OnlineV Insight

How To Spot Risky Email Forwarding Rules in Microsoft 365

Risky forwarding rules can quietly send business email outside the company. Learn what to inspect in Microsoft 365, when to treat a rule as suspicious, and how to respond.

To spot risky email forwarding rules in Microsoft 365, review mailbox forwarding, inbox rules, transport rules, delegates, and recent sign-in activity for any account sending mail to unexpected external addresses. A risky rule often hides messages, forwards invoices or password resets, uses unfamiliar domains, or appears after a suspicious sign-in.

Forwarding is not always malicious. Staff may forward mail during leave, route messages to a shared mailbox, or support a business workflow. The risk is silent forwarding that exposes client communication, invoices, password resets, legal documents, or internal approvals without the business noticing.

Why Forwarding Rules Matter

Email is the reset point for many systems. If an attacker controls forwarding, they may keep reading messages even after the visible password issue is fixed. They may also hide replies, delete warnings, or monitor payment discussions before sending a fraud attempt.

In Microsoft 365, forwarding can exist in more than one place. A review that only checks a user-visible Outlook rule may miss mailbox-level forwarding, administrator-created rules, delegated access, or transport rules. That is why the review should include both the mailbox and tenant-level configuration.

What To Inspect In Microsoft 365

  • Mailbox forwarding addresses configured on the user mailbox.
  • Inbox rules that forward, redirect, delete, mark as read, move, or hide messages.
  • Rules with vague names, no clear business purpose, or unfamiliar external domains.
  • Delegates and mailbox permissions that allow another account to read or send mail.
  • Transport rules that redirect messages outside the organization.
  • Recent sign-ins, impossible travel indicators, MFA changes, and new devices.
  • Audit logs showing rule creation, modification, and administrator activity.

Finance, ownership, administrator, HR, and shared mailboxes deserve extra attention because they often receive sensitive messages and payment information.

Business Scenario: Quiet Monitoring Before Invoice Fraud

A project coordinator reports that a client paid an invoice to the wrong account. The finance mailbox has an inbox rule that forwards messages containing the words invoice, wire, payment, and banking to an external address. Another rule moves replies from that client into an archive folder and marks them as read. The finance user did not create either rule.

The response should treat this as an account compromise, not just a bad setting. The business needs to disable the forwarding, preserve evidence, reset credentials, revoke sessions, review MFA methods, check delegates, look for similar rules in other mailboxes, and verify client communication outside email. Removing the rule without investigation may leave the attacker with another path back in.

Review Checklist For Forwarding Rules

  • List all mailboxes with external forwarding enabled.
  • Confirm who requested each rule and what business process it supports.
  • Check whether the forwarding address belongs to an approved vendor or employee-controlled account.
  • Look for rules that delete, hide, move, or mark messages as read.
  • Review high-risk keywords such as invoice, payment, banking, payroll, password, reset, and MFA.
  • Check sign-in history around the time each suspicious rule was created.
  • Disable or block external forwarding where it is not required.
  • Record exceptions with the business reason and review date.

Common Mistakes When Cleaning Up Rules

  • Deleting the rule before capturing screenshots, audit logs, and timestamps.
  • Resetting the password but forgetting to revoke active sessions.
  • Checking only the affected mailbox and missing similar rules in other accounts.
  • Leaving legacy forwarding in place because nobody wants to ask why it exists.
  • Assuming MFA is fine without checking whether new MFA methods were added.

Use caution with legitimate exceptions. Some businesses forward mail to ticketing systems, compliance archives, CRM tools, or external service desks. Those rules should be documented, scoped to the right mailbox, and approved by someone who understands the data being sent. A legitimate business rule can still be risky if it forwards more mail than intended.

After removing a suspicious rule, review whether the attacker may have read enough information to attempt fraud later. They may know invoice timing, client names, internal writing style, or approval habits. That is why finance and customer-facing teams should be told what to watch for after the technical cleanup is complete.

Microsoft 365 reviews should also include alerting. If external forwarding is allowed for a real reason, create a monitoring habit around it. A monthly report of external forwarding, new inbox rules, and high-risk mailbox changes can catch quiet drift before it becomes a client-facing problem.

Finally, decide who is allowed to approve new forwarding. If staff can create external forwarding without review, the business may not notice when data starts leaving the tenant. A simple approval rule for external forwarding keeps legitimate workflows possible while making unusual rules easier to spot.

Next Step: Review High-Risk Mailboxes First

Start with finance, ownership, HR, administrator, and shared mailboxes. Export or list forwarding rules, remove what is not approved, and treat suspicious rules as potential evidence of compromise. OnlineV provides cybersecurity support for Microsoft 365 email risk reviews. Related pages: cloud management, managed IT services, and cybersecurity insights.

Sources and further reading

Need Help Reducing Risk?

Separate urgent security gaps from noise

OnlineV can help review MFA, admin access, email risk, devices, backups, and offboarding so the next step is clear and realistic for your business.

Cybersecurity Assessment Cybersecurity Services
Book a Free IT & AI Review View Cybersecurity Services

Continue Reading

Three useful guides on this topic

What To Review After an Employee Leaves the Company Employee departures create security risk when access, devices, MFA, and shared credentials are not reviewed together. This checklist... What Small Businesses Should Know About Cyber Insurance Requirements Cyber insurance applications often expose weak security evidence. This guide helps small businesses prepare honest answers, close common... How To Build a Simple Incident Response Plan for a Small Business A simple incident response plan gives staff clear first-hour actions, contact paths, and recovery order before a breach...