Automatic forwarding

The Spark Team
Created:

Definition

💡  Automatic forwarding: a rule that copies or redirects incoming mail to another address the moment it arrives, without you opening it or doing anything by hand. Set it once, and every matching message (or every message, period) gets routed to wherever you've pointed it. Used deliberately, it's a handy way to route mail to the right person automatically. Used without your knowledge, it's one of the most common signs an account has been compromised. Both of those things are true at once, which is why this term deserves more care than "just another filter action."

Legitimate, everyday uses of automatic forwarding

People running client-facing operations use this constantly without necessarily naming it: invoices auto-forwarded to accounting, support requests auto-forwarded to a ticketing system, anything sent to a general inbox auto-forwarded to whoever's actually handling that inbox this month. It's the same trigger-and-action logic behind any email filter, just with "forward" as the action.

Can I forward mail to multiple addresses at once? 

Most providers support this, though some limit how many forwarding destinations a single rule can target.

Email forwarding and spam

Although, as we’ve mentioned, there are many legitimate reasons for using it, automatic forwarding is also a favorite tool of attackers who've compromised an account.  

Microsoft's own guidance on responding to a compromised account lists suspicious inbox rules, specifically rules that automatically forward email to unknown addresses, as one of the clearest signs an account has been taken over. An attacker sets up a quiet forwarding rule, often filtered to specific keywords like "invoice" or "password," and sits back collecting sensitive mail without ever needing to log in again.

This connects directly to email spoofing and phishing risk: a hidden forwarding rule is often how an attacker maintains access after the initial break-in, long after a password reset would normally have shut them out.

What to do if you think your automatic forwarding has been compromised

Checking your own forwarding rules

Setting up legitimate forwarding is usually a quick trip through your provider's filter or rules settings, using the same mechanism email automation covers for any rule-based action.

Checking for rules you didn't create is the more important habit. In Gmail, review Settings, then Forwarding and POP/IMAP, for any addresses you don't recognize. In Outlook, review Rules under Mail settings for anything auto-forwarding externally that you didn't set up yourself. If you find one you don't recognize, remove it and change your password immediately, since the rule itself is usually evidence the account was accessed by someone else.

How would I even know if a malicious forwarding rule exists on my account? 

Check your rules and filters periodically, especially after any suspicious login alert. Most compromise cases go unnoticed for a while precisely because the forwarding runs silently in the background.

Does changing my password remove an existing forwarding rule? 

No. A password reset stops future unauthorized logins, but any rule the attacker already created stays in place until someone manually deletes it.

Related terms

 

The Spark Team
Spark

Smart. Focused. Email.

Fast, cross-platform email designed to filter out the noise - so you can focus on what's important.