Learn › Am I being tracked?

Is someone reading your email?

Last reviewed 2026-07-29

Why this is different from a weak password

Securing your accounts covers passwords, security questions, and two-factor authentication. This is about the quiet plumbing inside your mailbox that can keep someone reading your email long after you’ve changed your password and turned on every login protection you have. A forwarding rule, filter, or delegate doesn’t need your current password — it was set up once and keeps working silently until someone finds and removes it. Email is also a skeleton key: most other accounts use your email address to reset a forgotten password, so someone who can read your email can work their way into everything else tied to it.

An inbox checked for quiet forwarding rules

Before you touch any setting below, read Safety first: before you remove anything. Removing a forwarding rule or revoking a delegate may not send a notification — but the person may notice their access stops working, which can tip them off at a moment when that isn’t safe. The documentation for these features doesn’t say whether a notification is sent either way. Screenshot what you find first and think through timing before you act.

Auto-forwarding: the quietest leak

A forwarding rule silently copies your incoming mail to another address — including password-reset links and security codes — without changing how your inbox looks to you.

In Gmail: go to Settings → See all settings → the Forwarding and POP/IMAP tab. The Forwarding section shows whether a forwarding address is set up; if you find one you didn’t add, Google’s own instructions are to select Disable forwarding. Google’s guidance on suspicious activity says that if you think someone else is signed in, change your password first, then check for and remove any unfamiliar signed-in devices (Google Help).

In Outlook: forwarding and redirect rules live under Settings → Mail → Rules (new Outlook and Outlook on the web), or Rules in classic Outlook for Windows. Microsoft’s documentation notes a forwarded message shows the recipient it came from you, while a redirected message still shows the original sender — so a redirect rule is easier to miss. Copies of anything forwarded or redirected still land in your own mailbox too.

Filters that forward, delete, or archive on arrival

A filter can do quietly what a forwarding rule does more visibly — send a copy of specific mail elsewhere, or make messages disappear the moment they arrive.

In Gmail, filters live under Settings → See all settingsFilters and Blocked Addresses. Google’s help page walks through finding, editing, or deleting any filter you didn’t create — look for ones that forward, delete, or skip the inbox for mail from your bank, lawyer, or password-reset addresses. In Outlook, the same review happens in Settings → Mail → Rules, since Outlook combines Gmail’s separate “filters” and “forwarding” into one rules list (Microsoft Support).

Delegates and shared mailbox access

A delegate is someone granted standing permission to read, send, and manage your email from their own account — no password needed.

In Gmail, delegates are added and removed under Settings → See all settings → the Accounts and Import tab, in “Grant access to your account.” Google’s documentation states plainly what a delegate can do — read, send, and delete messages, with their address showing when they send on your behalf — and what they can’t: chat as you, or change your password. To remove one, open that tab and click Delete next to the account; the documentation doesn’t say how quickly that takes effect.

Outlook’s delegate access works differently: Microsoft’s documentation states “Delegate access is only available if you’re using a work or school account in Microsoft 365 or with Exchange Online” — personal Outlook.com accounts lack this feature. Permissions range from Reviewer (read only) to Editor (read, create, change, delete); reviewing access typically means checking mailbox permissions with your administrator.

Connected apps and mail scopes

Third-party apps you’ve signed into with your Google account can be granted specific data access, potentially including your mail. Google’s documentation on sharing account access states linked apps “can only access the data and services that you authorize them to” — which can include Gmail, Drive, Calendar, Photos, and Contacts — and you can review or remove a linked app’s access at any time. Go through this list periodically and remove anything you don’t recognize.

App passwords: the legacy backdoor

An app password is a 16-digit code that lets an older app or device sign in without your regular password or a second-factor prompt. Google’s documentation is direct about their status: app passwords aren’t recommended and are unnecessary in most cases, since modern apps should use “Sign in with Google” instead. If one exists you don’t remember creating, open your App Passwords list, find it, and select Remove — after which that app “can’t access your Google Account again.” Google also states app passwords “are revoked when you change your Google Account password,” so a password change is itself a way to cut off this path.

Checking who’s actually signed in

Sessions and devices are a different audit — live sign-ins, not standing permissions. Google’s Security Checkup lets you review signed-in devices and remove any you don’t recognize, alongside recovery info and linked apps in one place. For Microsoft accounts, the Recent activity page shows when and where your account has been used over roughly the last 30 days, including device or browser type; if anything in “Unusual activity” wasn’t you, select This wasn’t me. Our advice: treat an empty activity list as inconclusive, not reassuring — Microsoft’s page doesn’t say how far back “Unusual activity” flags reach, so an empty list may just mean nothing was flagged, not that nothing happened.

Recovery chains: who resets your email

Your email recovers to a phone number or a second email address — if either belongs to someone else, they can reset your password and lock you out entirely. Google’s recovery-info documentation explains recovery contacts can send you a code to get back in, but also “block someone from using your account without your permission” — which only works if the contact is actually yours. Review yours under your account’s sign-in and security settings, confirm you control every one listed, and remove anything you don’t. Google notes changing recovery info may send verification codes to the old info for seven days, so don’t panic if you see an unfamiliar alert right after a legitimate change.

What tracking pixels and read receipts actually reveal

A tracking pixel is a tiny, often invisible image embedded in an email; when your mail app loads it, the sender’s server logs that the image was requested — usually meaning you opened the message. This differs from a read receipt, an explicit, visible request the sender attaches and which you can decline.

Gmail loads images automatically by default, but Google’s own documentation says Google scans images for suspicious content before you receive them, and separately states senders “can’t use image loading to get information about your computer or location” and can’t use images to set or read cookies — that protection is from Gmail’s own image proxy, not the malware scan. Google’s page also notes senders may still learn whether you’ve opened a message. Switch to Ask before displaying external images under Settings → See all settings → Images to stop images loading until you choose to view them.

Outlook’s default depends on which version you’re using — don’t assume one behavior across both. Classic Outlook for Windows blocks pictures by default: Microsoft’s page for classic Outlook states “Microsoft Outlook is configured by default to block automatic picture downloads from the Internet,” listing “Helping you avoid tracking pixels: invisible images that can tell a sender you’ve read the email” as a benefit. New Outlook and Outlook.com work differently: Microsoft’s page for those clients states images are “always downloaded automatically unless you (or your IT administrator) have enabled the Block external images setting.” Outlook.com’s default instead proxies images rather than blocking them: per Microsoft’s page on external image protection, with Always use the Outlook service to load images selected, images load through that proxy instead of directly from the sender, but still display automatically. To actually block images until you choose to view them on new Outlook or Outlook.com, turn on Block external images — the classic-Outlook default doesn’t apply there.

For read receipts, Microsoft notes a recipient can always decline to send one, with no way for a sender to force it. If a specific sender knowing you’ve opened their messages worries you, check which Outlook client and image setting you actually have rather than assuming images are blocked, and decline read receipts to close that second channel.

After the audit

None of this tells you how something got set up, only that it’s there. A forwarding rule could be years-old and forgotten, or new and deliberate — the audit doesn’t distinguish. Work through each path in order: forwarding, filters, delegates, connected apps, app passwords, sessions, recovery info.