How to find external forwarding and suspicious inbox rules

Attackers who get into a mailbox often add a rule that forwards mail outside or moves replies out of sight. Finding those rules early stops payment fraud.

Updated October 4, 2026

What to look for

  • Mailbox forwarding set to an outside address
  • Inbox rules that forward or redirect to outside addresses
  • Rules that move messages to RSS Feeds, Archive or Deleted Items, or mark them as read
  • Rules with names like a single dot or random characters
  • Rules that match words like invoice, payment, bank or wire

Using PowerShell

Connect-ExchangeOnline
# Mailbox-level forwarding
Get-Mailbox -ResultSize Unlimited | Where-Object { $_.ForwardingSmtpAddress -or $_.ForwardingAddress } |
  Select-Object UserPrincipalName, ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward
# Inbox rules that forward or redirect
Get-Mailbox -ResultSize Unlimited | ForEach-Object {
  Get-InboxRule -Mailbox $_.UserPrincipalName | Where-Object { $_.ForwardTo -or $_.RedirectTo -or $_.ForwardAsAttachmentTo } |
    Select-Object MailboxOwnerId, Name, ForwardTo, RedirectTo
}

Block it at the policy level

Outbound spam policies in Microsoft 365 can turn off automatic external forwarding for everyone, with exceptions for the few people who need it.

Doing it with TenantWard

The forwarding report lists every mailbox and rule that sends mail outside, with a button to remove it. 24/7 monitoring alerts you within 15 minutes when a new one appears, and can disable it automatically.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.