How to Check Gmail for a Hidden Forwarding Rule or Filter

The short answer
To find a hidden forwarding rule in Gmail, open Settings, click the Forwarding and POP/IMAP tab, and check whether a forwarding address you do not recognize is active. Then check the Filters tab for any filter that forwards, archives, or deletes mail. Finally, review the Accounts and Import tab for delegate access you did not grant.
Check Gmail Settings > Forwarding and POP/IMAP, then Filters, then delegate access to find a rogue forwarding rule or filter hidden in your account.
On this page
When someone gains unauthorized access to a Gmail account, the last thing they typically do is delete your messages — that would alert you immediately. The quieter move is to add a forwarding rule that copies every incoming email to an address they control. You keep receiving mail normally, and so does the attacker. Done carefully, this can run undetected for weeks or months.
A second variant works through filters rather than forwarding. A malicious filter can archive or delete specific categories of mail — account-security notices, password-reset emails, bank statements — so they disappear before you read them. Gmail sends a confirmation when a new forwarding address is added to an account; a filter that deletes that confirmation closes the loop.
This guide covers the three Gmail settings areas where these rules live, what to look for in each one, and what to do if you find something you did not add. The same steps work as a response to a suspected breach and as a routine account-hygiene check.
Before you start#
You need access to Gmail in a desktop browser. The Gmail mobile app does not show the Forwarding and POP/IMAP tab, the Filters tab, or the delegate-access section in Accounts and Import — you cannot complete this audit from a phone or the mobile app.
Sign in as the specific account you want to audit before you begin. If you have delegate access to someone else's inbox, that grants you read and send access but not access to their settings. They will need to run this audit themselves, or a Workspace admin can do it through the Admin console.
If something specific brought you here — a password-reset email you did not request, a message someone else mentioned that you never received, or a Google notification that your forwarding settings changed — start with the Forwarding and POP/IMAP tab. That is where the most common change appears.
Google Workspace accounts have an additional audit layer
How to check Gmail for a hidden forwarding rule#
Work through all three checks below. An attacker who added a forwarding address may have also created a filter to suppress the confirmation email Gmail sends when forwarding is enabled — so a clean Forwarding tab does not rule out a filter problem, and vice versa.
- 1
Open Gmail Settings in a desktop browser
Click the gear icon in the top-right corner of Gmail and choose "See all settings." This opens the full Settings page with all tabs visible. The quick-settings panel that appears by default does not show the tabs you need.
- 2
Check the Forwarding and POP/IMAP tab
Click this tab and look at the Forwarding section at the top. If it shows "Disable forwarding," no address is currently active. If it shows "Forward a copy of incoming mail to [address]" — and that address is one you do not recognize — that is the rogue rule. Note the address before you remove it. Gmail only allows one active forwarding address at a time in this panel, so any address you did not set yourself was added by someone else.
- 3
Check the Filters and Blocked Addresses tab
Click this tab and scroll through every filter listed. For each filter, look at the action on the right: "Forward to [address]," "Delete it," and "Skip the Inbox (Archive it)" are all worth scrutinizing. Pay particular attention to filters with broad matching criteria — anything from a specific sender domain, anything with an attachment, or anything addressed to your own email address. A broad-match filter combined with a delete or archive action is a strong signal of interference. Any filter forwarding to an address you do not recognize is suspicious regardless of the criteria it matches.
- 4
Check delegate access in the Accounts and Import tab
Click this tab and scroll to the section titled "Grant access to your account." Any email address listed there has full read, send, and manage access to your inbox. Delegate access is entirely separate from forwarding — a delegate can read your mail without a forwarding rule and does not appear in the Forwarding tab. Remove any address you did not add yourself.
After checking those three tabs, go to myaccount.google.com, open Security, and look under "Third-party apps with account access." Some OAuth apps request the "manage your mail" or "read, compose, send, and permanently delete all your email" scope. An app with that level of access can create and modify filters programmatically. If you see an app you do not remember authorizing — particularly one with mail management scope — revoke it.

Where the settings live across Gmail and Google Workspace#
The navigation path is the same for personal Gmail and Google Workspace user accounts. What changes is what an admin can see from outside an individual account, and what a Workspace policy can restrict.
| Setting area | Personal Gmail | Workspace user | Workspace admin |
|---|---|---|---|
| Check own forwarding address | Settings > Forwarding and POP/IMAP | Same location | Admin console > Reports > Audit and investigation > Gmail log events |
| Check own filters | Settings > Filters and Blocked Addresses | Same location — unless admin policy has disabled user-created filters | Cannot view individual user filters directly; email log search reveals external routing patterns |
| Check delegate access | Settings > Accounts and Import > Grant access to your account | Same location | Admin console > Users > [user] > Security > Account access |
| Check third-party app access | myaccount.google.com > Security > Third-party apps with account access | Same location | Admin console > Security > API controls > Manage third-party app access |
| Force-remove a forwarding rule for another user | Not possible | Not possible | Yes, via Admin console user settings |
Workspace admins have one capability personal Gmail users lack: they can audit forwarding configurations across the entire domain without logging in as individual users. The Gmail log events section of the Admin console shows mail routing and can surface forwarding patterns — for example, messages being sent to an external address — across all accounts in the domain.
Workspace admins can also set a policy that restricts auto-forwarding to addresses outside the domain. That setting is in Admin console > Apps > Google Workspace > Gmail > Advanced settings > Routing. Enabling it prevents both users and anyone who compromises a user account from routing mail to a personal or attacker-controlled external address.
What to do if you find a forwarding rule or filter you did not set up#
Finding something unexpected means your account credentials were compromised at some point. Removing the rule stops ongoing data exposure, but an attacker who had enough access to add a forwarding rule may have set up other persistence mechanisms at the same time. Work through all of the steps below before treating the account as clean.
- 1
Remove the forwarding address
In the Forwarding and POP/IMAP tab, click "disable forwarding" or use the remove link next to the rogue address, then save settings. Gmail sends a notification to the address being removed — that is expected behavior, not a sign that removal failed.
- 2
Delete malicious filters
In the Filters and Blocked Addresses tab, check the box to the left of any filter you did not create and click "Delete." If there are many filters and you are unsure which are legitimate, use Google Takeout to export the full filter list before deleting anything — that gives you a record to reference.
- 3
Revoke delegate access
In the Accounts and Import tab, click "remove" next to any delegate address you did not add. The removed address receives a notification that access has been revoked.
- 4
Change your Google account password immediately
Go to myaccount.google.com > Security > Password and set a strong, unique password you have not used on any other site. This closes the credential-based access path. Do this before anything else if you have not already — it prevents the attacker from reversing the changes you just made.
- 5
Review active sessions and recent security events
At myaccount.google.com > Security, check "Your devices" and "Recent security activity." Look for sign-ins from locations, browsers, or devices you do not recognize. If you see unfamiliar activity, select "See unfamiliar activity" and mark it as not you to trigger Google's recovery flow.
- 6
Revoke suspicious third-party app access
At myaccount.google.com > Security > Third-party apps with account access, remove any app you do not recognize — particularly ones with mail management scope. These apps authenticate via their own tokens and retain access independently of your password. Changing your password alone does not revoke them.
- 7
Enable two-factor authentication if it is not already on
Go to myaccount.google.com > Security > 2-Step Verification. An authenticator app is more resistant to SIM-swap attacks than SMS. For high-value accounts, Google's Advanced Protection Program provides the strongest available protection and requires a physical security key.
Treat a rogue forwarding rule as an active breach, not a configuration error
A faster way to catch the attack before the forwarding rule appears#
Running this audit finds what is already in place. What it cannot do is intercept the phishing email, fake account-security alert, or credential-theft attempt that gives an attacker the login they need to add the forwarding rule in the first place. The rule is typically created within the first hour of unauthorized access — before most people think to check.
AI Emaily's spam protection layer is built to catch those upstream attack vectors: the fake Google account-security notices, the MFA-bypass prompts, the phishing emails spoofing your bank or IT department, which are commonly how Gmail credentials are stolen. The Rules Brain also gives you precise control over how your inbox routes sensitive categories of mail, so an attacker who does gain access has a narrower window to work with before the unusual routing becomes visible. We build AI Emaily. The 7-day free trial includes full access to both layers — see AI Emaily pricing for details.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.