
If a hacker got into your email account, you would probably do the obvious thing and change your password right away. That is a good instinct. But it does not always solve the problem.
There is a small feature buried in your inbox settings that attackers use to stay hidden long after you have locked them out. It is called an inbox rule, and most business owners have no idea it exists.
What is an inbox rule?
An inbox rule is a setting that automatically moves emails into folders, flags certain messages, or forwards them to another address. You may already use rules to keep your inbox organized, sorting invoices into one folder and newsletters into another.
That same feature is exactly what makes it so useful to a criminal.
How attackers use inbox rules against you
When someone breaks into an email account, one of the first things they often do is create a hidden rule of their own. These rules can quietly forward copies of your emails to an outside address, move important messages out of your main inbox, or mark them as read so you never notice them arrive.
This happens fast. In many cases, attackers set up these rules within seconds of gaining access, before you even know anything is wrong.
That speed gives them a real advantage. With a hidden rule in place, an attacker can read your conversations, pull out sensitive information, and hide the security alerts that would normally tip you off. If they are after your finance team or leadership, they can also sit back and watch for the right moment to reroute a payment.
Here is the part that catches most people off guard: changing your password does not remove these rules. If you reset your password but skip this step, the attacker may still be reading everything that comes into your inbox.
How to check for hidden inbox rules
The good news is that this is easy to check once you know where to look. Every inbox rule has a name, and one that looks strange, generic, or unfamiliar is worth a closer look. Take a few minutes to review your rules periodically, and always check them right after any suspected security issue.
You do not need advanced technical skills to do this. Most email platforms list all active rules in one settings screen – anything you did not create yourself should raise a flag.
The takeaway
Modern cyberattacks do not always rely on complicated hacking techniques. Sometimes they simply use a feature that is already sitting inside your inbox, working exactly as it was designed to, just for the wrong person’s benefit. A quick habit of checking your inbox rules can close a gap that a password reset alone will not. If you would like a hand making sure your business email is locked down the right way, give us a call.

When people think about AI at work, they often imagine things like writing reports, analyzing data, or answering emails.
Legacy systems and outdated technology create hidden costs that drain your budget and slow your business down.
If phishing scams are supposed to trick people, why do so many of them still feel clumsy?