Security teams should treat mailbox forwarding as part of identity lifecycle control, not as an email-only issue. The key is to check for external forwarding, inbox rules, and delegate access when a user enters offboarding, then remove or block those settings before the account is disabled. Strong authentication does not make a risky mailbox action acceptable.
Why This Matters for Security Teams
Mailbox forwarding is a classic offboarding blind spot because it sits at the intersection of identity, email security, and data access. If forwarding, inbox rules, or delegate access remain active after a user leaves, the organisation can silently lose control of sensitive mail flow even when passwords are reset. That is why NHI Management Group treats lifecycle control as the real issue, not email hygiene alone. Current guidance suggests aligning this step with broader NHI Lifecycle Management Guide practices and with governance expectations in the NIST Cybersecurity Framework 2.0.
The risk is not limited to one mailbox. Forwarding can become a durable exfiltration path into external systems, personal accounts, or unmanaged collaboration spaces. In offboarding, the control objective is to revoke data redirection before the account is disabled, because disabled accounts can still leave behind rule-based paths that continue to move information. Practitioners also need to look for delegated access and shared mailbox permissions, which often survive longer than expected. In practice, many security teams encounter mailbox forwarding only after a former employee or attacker has already used it to continue receiving internal communications.
How It Works in Practice
Mailbox forwarding should be handled as a standard identity lifecycle check, with email settings reviewed before final deprovisioning. The sequence matters: identify the account, inspect forwarding targets, review inbox rules, check delegate access, then remove or block anything that sends mail outside approved channels. This is consistent with the broader lifecycle discipline described in the Top 10 NHI Issues, where stale access and unmanaged redirection routinely create hidden exposure.
Operationally, teams should separate three controls. First, policy control: decide whether external forwarding is allowed at all, and if so, for which roles and under what exceptions. Second, technical control: configure the mail platform to block automatic forwarding to external domains unless explicitly approved. Third, review control: verify the offboarding checklist includes mailbox rules, transport rules, mobile mail sync, and delegated send-as or read access. This is where identity and messaging admins need the same change record, because email settings often outlive the HR termination event.
- Check mailbox-level forwarding and hidden inbox rules.
- Remove delegate access, send-as rights, and shared mailbox permissions.
- Block external auto-forwarding except for approved cases.
- Log and validate the final state before account disablement.
Strong authentication does not make forwarding safe. A user can pass MFA and still redirect sensitive mail outside the enterprise, which is why this control belongs in offboarding and access governance. The Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs reinforces the same lifecycle principle for other identities: remove the path of access before assuming the account is gone. These controls tend to break down in hybrid email environments where cloud and on-premises rules are managed separately because forwarding may persist in one layer after the other has been revoked.
Common Variations and Edge Cases
Tighter forwarding control often increases help desk and HR coordination overhead, requiring organisations to balance user continuity against data-loss and leakage risk. The right answer is not always “block everything,” because some teams legitimately need temporary routing for legal, executive, or customer-service handoffs. Current guidance suggests using time-bound exceptions with explicit approval rather than permanent forwarding arrangements.
Edge cases matter. Shared mailboxes, litigation holds, and service accounts can create the illusion of a standard user offboarding event, but the control requirements differ. For example, a manager may request forwarding to a successor, yet that should usually be handled through shared mailbox access or ticketed mail routing, not silent auto-forwarding to an external address. If a mailbox contains regulated or highly sensitive data, security teams should also verify whether the mail platform supports audit logs for rule creation, because the absence of logging can make post-offboarding investigation difficult. The 2025 State of NHIs and Secrets in Cybersecurity found that 91% of former employee tokens remain active after offboarding, which is a strong reminder that lifecycle failures rarely stay confined to one control domain.
For most organisations, the practical standard is: no uncontrolled forwarding, no hidden inbox rules, and no leftover delegate paths after termination. Exceptions should be documented, time-limited, and reviewed like any other privileged access decision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Offboarding must revoke lingering mailbox forwarding paths tied to identity lifecycle. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions and least privilege apply to mailbox redirection and delegate rights. |
| NIST Zero Trust (SP 800-207) | PR.AC | Zero trust demands continuous verification of who can move data from a mailbox. |
| NIST AI RMF | GOVERN | Lifecycle governance applies to identity-driven data movement decisions and exceptions. |
| OWASP Agentic AI Top 10 | A01 | Autonomous workflows can exploit mailbox redirection as a data exfiltration path. |
Assign ownership for mailbox forwarding decisions and enforce documented approval for exceptions.
Related resources from NHI Mgmt Group
- How should security teams handle risks from AI browser extensions?
- How should security teams handle NHIs exposed during employee offboarding?
- How should security teams handle access approvals when requests arrive faster than humans can review them?
- How should security teams prioritise NHI remediation in cloud environments?