Overview

An email forwarding rule that the user did not create can be a sign of account compromise. Preserve evidence and treat the situation as a security incident rather than simply deleting the rule and moving on.

Possible account compromiseIf mail is being forwarded to an unknown external address, stop normal troubleshooting and escalate promptly. Unauthorized forwarding is a common persistence technique after mailbox compromise.

Why this happens

Attackers who gain mailbox access may create inbox rules or forwarding settings to copy messages, hide security notices, intercept password resets, or monitor business communications. Legitimate automation can also create forwarding, so the rule must be verified before conclusions are drawn.

Before you begin

  • Do not approve unexpected MFA prompts.
  • Capture screenshots of the rule before changing it.
  • Record the forwarding address and rule conditions.
  • Do not delete audit evidence or sign-in information.

Click-by-click troubleshooting

Step 1: Preserve the suspicious rule details

Action: In Outlook on the web, open Settings > Mail > Rules. Capture the rule name, conditions, actions, forwarding address, and whether it is enabled.

Why this matters: The rule itself is evidence that may help determine what the attacker was attempting to capture or hide.

What to look for: Look for external forwarding addresses, rules that delete messages, move security alerts, or hide replies.

Expected result: You should have a clear record of the rule before any remediation.

Step 2: Check mailbox forwarding settings

Action: Open Settings > Mail > Forwarding and record whether automatic forwarding is enabled and to what address.

Why this matters: Attackers can use mailbox-level forwarding even when no inbox rule is visible.

What to look for: Look for an external address the user or organization does not recognize.

Expected result: You should know whether unauthorized forwarding exists in one or both locations.

Step 3: Verify whether the user or administrator created the rule

Action: Ask the mailbox owner and authorized administrators whether the forwarding is expected. Do not rely only on the display name of the destination address.

Why this matters: Legitimate business workflows can use forwarding, but unknown forwarding requires security escalation.

What to look for: Confirm whether there is an approved business purpose and change record.

Expected result: The rule should be classified as authorized or suspicious.

Step 4: Secure the account using the approved incident process

Action: If the forwarding is unauthorized, contact IT immediately. An authorized administrator should follow the organization's account-compromise process, which may include password reset, session revocation, MFA review, and sign-in investigation.

Why this matters: Removing the rule alone does not remove an attacker who still has active credentials or sessions.

What to look for: Look for recent unfamiliar sign-ins, changed MFA methods, repeated prompts, or other mailbox changes.

Expected result: The account should be secured through a complete compromise-response process, not a single-rule deletion.

Step 5: Remove unauthorized forwarding only after evidence is preserved

Action: After IT confirms evidence is captured, disable or remove the unauthorized rule and forwarding setting using the approved response process.

Why this matters: This stops additional messages from being redirected while preserving investigative context.

What to look for: Confirm no other unexpected rules or forwarding destinations remain.

Expected result: Unauthorized redirection should be removed without destroying the evidence needed for investigation.

Step 6: Review for related mailbox compromise indicators

Action: Check Sent Items, Deleted Items, inbox rules, unusual replies, and security notifications. Authorized administrators should review sign-in logs and audit data.

Why this matters: Forwarding rules are often only one symptom of a compromised mailbox.

What to look for: Look for messages the user did not send, deleted security notifications, unfamiliar sign-in locations, or changes to MFA methods.

Expected result: The investigation should establish whether the forwarding was isolated or part of broader account compromise.

What to look for

  • Unknown external forwarding address is a strong compromise indicator.
  • Rules that hide replies or security mail are especially concerning.
  • Unexpected MFA or unfamiliar sign-ins strengthen the compromise assessment.
  • Deleting only the rule is not sufficient incident response.

When to stop

Treat unauthorized forwarding as a security incidentDo not continue ordinary troubleshooting, erase audit history, communicate sensitive incident details through the suspected mailbox, or assume the account is safe after deleting the rule.

When to contact IT

Contact J3 Systems Group immediately if the rule or forwarding address is unauthorized or cannot be explained. Include article code KB-05.012, screenshots, destination address, approximate discovery time, and any suspicious sign-in or MFA information.

Need help with this issue?

J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.

Contact J3 Systems Group

Authoritative references

Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.

Article KB-05.012 · Review after material vendor, licensing, interface, security, or service changes.