PanicStation.org
uk Technology & digital loss

What to do if…
unknown email rules are forwarding, deleting, archiving, or hiding messages

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Use your email provider’s official website or app to remove or disable any rule, filter, forwarding address, or mailbox setting you do not recognise. Then change the password, sign out other sessions, and secure the account because an unknown rule may mean someone else has accessed it.

Do not do these things

  • Do not approve an unexpected sign-in or security prompt.
  • Do not use account-recovery links from an unexpected email or text.
  • Do not leave an unknown forwarding rule active while investigating it.
  • Do not assume that changing the password will also remove mailbox rules or forwarding settings.
  • Do not reuse the old password or one used for another account.
  • Do not contact an unfamiliar forwarding address.
  • Do not share verification codes, passwords, or recovery details with anyone who contacts you unexpectedly.
  • Do not use a device you believe may be compromised when a trusted alternative is available.

What to do now

  1. Open the email provider’s official website or app directly. Do not enter through a link in a message. For a work, school, or organisation-managed account, contact the authorised IT or security team promptly.

  2. Check the account settings for rules, filters, forwarding, automatic replies, blocked senders, delegates, connected accounts, and other automatic message handling. Remove or disable anything you did not create or no longer recognise.

  3. If it is safe to do so without delaying removal, take a screenshot or note the suspicious rule, forwarding address, affected messages, and time you found it. Do not keep the rule active merely to collect information.

  4. Check the inbox, archive, deleted items, junk or spam, all-mail view, and unfamiliar folders. Restore important messages where the provider allows it.

  5. Change the email password after removing unknown forwarding rules or filters. Create a new, unique password, and change the password on any other account that used the same one.

  6. Use the account’s security settings to sign out other devices, applications, and active sessions. Remove devices, app passwords, connected applications, delegates, recovery addresses, or recovery phone numbers you do not recognise.

  7. Turn on two-step verification if the provider offers it. Keep any recovery codes or recovery details somewhere secure and separate from the email account.

  8. Review recent sign-ins and sent messages for activity you do not recognise. Tell affected contacts through another trusted route if suspicious messages may have been sent from your address.

  9. Check sensitive accounts linked to the email address, especially banking, payment, shopping, payroll, government, social-media, cloud-storage, and password-manager accounts. Open each service directly and look for unexpected password resets, sign-ins, purchases, or changed details.

  10. If money or payment information may be at risk, contact the relevant bank or payment provider immediately through its official app, website, or a trusted phone number. Report cyber crime or fraud through Report Fraud in England, Wales, or Northern Ireland, or contact Police Scotland on 101 if you are in Scotland.

What can wait

You do not need to reorganise the whole mailbox, rebuild every legitimate rule, identify exactly how access occurred, or decide whether to abandon the email address now. First stop the unwanted message handling, secure access, and check the most sensitive linked accounts.

Important reassurance

An unfamiliar rule does not by itself show that every message or linked account has been accessed. Removing it and securing the account promptly can stop further automatic handling while you check what may have been affected.

Scope note

This guide covers immediate steps for unexplained email rules, filters, forwarding, deletion, archiving, or hidden messages. Later recovery, investigation, workplace reporting, financial protection, or data-protection decisions may require help from the provider, an authorised IT team, a bank, the police, or a cyber-security specialist.

Important note

This is general information, not legal, financial, technical, or other professional advice. Email settings and recovery options vary between providers and managed accounts, so follow your provider’s official instructions or your organisation’s authorised support process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us