CrossTenant
Home / Guides / Gmail forwarding audit

Auditing Gmail forwarding across an organisation

Forwarding is what survives a clean-up: no session to keep alive, no password to defend, just a quiet copy of new mail leaving the organisation. Here is how to find the rules that should not exist.

Why forwarding is the quiet-compromise signal

Most clean-ups focus on the session: reset the password, sign the account out everywhere, revoke the suspicious app. Forwarding is the thing that does not need a session. An attacker who cannot keep a login can keep a forward: one rule, set in a quiet moment, and new mail keeps arriving somewhere it should not for as long as nobody looks.

Leavers are the other half of the problem. A departing employee who adds a forward to a personal address before handing back the laptop keeps reading whatever still lands in that mailbox, and mailboxes are often kept receiving mail for months for exactly that continuity reason. Treat forwarding as a standing audit target, not a one-off incident check: it is cheap to review, and it is where quiet compromise likes to live.

What to look for

Five things, in descending order of alarm:

  • Auto-forwarding to an address outside the customer's domain. This is the headline finding. Internal forwards are usually workflow; external ones need a named reason, a named owner and a date.
  • Forwarding added recently. A rule that has existed for years and is documented is probably fine. A rule that appeared in the last few weeks, on an account that had a password reset or an odd sign-in around the same time, is a lead worth pulling.
  • Filters that forward selectively. A filter that forwards only messages mentioning invoices, payments or a particular sender is harder to spot than a blanket forward and usually more deliberate. Read the conditions, not just the destination.
  • Delegates you cannot explain. Delegation gives another account ongoing access to the mailbox. Every delegate should be explainable in one sentence by the customer; treat any that is not as a finding.
  • Send-as addresses for people who left. A stale send-as entry lets someone write mail that appears to come from a person who no longer works there. Check the list against the current staff roster, not against memory.

How to run it manually

You can run this audit by hand, mailbox by mailbox, with patience. For each one, record four things: the forwarding destination if one is set, every filter that forwards or redirects, the delegate list, and the send-as list. Note the mailbox, the rule, the destination and whether anyone can explain it. Decide before you start what counts as a finding, so you are not making judgement calls mailbox by mailbox.

This works for a handful of mailboxes. It stops working at the first customer with fifty: per-mailbox checking is slow, error-prone and dull enough that it gets skipped, and across a book of customers it becomes a week of clicking. Worse, the result goes stale the day after you finish: a rule added on Tuesday is invisible to Monday's audit. A manual sweep proves the past, not the present, so if you audit by hand, put the next sweep in the diary before you close this one.

What to do with findings

  1. Confirm with the customer before removing anything. Some external forwards are legitimate: a director routing mail to another business they own, a shared mailbox feeding a supplier's ticket system. Put each finding to the customer, get a yes or a no in writing, and record who answered.
  2. Remove the rule, then check what else that account changed. A malicious forward is rarely the only change. On the same account, review filters, delegates, send-as entries, recovery details and recent sign-in activity, and if compromise looks likely, treat it as an incident: reset credentials, end the sessions, and widen the review to whatever that account had access to.
  3. Re-check on a schedule. Forwarding audits age badly. Agree an interval with the customer, put it in the calendar, and compare each sweep against the last one so new rules stand out instead of hiding in the noise.

One external forward is a reason to look harder at that account, not a reason to stop. The rule you found is the one that was easy to find; the interesting question is what else changed around the same time.

If the account belongs to a leaver, fold this into a proper offboarding rather than treating it as a one-off: the offboarding checklist covers forwarding alongside sessions, mail and data handover.

How CrossTenant helps

CrossTenant runs this audit as one sweep: every mailbox in every customer tenant on a single page, with forwarding destinations outside the customer's domain flagged, and delegate and send-as audits alongside. Remediation (disabling external auto-forwarding, removing delegates) sits behind a dry-run preview and an explicit confirmation, and every change lands in a per-tenant audit log. Scan reporting is honest by design: a mailbox that could not be read counts as failed, and a partial scan is labelled partial rather than presented as clean. See auditing mailbox exposure for the workflow, or mail governance for the full feature detail. Deep mail governance is part of the Complete tier: see pricing. CrossTenant is in early access.

Field guides

Run the sweep against your whole book

One sweep covers every mailbox in every tenant you manage, and a mailbox that could not be read counts as failed, never as clean. Book a demo to see the fleet sweep, then run it read-only first.