The Gmail filter visibility limit in InboxGuards

User-created Gmail filter changes are outside the audit data InboxGuards currently uses. Here is the boundary and the separate manual review to perform.

N°001sectiona filter change inboxguards cannot see

Section 01

A filter change InboxGuards cannot see

Here's a real scenario. An attacker gets into a Gmail account — a phished password, a reused one from a breach. They don't forward anything. They don't download anything. They create one Gmail filter: "if a message contains the word invoice, delete it." Or subtler: "mark replies from this vendor as read and archive them."

That filter can run on Google's servers whether anyone is signed in or not. The audit records used by InboxGuards do not expose user-created Gmail filter changes, so InboxGuards cannot detect the filter being created.

N°002sectionwhy it is outside inboxguards visibility

Section 02

Why it is outside InboxGuards visibility

InboxGuards uses supported records Google exposes through its Admin SDK Reports API, such as selected sign-in, forwarding, app-authorization, and administrative events.

The event records used by InboxGuards do not include user-created Gmail filter changes. Google may change editions, APIs, and event coverage, so evaluate current provider documentation and the exact data source a product uses.

N°003sectionwhy the blind spot is smaller than it sounds

Section 03

Why the blind spot is smaller than it sounds

A malicious filter can conceal mail and may appear alongside other compromise activity. Related activity does not always produce a record available to InboxGuards.

InboxGuards checks supported forwarding, app-grant, sign-in, and Google security-verdict records when Google exposes the required fields. Provider, edition, configuration, retention, and API limits still apply.

  • Supported Gmail forwarding event — checked and alerted when required fields are available
  • Supported third-party app grant — checked when Google exposes the event
  • Supported sign-in record — checked against configured location rules
  • Google's own "hijacked account" and "suspicious login" flags — surfaced after Google provides and InboxGuards processes the event
  • Repeated failed sign-ins followed by a success — the password-guessing signature, alerted as critical
N°004sectionwhat you can do about the filter itself

Section 04

What you can do about the filter itself

Review filters manually in Gmail: open Settings → See all settings → Filters and Blocked Addresses. Investigate any filter that deletes, archives, or marks mail as read when the account owner does not recognize it.

A relevant InboxGuards alert can be a reason for an authorized administrator to review filters, but the presence or absence of an alert does not prove whether a malicious filter exists.

N°005sectionwhy we're telling you this

Section 05

Why we're telling you this

InboxGuards is an alarm on configured supported signals, not an all-seeing shield. It does not guarantee visibility into every account change or incident.

On Google Workspace, InboxGuards checks supported forwarding, security-verdict, app-grant, password-guessing, and sign-in records. User-created Gmail filter rules remain outside its current data source and require separate review.

N°006faqcommon questions

FAQ

Common questions.

Can any monitoring service detect malicious Gmail filters?
InboxGuards cannot. The Google event records it currently uses do not expose user-created Gmail filter changes. Review filters manually in the user's Gmail settings and check current Google documentation for other authorized tools.
Does the Google Admin console show Gmail filters?
The audit records used by InboxGuards do not expose per-user Gmail filter changes. Availability in other Google administrative or investigation tools may depend on the current edition and product; consult Google's current documentation.
How would I know if my account had a malicious filter?
Possible symptoms include expected replies not appearing, conversations being archived, or mail showing as read. Review Gmail Settings → Filters and Blocked Addresses. A monitoring alert may justify that review, but related sign-in or forwarding activity may not be visible.
Is this different from Outlook's client-only rules?
They are different mechanisms with different visibility and execution behavior. Review the current Microsoft and Google documentation for the rule type and product edition you use.

Watch supported audit signals

$4 per user / month · 30-day money-back guarantee · Cancel anytime