User-created Gmail filter changes are outside the audit data InboxGuards currently uses. Here is the boundary and the separate manual review to perform.
Section 01
Here's a real scenario. An attacker gets into a Gmail account — a phished password, a reused one from a breach. They don't forward anything. They don't download anything. They create one Gmail filter: "if a message contains the word invoice, delete it." Or subtler: "mark replies from this vendor as read and archive them."
That filter can run on Google's servers whether anyone is signed in or not. The audit records used by InboxGuards do not expose user-created Gmail filter changes, so InboxGuards cannot detect the filter being created.
Section 02
InboxGuards uses supported records Google exposes through its Admin SDK Reports API, such as selected sign-in, forwarding, app-authorization, and administrative events.
The event records used by InboxGuards do not include user-created Gmail filter changes. Google may change editions, APIs, and event coverage, so evaluate current provider documentation and the exact data source a product uses.
Section 03
A malicious filter can conceal mail and may appear alongside other compromise activity. Related activity does not always produce a record available to InboxGuards.
InboxGuards checks supported forwarding, app-grant, sign-in, and Google security-verdict records when Google exposes the required fields. Provider, edition, configuration, retention, and API limits still apply.
Section 04
Review filters manually in Gmail: open Settings → See all settings → Filters and Blocked Addresses. Investigate any filter that deletes, archives, or marks mail as read when the account owner does not recognize it.
A relevant InboxGuards alert can be a reason for an authorized administrator to review filters, but the presence or absence of an alert does not prove whether a malicious filter exists.
Section 05
InboxGuards is an alarm on configured supported signals, not an all-seeing shield. It does not guarantee visibility into every account change or incident.
On Google Workspace, InboxGuards checks supported forwarding, security-verdict, app-grant, password-guessing, and sign-in records. User-created Gmail filter rules remain outside its current data source and require separate review.
FAQ
$4 per user / month · 30-day money-back guarantee · Cancel anytime