Blog/ Gmail how-tos

How to Check Gmail for a Hidden Forwarding Rule or Filter

Nafiul HasanNafiul Hasan· 11 min read
Security audit checklist for Gmail settings showing the three checkpoints — forwarding address, filters, and delegate access — used to detect a hidden forwarding rule

The short answer

To find a hidden forwarding rule in Gmail, open Settings, click the Forwarding and POP/IMAP tab, and check whether a forwarding address you do not recognize is active. Then check the Filters tab for any filter that forwards, archives, or deletes mail. Finally, review the Accounts and Import tab for delegate access you did not grant.

Check Gmail Settings > Forwarding and POP/IMAP, then Filters, then delegate access to find a rogue forwarding rule or filter hidden in your account.

On this page
  1. 01Before you start
  2. 02How to check Gmail for a hidden forwarding rule
  3. 03Where the settings live across Gmail and Google Workspace
  4. 04What to do if you find a forwarding rule or filter you did not set up
  5. 05A faster way to catch the attack before the forwarding rule appears

When someone gains unauthorized access to a Gmail account, the last thing they typically do is delete your messages — that would alert you immediately. The quieter move is to add a forwarding rule that copies every incoming email to an address they control. You keep receiving mail normally, and so does the attacker. Done carefully, this can run undetected for weeks or months.

A second variant works through filters rather than forwarding. A malicious filter can archive or delete specific categories of mail — account-security notices, password-reset emails, bank statements — so they disappear before you read them. Gmail sends a confirmation when a new forwarding address is added to an account; a filter that deletes that confirmation closes the loop.

This guide covers the three Gmail settings areas where these rules live, what to look for in each one, and what to do if you find something you did not add. The same steps work as a response to a suspected breach and as a routine account-hygiene check.

Before you start#

You need access to Gmail in a desktop browser. The Gmail mobile app does not show the Forwarding and POP/IMAP tab, the Filters tab, or the delegate-access section in Accounts and Import — you cannot complete this audit from a phone or the mobile app.

Sign in as the specific account you want to audit before you begin. If you have delegate access to someone else's inbox, that grants you read and send access but not access to their settings. They will need to run this audit themselves, or a Workspace admin can do it through the Admin console.

If something specific brought you here — a password-reset email you did not request, a message someone else mentioned that you never received, or a Google notification that your forwarding settings changed — start with the Forwarding and POP/IMAP tab. That is where the most common change appears.

Google Workspace accounts have an additional audit layer

Workspace admins can check forwarding settings for any user in the domain from the Admin console, without logging in to individual accounts. Personal Gmail users cannot do this. The platform differences table further down covers the admin paths alongside the user paths.

How to check Gmail for a hidden forwarding rule#

Work through all three checks below. An attacker who added a forwarding address may have also created a filter to suppress the confirmation email Gmail sends when forwarding is enabled — so a clean Forwarding tab does not rule out a filter problem, and vice versa.

  1. 1

    Open Gmail Settings in a desktop browser

    Click the gear icon in the top-right corner of Gmail and choose "See all settings." This opens the full Settings page with all tabs visible. The quick-settings panel that appears by default does not show the tabs you need.

  2. 2

    Check the Forwarding and POP/IMAP tab

    Click this tab and look at the Forwarding section at the top. If it shows "Disable forwarding," no address is currently active. If it shows "Forward a copy of incoming mail to [address]" — and that address is one you do not recognize — that is the rogue rule. Note the address before you remove it. Gmail only allows one active forwarding address at a time in this panel, so any address you did not set yourself was added by someone else.

  3. 3

    Check the Filters and Blocked Addresses tab

    Click this tab and scroll through every filter listed. For each filter, look at the action on the right: "Forward to [address]," "Delete it," and "Skip the Inbox (Archive it)" are all worth scrutinizing. Pay particular attention to filters with broad matching criteria — anything from a specific sender domain, anything with an attachment, or anything addressed to your own email address. A broad-match filter combined with a delete or archive action is a strong signal of interference. Any filter forwarding to an address you do not recognize is suspicious regardless of the criteria it matches.

  4. 4

    Check delegate access in the Accounts and Import tab

    Click this tab and scroll to the section titled "Grant access to your account." Any email address listed there has full read, send, and manage access to your inbox. Delegate access is entirely separate from forwarding — a delegate can read your mail without a forwarding rule and does not appear in the Forwarding tab. Remove any address you did not add yourself.

After checking those three tabs, go to myaccount.google.com, open Security, and look under "Third-party apps with account access." Some OAuth apps request the "manage your mail" or "read, compose, send, and permanently delete all your email" scope. An app with that level of access can create and modify filters programmatically. If you see an app you do not remember authorizing — particularly one with mail management scope — revoke it.

Diagram of the three Gmail settings checkpoints for a forwarding-rule audit: Forwarding and POP/IMAP tab for active forwarding addresses, Filters tab for archive and delete rules, and Accounts and Import tab for delegate access
The three audit checkpoints in Gmail Settings, plus the third-party app review at myaccount.google.com.

Where the settings live across Gmail and Google Workspace#

The navigation path is the same for personal Gmail and Google Workspace user accounts. What changes is what an admin can see from outside an individual account, and what a Workspace policy can restrict.

Setting areaPersonal GmailWorkspace userWorkspace admin
Check own forwarding addressSettings > Forwarding and POP/IMAPSame locationAdmin console > Reports > Audit and investigation > Gmail log events
Check own filtersSettings > Filters and Blocked AddressesSame location — unless admin policy has disabled user-created filtersCannot view individual user filters directly; email log search reveals external routing patterns
Check delegate accessSettings > Accounts and Import > Grant access to your accountSame locationAdmin console > Users > [user] > Security > Account access
Check third-party app accessmyaccount.google.com > Security > Third-party apps with account accessSame locationAdmin console > Security > API controls > Manage third-party app access
Force-remove a forwarding rule for another userNot possibleNot possibleYes, via Admin console user settings

Workspace admins have one capability personal Gmail users lack: they can audit forwarding configurations across the entire domain without logging in as individual users. The Gmail log events section of the Admin console shows mail routing and can surface forwarding patterns — for example, messages being sent to an external address — across all accounts in the domain.

Workspace admins can also set a policy that restricts auto-forwarding to addresses outside the domain. That setting is in Admin console > Apps > Google Workspace > Gmail > Advanced settings > Routing. Enabling it prevents both users and anyone who compromises a user account from routing mail to a personal or attacker-controlled external address.

What to do if you find a forwarding rule or filter you did not set up#

Finding something unexpected means your account credentials were compromised at some point. Removing the rule stops ongoing data exposure, but an attacker who had enough access to add a forwarding rule may have set up other persistence mechanisms at the same time. Work through all of the steps below before treating the account as clean.

  1. 1

    Remove the forwarding address

    In the Forwarding and POP/IMAP tab, click "disable forwarding" or use the remove link next to the rogue address, then save settings. Gmail sends a notification to the address being removed — that is expected behavior, not a sign that removal failed.

  2. 2

    Delete malicious filters

    In the Filters and Blocked Addresses tab, check the box to the left of any filter you did not create and click "Delete." If there are many filters and you are unsure which are legitimate, use Google Takeout to export the full filter list before deleting anything — that gives you a record to reference.

  3. 3

    Revoke delegate access

    In the Accounts and Import tab, click "remove" next to any delegate address you did not add. The removed address receives a notification that access has been revoked.

  4. 4

    Change your Google account password immediately

    Go to myaccount.google.com > Security > Password and set a strong, unique password you have not used on any other site. This closes the credential-based access path. Do this before anything else if you have not already — it prevents the attacker from reversing the changes you just made.

  5. 5

    Review active sessions and recent security events

    At myaccount.google.com > Security, check "Your devices" and "Recent security activity." Look for sign-ins from locations, browsers, or devices you do not recognize. If you see unfamiliar activity, select "See unfamiliar activity" and mark it as not you to trigger Google's recovery flow.

  6. 6

    Revoke suspicious third-party app access

    At myaccount.google.com > Security > Third-party apps with account access, remove any app you do not recognize — particularly ones with mail management scope. These apps authenticate via their own tokens and retain access independently of your password. Changing your password alone does not revoke them.

  7. 7

    Enable two-factor authentication if it is not already on

    Go to myaccount.google.com > Security > 2-Step Verification. An authenticator app is more resistant to SIM-swap attacks than SMS. For high-value accounts, Google's Advanced Protection Program provides the strongest available protection and requires a physical security key.

Treat a rogue forwarding rule as an active breach, not a configuration error

Adding a forwarding rule requires authenticated access to the account. If you find one you did not set up, the attacker had your credentials — which means they may have been reading your mail for an extended period before you noticed. If this is a work account, notify your IT or security team immediately. If it is a personal account with access to financial or sensitive professional information, review what arrived during the window the forwarding was active and consider whether any of it could be used for further attacks.

A faster way to catch the attack before the forwarding rule appears#

Running this audit finds what is already in place. What it cannot do is intercept the phishing email, fake account-security alert, or credential-theft attempt that gives an attacker the login they need to add the forwarding rule in the first place. The rule is typically created within the first hour of unauthorized access — before most people think to check.

AI Emaily's spam protection layer is built to catch those upstream attack vectors: the fake Google account-security notices, the MFA-bypass prompts, the phishing emails spoofing your bank or IT department, which are commonly how Gmail credentials are stolen. The Rules Brain also gives you precise control over how your inbox routes sensitive categories of mail, so an attacker who does gain access has a narrower window to work with before the unusual routing becomes visible. We build AI Emaily. The 7-day free trial includes full access to both layers — see AI Emaily pricing for details.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Catch the phishing attempt before the forwarding rule appears.

AI Emaily's spam and phishing protection intercepts the account-takeover attempts that lead to hidden forwarding rules — before an attacker reaches your settings. Start a 7-day free trial and see AI Emaily pricing for details.

  • 7-day free trial
  • Cancel anytime
  • Every provider