Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› How do security teams know whether a mail…
Cyber Security

How do security teams know whether a mail forwarding rule is materially risky?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Cyber Security

Look for rules that move content outside the tenant, apply broadly across incoming mail, or create persistence that normal user review will miss. The risk is highest when the rule is silent, long-lived, and not tied to an explicit business process. Those are the patterns that create invisible exposure windows.

What makes a mail forwarding rule materially risky

A forwarding rule becomes materially risky when it changes the mail system from a simple convenience feature into an unmanaged data path. The key issue is not that forwarding exists, but that it can quietly redirect sensitive messages, bypass normal review, and keep operating after the original user forgets it is there.

The strongest warning signs are rules that forward to external domains, apply to broad message patterns, or trigger before the user would reasonably notice. Those patterns matter because they turn a mailbox into a persistence point, not just a delivery preference.

For teams assessing exposure, the question is whether the rule creates an invisible route for content that would otherwise stay inside the tenant. If the rule can forward finance, legal, HR, or security mail without a clear operational need, it is no longer a low-impact convenience setting.

Which rule patterns usually create the biggest exposure

Broad forwarding rules are the most dangerous because they can collect far more content than the user appears to be reading. A rule that catches all inbound mail, all messages from a domain, or all mail matching generic keywords can exfiltrate a much larger slice of business communication than a narrow exception rule.

External destinations raise the stakes further because they move content outside tenant controls, retention policies, and monitoring assumptions. Even when the forwarding target is legitimate, security teams should treat it differently if it crosses a trust boundary or creates a second copy of sensitive mail in an uncontrolled environment.

Persistence is the other major signal. A rule that survives mailbox changes, inbox cleanup, or casual user review is more likely to support long-term exposure than a short-lived workflow aid. OWASP Non-Human Identity Top 10 is useful here because the same abuse pattern shows up whenever long-lived access paths are left in place without strong lifecycle control.

How teams should judge impact, not just existence

The practical test is whether the rule changes the blast radius of a mailbox compromise or an insider event. If an attacker, rogue admin, or careless user can add a silent rule and receive mail off-platform, the rule can become a low-noise collection mechanism for passwords resets, invoices, legal notices, and internal approvals.

Materiality also depends on what mail the rule can see. Forwarding that touches executive mailboxes, security alerts, shared mailboxes, or regulated content is more serious than a narrow personal convenience rule because it can expose data, create fraud opportunities, and undermine incident detection.

Security teams should also consider whether the rule is auditable and reversible. If the tenant does not make the rule easy to inventory, alert on, or remove, then the control failure is not only the forwarding itself, but the lack of visibility around it.

Risk and Threat Considerations

Mail forwarding rules become a threat when they are used as a quiet exfiltration path or a persistence mechanism after compromise. The danger is highest when a rule is hidden from routine review, forwards outside the organization, and can continue to copy sensitive mail long after the triggering event.

Failure mechanism: An attacker or insider adds a rule that silently copies messages to an external mailbox, then relies on the fact that mail flow changes are often less visible than interactive account actions.

Impact: The rule can expose credentials, invoices, approvals, legal correspondence, and other sensitive content, while also supporting fraud, replay, and long-term surveillance of the mailbox.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeBroad forwarding paths expand access to mail content beyond need-to-know.
AU-6 — Audit Record Review, Analysis, and ReportingForwarding rules are risky when they are not routinely reviewed or alerted on.
AC-2 — Account ManagementMailbox rules are lifecycle-managed access paths that need ownership and revocation.
Recommendation — Limit forwarding permissions to narrowly approved business cases and remove unnecessary mail relay paths. Monitor and review mailbox rule changes so unusual forwarding is detected quickly. Review and revoke unauthorized forwarding rules as part of account lifecycle control.
CIS Controls v8CIS-6 — Access Control ManagementMail forwarding is an access path that should be explicitly governed and removed when unjustified.
CIS-8 — Audit Log ManagementRule changes must be visible to spot silent persistence and exfiltration.
Recommendation — Restrict and remove unauthorized forwarding paths to reduce data exposure. Log and alert on forwarding rule creation, change, and external destinations.

Practitioner Guidance

What to verify: Confirm whether each rule forwards outside the tenant, whether it applies to all mail or broad filters, and whether the destination is owned by the same business process. Rules that cannot be tied to a documented workflow deserve immediate review.

What to prioritize: Start with executive, finance, HR, security, and shared mailboxes, then move to any account with mailbox delegation or recent sign-in anomalies. Those populations are most likely to create high-value exposure if forwarding is misused.

What good looks like: Teams should be able to inventory forwarding rules quickly, explain why each one exists, and remove any rule that is silent, externally routed, or older than the approved business need. A rule that cannot be justified in plain language is usually a risk candidate.

Practitioner takeaway: Treat forwarding as a control decision, not a convenience feature, and assume any silent external rule can turn ordinary mail into a durable exfiltration channel until proven otherwise.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org