OnlineV Insight

How To Spot Risky Email Forwarding Rules in Microsoft 365

Review risky Microsoft 365 forwarding rules by identifying business need, external destinations, mailbox ownership, and unexpected changes before an.

Forwarding rules deserve attention because they can move sensitive conversations outside normal oversight. Review legitimate business use, external destinations, shared mailbox rules, and unfamiliar changes.

Why this deserves a focused review

Legitimate forwarding is sometimes used for shared reception, workflow routing, or a third-party service. The point of review is to ensure each exception has a reason, an owner, and a destination that remains appropriate.

Scenario

A compromised account creates an inbox rule that forwards finance messages to an outside address and hides them from the inbox. The faster the rule is found, the sooner the business can investigate scope.

Review sequence

01. Review inbox and transport rules for external forwarding.

02. Confirm a business owner for each legitimate exception.

03. Check recent sign-ins and mailbox changes when something looks unusual.

04. Remove unexplained or obsolete rules.

05. Document the incident path if compromise is suspected.

Useful record

When a rule is suspicious, avoid treating it as a simple housekeeping item. Consider the possibility of account compromise and coordinate the review of sign-ins, recovery methods, affected messages, and other access changes.

  • Review inbox and transport rules for external forwarding.
  • Confirm a business owner for each legitimate exception.
  • Check recent sign-ins and mailbox changes when something looks unusual.
  • Remove unexplained or obsolete rules.
  • Document the incident path if compromise is suspected.

Common mistake

Deleting a suspicious rule and assuming the event is over. Preserve relevant evidence and review the account, recipients, and related sign-ins.

Practical next step

Follow the organization’s incident process and retain the records needed for any internal, insurer, legal, or privacy follow-up. OnlineV can help apply this through the relevant service. Continue with email security basics microsoft 365 small business, what to do if business email account is compromised, microsoft 365 security settings small businesses should review.

Detailed guidance

To spot risky email forwarding rules in Microsoft 365, review mailbox forwarding, inbox rules, transport rules, delegates, and recent sign-in activity for any account sending mail to unexpected external addresses. A risky rule often hides messages, forwards invoices or password resets, uses unfamiliar domains, or appears after a suspicious sign-in.

Forwarding is not always malicious. Staff may forward mail during leave, route messages to a shared mailbox, or support a business workflow. The risk is silent forwarding that exposes client communication, invoices, password resets, legal documents, or internal approvals without the business noticing.

Email is the reset point for many systems. If an attacker controls forwarding, they may keep reading messages even after the visible password issue is fixed. They may also hide replies, delete warnings, or monitor payment discussions before sending a fraud attempt.

In Microsoft 365, forwarding can exist in more than one place. A review that only checks a user-visible Outlook rule may miss mailbox-level forwarding, administrator-created rules, delegated access, or transport rules. That is why the review should include both the mailbox and tenant-level configuration.

Finance, ownership, administrator, HR, and shared mailboxes deserve extra attention because they often receive sensitive messages and payment information.

A project coordinator reports that a client paid an invoice to the wrong account. The finance mailbox has an inbox rule that forwards messages containing the words invoice, wire, payment, and banking to an external address. Another rule moves replies from that client into an archive folder and marks them as read. The finance user did not create either rule.

The response should treat this as an account compromise, not just a bad setting. The business needs to disable the forwarding, preserve evidence, reset credentials, revoke sessions, review MFA methods, check delegates, look for similar rules in other mailboxes, and verify client communication outside email. Removing the rule without investigation may leave the attacker with another path back in.

Use caution with legitimate exceptions. Some businesses forward mail to ticketing systems, compliance archives, CRM tools, or external service desks. Those rules should be documented, scoped to the right mailbox, and approved by someone who understands the data being sent. A legitimate business rule can still be risky if it forwards more mail than intended.

After removing a suspicious rule, review whether the attacker may have read enough information to attempt fraud later. They may know invoice timing, client names, internal writing style, or approval habits. That is why finance and customer-facing teams should be told what to watch for after the technical cleanup is complete.

Microsoft 365 reviews should also include alerting. If external forwarding is allowed for a real reason, create a monitoring habit around it. A monthly report of external forwarding, new inbox rules, and high-risk mailbox changes can catch quiet drift before it becomes a client-facing problem.

Finally, decide who is allowed to approve new forwarding. If staff can create external forwarding without review, the business may not notice when data starts leaving the tenant. A simple approval rule for external forwarding keeps legitimate workflows possible while making unusual rules easier to spot.

Start with finance, ownership, HR, administrator, and shared mailboxes. Export or list forwarding rules, remove what is not approved, and treat suspicious rules as potential evidence of compromise. OnlineV provides cybersecurity support for Microsoft 365 email risk reviews. Related pages: cloud management, managed IT services, and cybersecurity insights.

Sources and further reading

Need Help Reducing Risk?

Separate urgent security gaps from noise

OnlineV can help review MFA, admin access, email risk, devices, backups, and offboarding so the next step is clear and realistic for your business.

Cybersecurity Assessment Cybersecurity Services
Book a Free IT & AI Review View Cybersecurity Services

Continue Reading

Three useful guides on this topic

What To Review After an Employee Leaves the Company After an employee leaves the company, review every place they could still access business systems: Microsoft 365, email,... What Small Businesses Should Know About Cyber Insurance Requirements Prepare for cyber-insurance questions by documenting actual controls and gaps, without treating a checklist as a promise of... How To Build a Simple Incident Response Plan for a Small Business A simple incident response plan for a small business should explain who makes decisions, who to contact, what...