Gmail-এ “You are forwarding your email” notice দেখলেন, অথচ আপনি কোনো forwarding address যোগ করেননি—এটি cosmetic inbox problem নয়। কেউ account access পেলে password reset, invoice বা security alert-এর copy নিজের address-এ পাঠাতে forwarding ও filter rule তৈরি করতে পারে। শুধু notice dismiss বা rule off করলে incident শেষ হয় না; active session, recovery method, app access এবং incoming-mail settings review করতে হয়। আবার office admin বা আপনার পুরোনো setup legitimate forwarding করে থাকতে পারে, তাই evidence না দেখে accusation করবেন না। Safe device ও official account path থেকে controlled response নিন এবং suspicious changes-এর record রাখুন।
Notice-এর link নয়, official settings খুলুন
Alert email বা popup phishing-ও হতে পারে। Message-এর link click না করে Gmail app, saved bookmark বা নিজে লেখা `myaccount.google.com` path দিয়ে account খুলুন। URL, signed-in profile এবং device trusted কি না দেখুন। Shared বা public computer হলে sensitive recovery কাজ করবেন না। Gmail Settings-এর Forwarding and POP/IMAP section-এ actual status দেখুন। Google-এর official automatic forwarding guidance বলছে অচেনা forwarding notice দেখলে password অবিলম্বে বদলাতে এবং Settings থেকে forwarding বন্ধ করতে। আগে destination address ও timestamp screenshot নিলে incident record থাকে।
Forwarding এবং filter দুটোই review করুন
Global forwarding off থাকলেও specific filter matching mail বাইরে পাঠাতে পারে। Filters and Blocked Addresses-এ “forward it”, “delete it”, “skip inbox”, “mark as read” বা security sender match করে এমন unfamiliar rule খুঁজুন। Rule name harmless হলেও criteria খুলে দেখুন। Bank, password reset, invoice বা verification code keyword target হলে risk বেশি। নিজের পুরোনো automation হলে destination owner এবং business need reconfirm করুন। Suspicious rule-এর screenshot নিয়ে তারপর disable/remove করুন। Filter delete করার আগে affected messages কোথায় গেছে search করুন। Trash, Archive, Spam ও Sent folders check করুন; attacker evidence hide করতে labels বা deletion rule ব্যবহার করতে পারে।
Password clean device থেকে বদলান
Forwarding কে তৈরি করেছে না জানলে current password compromised ধরে response নিন। Updated device ও trusted network থেকে long unique password set করুন; অন্য account-এ একই password থাকলে সেগুলিও আলাদা করুন। Email inbox অনেক service-এর reset hub, তাই আগে Gmail secure করা logical। Unknown browser extension বা malware suspicion থাকলে শুধু password change যথেষ্ট নয়; device security scan ও trusted technical help লাগতে পারে। Password field কোনো support caller-এর সঙ্গে share করবেন না। Recovery চলাকালীন পাওয়া OTP, backup code বা approval prompt কাউকে দেবেন না।
Active sessions, devices ও recovery methods দেখুন
Google Account Security-তে recent devices এবং sessions review করুন। Location label approximate হতে পারে, তাই device model, browser এবং activity time একসঙ্গে দেখুন। Unknown session sign out করুন এবং নিজের পুরোনো lost/sold device-ও remove করুন। Recovery phone, recovery email, passkey এবং 2-Step Verification method-এ অচেনা entry আছে কি না দেখুন। Attacker নিজের recovery method যোগ করলে password বদলের পরে আবার ঢুকতে পারে। Google-এর suspicious account activity guidance automatic forwarding, filters, outgoing address, POP/IMAP ও unfamiliar devices-কে review করতে বলে। Change log থাকলে timestamps লিখে রাখুন।
Delegation, POP/IMAP ও app access বাদ দেবেন না
Gmail delegation অন্য account-কে mailbox পড়া বা message পাঠানোর access দিতে পারে। Accounts section-এ delegates ও “send mail as” addresses review করুন। POP/IMAP legitimate desktop client-এর জন্য on থাকতে পারে; আপনি ব্যবহার না করলে unexpected enablement investigate করুন। App passwords, OAuth-connected mail clients এবং third-party automation আলাদা access path। Unknown app revoke করুন, কিন্তু business workflow break হতে পারে বলে known integration owner-এর সঙ্গে confirm করুন। Forwarding remove করেও malicious session active থাকলে rule আবার তৈরি হতে পারে। তাই settings, identity ও device—তিন layer একসঙ্গে secure না করা পর্যন্ত incident closed বলবেন না।
Missing mail ও external account damage খুঁজুন
Important senders-এর recent messages search করুন: password reset, new sign-in, payment, order, payroll, domain registrar এবং cloud storage alerts। “No longer receive emails” বা Sent folder-এ নিজের লেখা নয় এমন message suspicious signal। Forwarding period জানা গেলে সেই date range focus করুন। Bank বা business system-এ change দেখা গেলে email-এর phone number নয়, known official channel দিয়ে provider contact করুন। Work account হলে internal security/admin team-কে দ্রুত জানান; audit logs personal UI-এর বাইরে থাকতে পারে। Suspicious message bulk delete করার আগে evidence preserve করুন। Actual financial loss বা identity misuse হলে applicable provider এবং local authority guidance নিন।
Mailbox compromise response checklist
- Trusted path: Official app/bookmark থেকে correct account খোলা।
- Rules: Global forwarding ও specific filters reviewed।
- Password: Clean device থেকে unique credential set।
- Sessions: Unknown devices signed out এবং old devices removed।
- Recovery: Phone, email, passkey ও 2-Step methods checked।
- Access: Delegates, POP/IMAP, app passwords ও OAuth reviewed।
- Impact: Missing mail, sent mail ও linked accounts investigated।
Recovery-এর পরে কয়েকদিন monitor করুন
সব change করার পরে forwarding page ও filters আবার খুলে confirm করুন। নতুন security alert, unknown login বা rule reappearance নজরে রাখুন। Trusted contact-কে আপনার address থেকে unusual mail পেয়েছেন কি না জিজ্ঞেস করতে পারেন। Business mailbox হলে admin audit এবং outbound log review শেষ না হওয়া পর্যন্ত monitoring চালান। Incident date, discovered rule, actions এবং provider case number লিখে রাখুন। Password change একমাত্র fix নয়; persistent access path সরানো, affected external account check করা এবং recovery settings নিজের control-এ ফেরানোই complete response।
দ্রুত উত্তর
সাধারণ প্রশ্ন ও উত্তর
Forwarding notice দেখলেই কি account hacked?
নিজে বা authorized admin rule করলে legitimate হতে পারে। আপনি না-করে থাকলে এটিকে serious warning ধরে official settings ও security activity review করুন।
শুধু forwarding off করলেই হবে?
না। Password, active sessions, recovery methods, filters, delegates, app access এবং POP/IMAP review না করলে অন্য access path থেকে যেতে পারে।
Suspicious email-এর link দিয়ে password বদলাব?
না। Saved app, bookmark বা নিজে লেখা official account URL দিয়ে security settings খুলুন; alert message-এর link বা phone number এড়িয়ে চলুন।