← All posts

How To Find and Stop Unauthorized Email Forwarding Rules

September 16, 2026

The malicious inbox rule is the signature of business email compromise. Here is how to find every variant of it and block the technique for good.

If you find a forwarding rule nobody created, you are not looking at a configuration mistake. You are looking at the working end of a business email compromise.

Why attackers need the rule

An intruder in a mailbox has a problem: the real owner can see the same messages. So they build a rule that hides the fraud thread. Common shapes we find:

  • Forward all mail to an external address, often a free provider or a lookalike domain
  • Move anything containing "invoice", "wire", "ACH", "remittance", or a bank name into an obscure folder
  • Delete replies from one specific vendor or from the finance team
  • Forward only mail from a single high-value counterparty

Where to look

Microsoft 365: mailbox inbox rules, mailbox forwarding settings, transport and mail flow rules at the tenant level, and connected applications. Note that a rule created through a client can be invisible in another client — check with PowerShell rather than trusting one interface.

Google Workspace: Gmail filters, forwarding addresses, send-as entries, delegation, and OAuth grants with Gmail scope.

Preserve before you delete

Export the rule definition, its creation timestamp, and the audit event showing which session created it. That timestamp usually anchors the whole investigation, because it tells you when the attacker actually got in.

Block the technique

  • Disable automatic external forwarding by policy, with an approved exception list
  • Alert on every new forwarding rule and on any rule creation from an unfamiliar IP
  • Require MFA everywhere and disable legacy authentication
  • Review rules on finance and executive mailboxes on a schedule, not only after an incident

Detection here is cheap and the payoff is enormous, because the rule usually appears days or weeks before the fraudulent invoice does. That gap is the window our SOC works inside through managed detection and response and breach hunting.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

inbox rulesemail forwardingBECdetection

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.