Is Someone Secretly Forwarding Your Company Email? How to Check Microsoft 365

Is Someone Secretly Forwarding Your Company Email? How to Check Microsoft 365

Is Someone Secretly Forwarding Your Company Email? How to Check Microsoft 365

Deon M.
Deon M.

5 Minute Read

undefined Minute Read

If a company mailbox has been compromised, changing the password is important, but it may not remove everything the attacker changed.

An attacker can create an inbox rule or automatic forwarding setting that quietly sends copies of incoming email somewhere else. That could include invoices, password-reset messages, customer conversations, or internal information.

Microsoft specifically lists suspicious inbox rules and newly added external forwarding as signs of a compromised Microsoft 365 account.

If you suspect a mailbox has been accessed, check the account itself, the forwarding settings, active sessions, and connected applications.

Can someone keep receiving email after the password is changed?

Yes.

Imagine an attacker gets access to an employee's Microsoft 365 account and creates a rule that forwards certain messages to an outside address.

The employee changes their password. The attacker may lose direct access to the account, but the forwarding rule can remain.

Microsoft warns that suspicious inbox rules may automatically forward email to unknown addresses or move messages into folders such as Junk Email, Notes, or RSS Subscriptions to make them harder for the user to notice.

That is why a password reset should be part of the response, not the entire response.

What are the warning signs of hidden email forwarding?

What are the warning signs of hidden email forwarding?

The problem is often discovered because something feels wrong rather than because Microsoft 365 stops working completely.

Watch for:

  • Messages unexpectedly disappearing

  • Customers receiving replies the employee did not send

  • Vendors questioning unusual payment instructions

  • Password-reset emails going missing

  • Messages appearing in unusual folders

  • New forwarding addresses nobody recognizes

  • Unexpected rules inside the mailbox

  • Sign-ins from unfamiliar devices or locations

Microsoft identifies missing or deleted email, suspicious sent messages, unexplained account changes, and newly added external forwarding as common signs of mailbox compromise.

A mailbox can appear completely normal while selected messages are quietly being copied elsewhere.

Why isn't changing the password enough?


Because the attacker may have already established another way to maintain access.

After a suspected compromise, administrators should look beyond the password and review:

  • Active sign-in sessions

  • Inbox and forwarding rules

  • MFA methods

  • Recently connected applications

  • Account permissions

  • Recent sign-in activity

Microsoft recommends revoking active sessions when responding to a compromised Microsoft 365 mailbox. This helps invalidate existing access rather than waiting for sessions to expire naturally.

The goal is to remove the attacker's access and anything they changed while they had it.

Why should connected applications be checked too?

Why should connected applications be checked too?

Microsoft 365 accounts can give third-party applications permission to access company information.

An employee may legitimately connect a scheduling tool, CRM, document application, or other service. But if an attacker tricks someone into approving a malicious application, changing the user's password may not address that application permission.

Microsoft recommends reviewing applications that have user consent after an account compromise and removing anything that should not be there.

Administrators should ask a simple question:

Do we recognize every application that currently has access to this user's account?

If the answer is no, investigate before assuming the account is secure.

Where should Microsoft 365 administrators check for forwarding?

Where should Microsoft 365 administrators check for forwarding?

Start with the affected mailbox.

In the Exchange admin center, administrators can open the user's mailbox and review its Email forwarding settings. Microsoft allows forwarding to another internal mailbox or an external email address, so any destination should be confirmed as legitimate.

Then review the mailbox's inbox rules. Look for rules that:

  • Forward or redirect messages

  • Delete messages automatically

  • Move messages into unusual folders

  • Apply only to invoices, payments, executives, or specific vendors

  • Send information to an unfamiliar address

Some malicious rules may also be hidden from the normal user view. Microsoft documents additional administrator checks that can identify hidden inbox rules when investigating a compromised mailbox.

Microsoft 365 administrators can also use the Auto-forwarded messages report in Exchange Online to see which users are automatically forwarding messages, where the messages are going, and which external domains are receiving them. Microsoft specifically describes this report as a way to look for potential data leaks.

What should a business do after finding suspicious forwarding?

What should a business do after finding suspicious forwarding?

If a suspicious rule or forwarding address is found, treat it as a sign that the mailbox may have been compromised.

A practical response is:

  1. Remove or disable the suspicious forwarding rule.

  2. Reset the affected user's password.

  3. Revoke active sessions.

  4. Review MFA methods and remove anything unfamiliar.

  5. Review connected applications and permissions.

  6. Check recent sign-ins and mailbox activity.

  7. Determine what information may have been forwarded.

  8. Look for suspicious messages sent from the account.

Microsoft recommends disabling malicious inbox rules, resetting credentials, and investigating additional activity when suspicious forwarding is confirmed.

Businesses should also consider restricting automatic external forwarding unless there is a legitimate business reason for it. Microsoft warns that external automatic forwarding can increase exposure to account-takeover attacks and provides Microsoft 365 controls for limiting it.

Integrate Cyber Takeaway

Integrate Cyber Takeaway

Changing a compromised Microsoft 365 password is important, but it should not be the final step.

Check forwarding settings, inbox rules, active sessions, MFA methods, connected applications, and recent account activity.

If something looks unfamiliar, investigate it before returning the mailbox to normal use.

The bigger lesson is simple: when an attacker gets into email, you need to look at what they changed, not only how they got in.

Changing a compromised Microsoft 365 password is important, but it should not be the final step.

Check forwarding settings, inbox rules, active sessions, MFA methods, connected applications, and recent account activity.

If something looks unfamiliar, investigate it before returning the mailbox to normal use.

The bigger lesson is simple: when an attacker gets into email, you need to look at what they changed, not only how they got in.

Know where you’re exposed before someone else does 

Book a scoping call and we’ll help define the right penetration testing approach for your environment. 

Know where you’re exposed before someone else does 

Book a scoping call and we’ll help define the right penetration testing approach for your environment. 

Know where you’re exposed before someone else does 

Book a scoping call and we’ll help define the right penetration testing approach for your environment. 

integrate cyber newsletter

Subscribe To Our Weekly Newsletter

Practical advice, real threats explained, and simple steps to strengthen your security every week.

integrate cyber newsletter

Subscribe To Our Weekly Newsletter

Practical advice, real threats explained, and simple steps to strengthen your security every week.

integrate cyber newsletter

Subscribe To Our Weekly Newsletter

Practical advice, real threats explained, and simple steps to strengthen your security every week.