Join our Newsletter — 33% off our NHI Course

When should organisations treat external email auto-forwarding as an unacceptable risk rather than a convenience feature?

Organisations should treat external auto-forwarding as high risk when mailboxes contain payment workflows, sensitive business records, or access to supplier and executive conversations. Forwarding creates an easy exfiltration path and can hide compromise for long periods. If the business must allow it, narrow the scope, monitor every rule change, and alert on forwarding to unfamiliar destinations.

When external forwarding becomes a data-exposure problem, not a productivity shortcut

External auto-forwarding stops being a convenience feature once the mailbox is part of a business process or contains information whose disclosure would create operational, financial, or contractual harm. The key question is not whether the rule is easy to use, but whether it moves sensitive content outside the organisation’s control boundary without a compensating security control.

That risk is highest when the mailbox carries invoices, payment approvals, supplier negotiations, executive correspondence, legal material, or incident-related messages. In those cases, forwarding turns ordinary email into an unmanaged export path, and the organisation loses practical control over retention, access, and downstream copying.

Why forwarding also creates a stealthy compromise path

External forwarding is not just a confidentiality issue. It can also be abused as a persistence and exfiltration mechanism because it allows an attacker or insider to keep receiving copied mail without changing the victim’s visible workflow. A rule can survive password resets, and unless mailbox settings are reviewed, the compromise may look like normal mail delivery.

That is why monitoring mailbox rule changes matters as much as deciding whether forwarding should be allowed at all. If the organisation only blocks obvious phishing but ignores forwarding rules, it can miss a low-noise channel for draining sensitive messages over time.

Mailbox forwarding to an unfamiliar domain should be treated as a strong signal for review because it often indicates an exception, a misconfiguration, or a compromise path that is easier to overlook than interactive logon abuse.

How to decide whether to allow it at all

The practical decision is whether the business need outweighs the exposure created by copying mail beyond corporate controls. In environments with regulated records, sensitive customer data, or approval workflows, the default should be denial. If a use case genuinely requires forwarding, it should be narrow, time-bounded, and traceable.

Where forwarding remains permitted, the security requirement is to reduce the blast radius: restrict who can create rules, limit destinations, review exceptions regularly, and make rule changes visible to operations and security teams. The less trustworthy the mailbox content, the less acceptable external forwarding becomes as a standing pattern.

Risk and Threat Considerations

External forwarding creates an easy exfiltration route for sensitive correspondence and can let malicious activity blend into ordinary mail handling. The risk rises sharply when the mailbox supports payment execution, executive decision-making, supplier relationships, or other high-value business processes.

Failure mechanism: A forwarding rule copies messages to an outside address, bypassing the organisation’s normal access controls, monitoring expectations, and retention boundary. An attacker, insider, or careless user can use the rule to siphon content continuously, often without changing message flow in the original mailbox.

Impact: Loss of confidentiality, increased fraud exposure, weaker incident detection, and possible compliance or contractual breach if sensitive records leave approved systems. In the worst case, forwarded mail becomes a durable shadow copy of business communications that survives longer than the compromise that created it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-4 — Information Flow Enforcement External forwarding is an information flow out of the organization boundary.
AU-12 — Audit Record Generation Forwarding rule creation and changes need auditable visibility.
AC-6 — Least Privilege Forwarding exceptions should be limited to only the accounts and cases that need them.
Recommendation — Restrict mail forwarding paths and enforce approved information flows. Log mailbox rule creation and changes for security review. Limit who can create or override forwarding rules.
ISO/IEC 27001:2022 A.8.12 — Data leakage prevention External forwarding can leak sensitive email content beyond approved channels.
Recommendation — Apply leakage controls to stop unauthorized email exfiltration.
CIS Controls v8 CIS-6 — Access Control Management Forwarding is an access-path and exception-management problem for email accounts.
Recommendation — Review and revoke risky mailbox forwarding exceptions promptly.

Practitioner Guidance

What to prioritise: Treat any mailbox that participates in payment, vendor, legal, HR, or executive workflows as a candidate for default-deny external forwarding. Those are the mailboxes where the business impact of exfiltration is usually highest.

What to verify: Confirm whether forwarding is user-controlled, admin-controlled, or inherited from legacy rules, and validate whether monitoring covers new rules, destination changes, and inbox delegation changes. If you cannot observe rule creation reliably, you do not have a trustworthy exception process.

Decision rule: If the mailbox contains content that would be damaging to disclose outside the organisation, do not treat forwarding as a convenience feature. If the business insists on an exception, bound it to an approved recipient, a defined period, and explicit review.

Practitioner takeaway: External forwarding is acceptable only when the mailbox content is low sensitivity and the organisation can detect, justify, and revoke the rule quickly; otherwise it should be treated as an untrusted data-export path.