Suspicious email forwarding rules can quietly copy business messages to an attacker. These rules may remain hidden while the attacker studies invoices, passwords, contracts, or conversations. This guide explains why attackers create them, where to inspect them, what evidence to preserve, and what else to secure.

Why attackers create forwarding rules
An attacker often wants continued access without logging in repeatedly. A mailbox rule can forward new messages, move them into an obscure folder, mark them as read, or delete selected alerts. That access can survive after the original phishing message disappears.
Forwarding also helps an attacker understand business processes. They may watch payment requests, vendor messages, password resets, customer complaints, or executive conversations. The information can support fraud even when the attacker never sends a message from the account.
Some rules target specific words or senders. For example, a rule might forward messages containing “invoice” while leaving ordinary mail alone. Other rules redirect mail outside the organization or move security notifications away from the inbox.
Not every unusual rule proves an attack. A legitimate integration, assistant, ticketing system, archive, or employee workflow may use forwarding. However, an unfamiliar destination, recent creation time, or rule that hides messages deserves prompt review.
Start with a safe response
Before changing the rule, decide whether the account may still be under attacker control. If the user clicked a suspicious link, entered a password, approved an unexpected sign-in, or noticed unfamiliar activity, treat the event seriously.
- Use a trusted device and a known-safe network for investigation.
- Record the time, user, mailbox, symptoms, and known suspicious messages.
- Do not click links or open attachments in the suspicious message.
- Ask the user to avoid deleting mail until evidence collection is complete.
- Notify the person responsible for business email and incident decisions.
Next, secure access through the identity provider. Reset the password from a trusted device, revoke active sessions, and review multifactor authentication methods. Remove unfamiliar recovery addresses, phone numbers, authenticator devices, and application consents.
These actions can change the evidence. Therefore, capture available details first when the risk is manageable. If the attacker appears active, containment takes priority over perfect documentation. Read this account compromise response guide for the broader recovery sequence. CISA provides practical guidance for recognizing and reporting phishing.
Where to inspect suspicious email forwarding rules
The exact menu names depend on the mail platform, subscription, and administrator permissions. Look in both the user mailbox and the organization’s administrative controls. A mailbox rule may exist even when the main email settings page looks normal.
Microsoft 365 and Outlook
Check Outlook on the web for rules, sweep settings, automatic replies, and forwarding preferences. Review inbox rules for actions such as forwarding, redirecting, deleting, moving, or marking messages as read.
An administrator should also inspect Exchange Online settings and audit records. Look for newly created rules, changes to mailbox forwarding, unusual sign-ins, consent grants, and changes to authentication methods. A tenant may have separate controls for external forwarding, so review both the mailbox and organization policy.
Google Workspace and Gmail
In Gmail, inspect filters and forwarding settings. Review filters that forward, archive, delete, skip the inbox, apply labels, or mark messages as read. Check whether an unfamiliar forwarding address was added and whether it was verified.
Administrators should review the Google Admin console for audit events, login activity, OAuth application access, and account recovery changes. Gmail can also contain delegated mailbox access. Confirm that delegates and third-party applications are expected.
Other mail systems
Hosted mail panels may expose forwarding under mailbox settings, aliases, filters, or autoresponders. Self-hosted systems can store rules in server-side filtering tools, webmail settings, or account configuration files.
Do not assume a desktop mail application shows every server-side rule. A rule that runs in the provider’s cloud can continue working when Outlook, Apple Mail, or another client is closed.
How to assess a rule
Review the rule’s name, creation or modification time, conditions, actions, and destination. Compare those details with the employee’s normal work. A rule that supports an approved workflow should have a clear owner and documented purpose.
- Destination: Is the address internal, approved, and controlled by the business?
- Scope: Does the rule affect all messages or sensitive subjects?
- Action: Does it forward, redirect, delete, archive, or hide mail?
- Timing: Did it appear near a suspicious login or reported phishing event?
- Ownership: Can a manager or system owner explain why it exists?
External forwarding is especially important because it can transmit confidential information outside normal controls. Still, an internal rule can also be harmful if it hides alerts or routes messages to an account the attacker controls.
Do not rely on the rule name. Attackers can use ordinary names such as “Archive,” “Receipts,” or “Notifications.” The conditions and actions matter more than the label.
What evidence to preserve
Preserve enough information to reconstruct what happened. Avoid collecting more personal content than the investigation requires. Access should follow the organization’s privacy and legal policies.
- Take screenshots showing the rule, destination, conditions, actions, and timestamps.
- Export rule details when the platform supports an administrator-friendly export.
- Record sign-in times, source locations, devices, and authentication results.
- Save audit events for rule creation, mailbox forwarding, password changes, and session revocation.
- Preserve the original suspicious message, including headers when possible.
- List messages that may have been forwarded, deleted, or exposed.
- Record every containment action, its time, and the person who performed it.
Keep original files unchanged. Work from copies when analysis requires opening or searching them. Store evidence in a restricted location and use consistent timestamps, including the time zone.
Mailbox logs vary by platform and license. Some providers may expire records or restrict them to administrators. A technician should verify available retention before assuming a complete history exists.
Remove the rule and close related access
After capturing appropriate evidence, remove the malicious rule or disable it according to the incident plan. Confirm that the external forwarding address, filter, alias, delegate, and application access no longer provide a path into the mailbox.
Then review active sessions and connected devices. Revoke sessions where the identity provider supports it. Reset the password again if someone changed it before all attacker access was removed. Require multifactor authentication, preferably with an approved method that the user and administrator can verify.
Check for mailbox permissions, delegated access, shared mailboxes, transport rules, and automatic replies. In Microsoft 365, tenant-level forwarding controls may need attention. In Google Workspace, administrators may need to review routing rules and third-party app access.
Do not simply delete every unfamiliar item without recording it. Deleting a rule can stop exposure, but it may also remove useful evidence. When the account handled sensitive data, involve an incident lead before broad cleanup.
Secure the wider business environment
A forwarding rule may be one symptom of a broader identity compromise. Review other accounts that share the same password, use the same recovery email, or received sensitive messages from the affected mailbox.
- Search sent mail, deleted items, drafts, and sign-in alerts for unauthorized activity.
- Contact financial institutions or vendors if payment instructions may have changed.
- Warn recipients about suspicious messages sent from the account.
- Review domain email authentication and forwarding policies.
- Check endpoint security on devices used to access the mailbox.
- Confirm that backups and important records remain available and protected.
A review of suspicious email forwarding rules should also include recovery planning. Confirm that critical records can be restored by following the organization’s backup testing process.
Email authentication helps reduce spoofing, but it does not remove a real attacker from a compromised mailbox. Review SPF, DKIM, and DMARC with the organization’s mail administrator. Microsoft’s email authentication overview explains how these controls work together.
Also review business processes. Require a second channel for bank-detail changes, unexpected payment requests, and urgent password resets. A technical control is stronger when staff know how to challenge unusual requests.
When to escalate the investigation
Escalate promptly when the rule forwarded confidential data, the attacker accessed a privileged account, multiple mailboxes show similar changes, or unauthorized messages went out. Escalation may involve management, legal counsel, cyber insurance contacts, a managed security provider, or law enforcement.
Preserve the timeline before making broad changes. Identify the first known suspicious event, the first unauthorized rule, affected messages, containment steps, and remaining uncertainty. This record supports recovery and helps prevent repeated mistakes.
After containment, document the approved mail settings and review them periodically. Alerting on external forwarding, unusual inbox rules, risky sign-ins, and authentication changes can shorten future investigations.
Final checklist
Use this short sequence when reviewing suspicious email forwarding rules:
- Work from a trusted device and record the initial facts.
- Inspect mailbox rules, filters, forwarding, delegates, and automatic replies.
- Review identity, sign-in, audit, and application-access records.
- Preserve rule details and relevant messages before cleanup when practical.
- Remove unauthorized access, revoke sessions, reset credentials, and verify MFA.
- Search for related mailbox, financial, endpoint, and domain activity.
- Document the timeline and monitor for recurrence.
Suspicious email forwarding rules can be straightforward to remove, but the surrounding investigation may require careful judgment. Tech Rescue Ops LLC can help review mailbox settings, preserve technical evidence, and coordinate a safe recovery plan when internal staff need assistance.
