Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Suspicious Forwarding Rule
Threats, Abuse & Incident Response

Suspicious Forwarding Rule

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

A suspicious forwarding rule is an email configuration that automatically copies or redirects messages to an unexpected destination, often outside the organisation. In security investigations, it can indicate account compromise, mailbox abuse, or covert data exfiltration through a legitimate mail system.

What a suspicious forwarding rule is doing

A suspicious forwarding rule silently moves email to an unexpected mailbox, alias, or external destination. Because it uses a legitimate mail feature, it can blend into normal administration while changing where sensitive messages actually go.

This matters because forwarding is not just a delivery preference, it is a routing control. Once a rule exists, the mailbox owner may continue receiving messages in the inbox while a copy leaves the organisation without an obvious alert.

How attackers abuse forwarding rules

In compromise cases, forwarding is often used to monitor conversations, harvest resets, and collect business-sensitive content over time. It is especially useful after phishing or password theft, because the attacker can stay passive and let the mailbox keep producing valuable material.

Forwarding may also be combined with inbox filtering, delegated access, or deleted-message hiding so the user notices less. That makes it a common persistence and exfiltration pattern in email investigations, not just a harmless user misconfiguration.

Why it is difficult to spot

Suspicious forwarding rules are hard to notice because the mailbox can still look healthy from the user perspective. Messages may arrive normally, while copies are redirected in the background to another account or domain.

Detection often depends on reviewing mailbox settings, audit trails, and recent account activity rather than waiting for a visible disruption. A rule that targets a personal mailbox, consumer provider, or unrelated business unit deserves particular scrutiny.

Common security implications

The security impact is usually confidentiality loss first, followed by potential account abuse and broader compromise. Forwarded mail can contain password resets, internal approvals, customer data, contracts, and other information that gives an intruder more reach than the original mailbox alone.

In some environments, forwarding also creates governance problems because it undermines retention, monitoring, and data-handling expectations. If the rule persists, it can keep leaking information long after the initial compromise is contained.

Risk and Threat Considerations

Suspicious forwarding rules are risky because they can turn a normal mailbox into a quiet data-exfiltration channel. The exposure is often persistent, low-noise, and easy to overlook if teams only check login events and ignore mailbox configuration changes.

Failure mechanism: An attacker or insider creates or modifies a forwarding rule after gaining mailbox access, then uses the rule to copy messages to an external destination while remaining hidden inside legitimate email flow.

Impact: Sensitive correspondence, reset links, approvals, and other business content can be siphoned out continuously, extending the blast radius of the original compromise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1114 — Email CollectionEmail forwarding rules are used to collect mailbox content covertly.
Recommendation — Monitor mailbox rule changes and investigate forwarding as part of email collection detection.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeRestrict who can create or alter forwarding and mailbox routing settings.
AU-12 — Audit Record GenerationMailbox rule creation and change events need auditable traces for investigations.
SI-4 — System MonitoringForwarding-rule abuse is best found through monitoring of account and mailbox configuration drift.
Recommendation — Limit mailbox rule administration to the smallest necessary set of users and admins. Log forwarding-rule changes and retain the records for security review. Alert on suspicious mailbox rule creation, modification, and external forwarding destinations.
ISO/IEC 27001:2022A.8.15 — LoggingEmail rule changes are configuration events that should be logged and reviewable.
A.8.16 — Monitoring activitiesSuspicious forwarding is detected by monitoring account and mailbox behaviour over time.
Recommendation — Collect and review logs for mailbox forwarding-rule creation and changes. Monitor mailbox settings for external forwarding and unexpected routing changes.

Practitioner Guidance

What to watch for: Investigators should treat new forwarding destinations, unusual rule names, hidden filters, and mailbox changes made soon after suspicious sign-in activity as high-signal findings. A rule that points outside the organisation is more concerning when the user cannot explain why it exists.

Governance implication: Mailbox forwarding should be reviewed as an access-control and data-loss issue, not only as an email preference. Where policy allows forwarding at all, organisations should make ownership, approval, and periodic review explicit so that invisible redirection does not become a default exfiltration path.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org