What to look for
- Mailbox forwarding set to an outside address
- Inbox rules that forward or redirect to outside addresses
- Rules that move messages to RSS Feeds, Archive or Deleted Items, or mark them as read
- Rules with names like a single dot or random characters
- Rules that match words like invoice, payment, bank or wire
Using PowerShell
Connect-ExchangeOnline
# Mailbox-level forwarding
Get-Mailbox -ResultSize Unlimited | Where-Object { $_.ForwardingSmtpAddress -or $_.ForwardingAddress } |
Select-Object UserPrincipalName, ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward
# Inbox rules that forward or redirect
Get-Mailbox -ResultSize Unlimited | ForEach-Object {
Get-InboxRule -Mailbox $_.UserPrincipalName | Where-Object { $_.ForwardTo -or $_.RedirectTo -or $_.ForwardAsAttachmentTo } |
Select-Object MailboxOwnerId, Name, ForwardTo, RedirectTo
}Block it at the policy level
Outbound spam policies in Microsoft 365 can turn off automatic external forwarding for everyone, with exceptions for the few people who need it.
Doing it with TenantWard
The forwarding report lists every mailbox and rule that sends mail outside, with a button to remove it. 24/7 monitoring alerts you within 15 minutes when a new one appears, and can disable it automatically.
See where your company stands
Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.