Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Inbox Forwarding Rule
Cyber Security

Inbox Forwarding Rule

← Back to Glossary
By NHI Mgmt Group Updated September 8, 2026 Domain: Cyber Security

An inbox forwarding rule is a mail rule that automatically redirects messages to another destination. In abuse scenarios, it can be used to quietly exfiltrate sensitive email or maintain persistence. It is a useful detection point because rule creation is often more consistently logged than earlier reconnaissance.

Expanded Definition

An inbox forwarding rule is a mail policy or client-side rule that sends selected messages to another mailbox, address, or external destination without requiring manual action on each message. In normal use, it can support delegations, shared administration, or backup workflows. In abuse cases, it becomes a quiet control-plane change rather than a noisy content theft event.

The boundary that matters is whether the rule changes message flow at the mailbox level or merely filters what a user sees. A forwarding rule can coexist with other mailbox automation such as signatures, categorisation, or inbox sorting, but those features do not redirect mail off-platform. That distinction is important because defenders often look for message reads, deletes, or phishing clicks first, while rule abuse may preserve the inbox experience and stay hidden. Where mailbox forwarding is governed centrally, the security question is usually whether external forwarding is permitted at all and who can create it.

Examples and Use Cases

Inbox forwarding rules appear in both legitimate operations and abuse patterns. The same mechanism can support business continuity or quietly move sensitive correspondence outside the tenant.

  • A support mailbox forwards executive mail to an assistant during travel or leave cover.
  • A shared team inbox routes vendor messages to a specialist queue for faster handling.
  • A compromised account creates a rule that forwards all new messages containing invoices, reset links, or approvals to an attacker-controlled address.
  • A mailbox migration temporarily forwards messages to preserve continuity while identities are moved between systems.
  • A security team reviews suspicious rule creation as a detection source because the rule event may be more visible than the earlier account access that led to it.

The main trade-off is convenience versus control. The more automatic the forwarding, the easier it is for legitimate workflows to function, but the less obvious it becomes when a rule is used to siphon communications outside normal oversight.

Security Implications

When inbox forwarding rules are misunderstood or weakly governed, they can create a low-friction exfiltration path for sensitive information. Email often carries password resets, transaction approvals, customer data, contracts, and internal discussions, so a hidden rule can expose both content and timing without triggering obvious user complaints. The rule may persist even after the initial compromise is removed if mailbox settings are not reviewed.

Observable symptoms include unexpected delivery gaps, replies that never reach intended recipients, unexplained rule additions, or mail sent to unfamiliar domains. In many environments, the failure is not the forwarding feature itself but the assumption that mailbox access logging alone is enough. Once the attacker can modify mail rules, they can maintain passive visibility with very little ongoing activity.

Practitioner observation: rule changes are often more reliable to investigate than the original intrusion path, which makes mailbox rule review a practical pivot during email compromise triage.

Domain and Governance Relevance

For identity and access governance, inbox forwarding rules matter because they represent a delegated data-routing decision, not just a user preference. The governance question is whether a mailbox is allowed to move messages to another trust boundary, especially an external one. That decision affects confidentiality, accountability, and retention, and it often sits at the intersection of messaging policy, identity assurance, and monitoring.

In environments with non-human identities, forwarding rules can also interact with service mailboxes, shared operational inboxes, and automated notification accounts. Those mailboxes may receive sensitive alerts, reset messages, or approval traffic that other systems depend on, so forwarding can expand the blast radius of a compromised or poorly governed mailbox. For NHIMG, the key point is that inbox rules are a control surface around identity-linked communications, not merely a usability feature.

Where organisations permit external forwarding, the most important governance issue is whether the exception is explicit, reviewable, and limited to a defined business need rather than enabled by default.

Risk and Threat Considerations

Inbox forwarding rules create a material persistence and exfiltration risk because they can redirect future messages after the initial compromise has been achieved. Attackers value them because they are low-noise, durable, and often overlooked during incident response compared with password resets or session revocation.

Failure mechanism: An attacker who gains mailbox access creates or modifies a forwarding rule so new messages are silently copied or moved to an external destination. The rule can preserve access to password resets, invoices, approvals, or sensitive internal exchanges even if the attacker no longer logs in interactively.

Impact: Confidential mail content is exposed outside the organisation, compromise persistence increases, and the mailbox can continue leaking information until rules are reviewed and removed. In regulated or approval-driven workflows, the same mechanism can also distort business processes by diverting messages away from intended recipients.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1114.003 — Email Collection: Email Forwarding RuleDirectly covers malicious inbox forwarding for collection and persistence.
Recommendation — Map suspicious rule changes to T1114.003 and hunt for mailbox collection activity.
CIS Controls v86.3 — Access Control ManagementForwarding rules are an access-control exception that can expose mail externally.
Recommendation — Restrict and review forwarding exceptions under access control governance.
NIST CSF 2.0PR.AA-5 — Identity and Access ManagementMailbox rule creation is an identity-governed action affecting data routing.
DE.CM-1 — Monitoring and Event AnalysisForwarding-rule creation is a high-value detection signal in mailbox abuse.
Recommendation — Limit who can create forwarding rules and monitor rule changes as access events. Alert on new forwarding rules and investigate unexpected destination changes.
OWASP Non-Human Identity Top 10NHI-01 — Inventory and OwnershipMailbox automation on service or shared accounts needs clear ownership and review.
Recommendation — Inventory mailboxes with forwarding authority and assign accountable owners.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org