PanicStation.org
us Technology & digital loss

What to do if…
unknown email rules are forwarding, deleting, archiving, or hiding messages

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat unfamiliar email rules as a possible sign of unauthorized access. From a trusted device, open the email provider directly, secure the account, and remove rules, filters, or forwarding settings you did not create.

Do not do these things

  • Do not use password-reset or security links from unexpected messages; open the provider’s official app or website yourself.
  • Do not delete the email account or wipe the entire mailbox in panic.
  • Do not assume that removing one visible rule has fully secured the account.
  • Do not reuse the old password or a password used for another account.
  • Do not share passwords, verification codes, recovery codes, or screen access with unsolicited support callers or messages.
  • Do not make security changes from a device you reasonably suspect contains harmful software when a trusted device is available.
  • Do not send sensitive information from the affected mailbox until you have secured it.

What to do now

  1. Use a device you trust. Open the provider’s official app or type its website address yourself. If you only have a potentially affected computer, update its security software and run a scan before entering a new password.

  2. If this is a work, school, or managed account, contact the organization’s IT or security team through a known help desk, phone number, or internal portal. Ask whether they need details of the unfamiliar rules before you change them.

  3. Note or take screenshots of the names, conditions, actions, and destination addresses of unfamiliar rules if you can do so safely. Then disable or delete rules that forward, redirect, delete, archive, mark as read, move, or hide messages without your permission.

  4. Change the email account password to a strong password that you do not use anywhere else. Use the provider’s account-recovery process if you cannot sign in or change it.

  5. Use the provider’s security settings to sign out other devices or sessions where that option is available. Turn on multifactor authentication and check that the recovery email addresses, phone numbers, authentication methods, and backup options belong to you.

  6. Review recent security activity, sign-ins, connected devices, and applications with account access. Report unfamiliar activity through the provider’s security controls and remove access you do not recognize.

  7. Check all available mailbox settings, not only the rule you first noticed. Look for unfamiliar filters, forwarding addresses, blocked senders, delegates, shared access, connected accounts, automatic replies, reply-to addresses, app passwords, and POP or IMAP access.

  8. Check Sent, Archive or All Mail, Trash or Deleted Items, Spam or Junk, and unfamiliar folders. Search for recent password resets, security alerts, payment notices, account changes, and messages from important services. Restore needed messages when the provider offers that option.

  9. Change the password on any other account that used the same or a similar password. Prioritize banking, payment, shopping, cloud-storage, social-media, and other accounts that can be reset through the affected email address.

  10. If you find unauthorized purchases, transfers, new accounts, or misuse of personal information, contact the affected company through its official app, website, statement, or payment-card number. Use IdentityTheft.gov for steps matched to identity theft.

  11. Update devices and browsers used with the account. Remove browser extensions or applications you do not recognize and run a current security scan. If harmful software is found after you changed the password, change it again from a trusted device.

  12. If the mailbox sent suspicious messages, warn recent contacts through another trusted channel after securing the account. Tell them not to open unexpected links, attachments, or payment requests that appeared to come from you.

What can wait

You do not need to identify who created the rules, reconstruct every missing message, choose a new email provider, or understand the full technical cause right now. Detailed mailbox cleanup, long-term monitoring, and formal reports can wait until the account is secure and the unknown rules have stopped affecting messages.

Important reassurance

An unfamiliar rule does not prove how it was created, but it is a clear reason to check the whole account. You do not need to know the cause before securing access, stopping the rule, and checking where messages went.

Scope note

This guide covers immediate account-security and message-recovery steps only. Later decisions may require help from the email provider, an organization’s IT team, a device-security specialist, a financial institution, or an identity-theft specialist.

Important note

This is general information, not individualized cybersecurity, legal, financial, or other professional advice. Email settings and recovery options vary, so follow the current instructions on your provider’s official security and recovery pages.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us