The inbox rule an attacker left behind
After a phishing compromise, a hidden mail rule can keep deleting or forwarding your mail — and a password reset never touches it. How to find and clear it in ten minutes.
Someone clicked a convincing email a fortnight ago, typed the password into a page that looked just like the real sign-in, and realised a minute later it wasn’t. You did the sensible thing straight away: changed the password, turned on two-factor, told everyone to be careful. The account felt cleaned up, and the incident quietly closed.
What nobody looked at was the mailbox’s own rules. In the first seconds after signing in, an attacker often creates a simple mail rule — anything containing “invoice”, “payment” or “bank” gets forwarded to an outside address and then marked as read, or moved straight to a folder you never open, or deleted. This is routine rather than rare: researchers at Proofpoint found that about one in ten compromised Microsoft 365 accounts had a rule like this created within seconds of the break-in. It costs them a few clicks and it outlives everything you did afterwards, because resetting a password signs the intruder out but leaves the rule exactly where it is. The mailbox keeps working perfectly. It just quietly works for someone else as well.
That’s the quiet failure: not a locked account or an obvious break-in, but a small, sensible-looking setting that keeps siphoning off the emails that matter most, long after you were sure it was over.
Why it stays invisible
A mail rule is meant to be boring. It’s the same machinery that files newsletters or flags messages from your boss, so it raises no alarm and shows up in no security report. When you reset a password, none of the usual tools go and read the rules you already had — they weren’t part of the break-in as the system sees it, they’re just your settings.
The rules an attacker builds are designed to be missed. They forward a copy rather than diverting the original, so you still get most of your mail and nothing seems absent. The telltale ones name a folder like “RSS Feeds” or a single full stop as their destination — a folder you’ll never think to open — and they switch the message to “read” so no unread badge ever hints that something was touched. The damage is entirely in what you don’t see: the supplier who says they emailed you new bank details you never received, the reset link for another account that never arrived, the quiet forwarding of anything that mentions money.
And because it survives the reset, the timeline works against you. Weeks later, when a payment goes to the wrong account, the compromise feels like ancient history — surely that was dealt with. The rule is still there, doing the one job it was left to do.
Find it yourself
You can check your own mailbox in about ten minutes, and you don’t need an administrator to do it for your own account.
-
Open your rules list. In Outlook on the web, click the gear icon (top right) → Mail → Rules. In new Outlook for Windows, it’s Settings → Mail → Rules; in classic Outlook, File → Manage Rules & Alerts. In Gmail, open Settings (the gear) → See all settings → Filters and Blocked Addresses.
-
Read every rule as if you didn’t make it. You’re looking for anything you don’t remember creating, especially rules that forward or redirect mail to an address outside your organisation, that delete messages or move them to Deleted Items, or that file into an odd, rarely-opened folder. Be suspicious of rules triggered by words like invoice, payment, bank, wire or urgent, and of any rule with a blank or one-character name.
-
Check forwarding separately. A mailbox can also forward everything without a rule. In Outlook web, go to Settings → Mail → Forwarding and confirm it’s off; in Gmail, Settings → Forwarding and POP/IMAP. This is a different switch from the rules list, and attackers use both.
-
If you run Microsoft 365, check across everyone. An administrator can list every forwarding rule in the tenant at once. In PowerShell,
Get-InboxRuleper mailbox will show them; the Microsoft 365 Defender portal also has a built-in hunt for suspicious inbox-forwarding rules. If that’s beyond you, it’s a fair thing to ask your IT provider to run — the phrase to give them is “check all mailboxes for external forwarding rules”.
The usual jolt is at step 2: not a dramatic rule, just a quiet one pointing at a folder you forgot you had.
The fix
Clearing it is quick, but the order matters, because you want to close the door and change the locks.
Delete the rule, and note where it pointed. Remove any rule you didn’t create, and write down the forwarding address before you do — it tells you, and anyone investigating, where your mail was going. Turn off any forwarding you didn’t set up.
Assume the reset wasn’t enough. If a malicious rule was there, the account was genuinely in someone else’s hands, so treat everything the rule could have leaked as compromised: reset any passwords whose reset emails might have been intercepted, and warn anyone — suppliers especially — whose payment details could have been quietly swapped. This is the part people skip, and it’s the part that actually stops the fraud.
Cut off the session, not just the password. Changing a password doesn’t always sign an attacker out of an existing session. In Microsoft 365, an admin can “sign out of all sessions” (revoke the tokens); in Google Workspace, use the account’s Sign out all sessions. Do this alongside the password change, not instead of it.
Make the next rule visible. After any suspected compromise, add checking the rules and forwarding settings to your recovery checklist — it’s the step almost everyone misses. Larger mailboxes can alert an administrator whenever a new forwarding rule is created, which turns a silent change into an email you’ll actually see.
None of this needs a forensics team. It needs someone to open the rules list once, read it with fresh eyes, and remember that a password reset locks the door but doesn’t check who’s already inside.
One real, fixable exposure every week. Free.