goes a long way toward keeping your inbox, and your broader digital life, under your control.

Good to Know

Attackers often hide forwarding rules with names that look legitimate or place them in less-visible settings like server-side rules. Even if you change your password, a rogue rule can keep exfiltrating mail until you remove it and revoke all sessions.