The mailbox rule you didn't make
Picture a small business where the owner's email account was compromised three months ago. The attacker guessed the password, logged in once, set up two rules, and left. The first rule forwards a copy of every incoming message to an external address. The second rule moves those messages to the trash and marks them as read, so there is no unread count and no visible copy in the inbox. The owner never noticed. For three months, the attacker has received every email: customer inquiries, vendor invoices, password reset links for other services, internal messages from the bookkeeper. The attacker is patient. They are learning the business, watching for the right opportunity to send a payment redirect or a convincing request. The owner assumes that if the account were compromised, something would look wrong. Nothing looks wrong because the rules are doing exactly what they were designed to do.
That is the version where the attacker has not acted yet. The worse version is the rule that forwards every message and then deletes it permanently, so the owner never sees customer orders or vendor messages and assumes the sender never wrote. Or the rule that only forwards messages containing the word "invoice" or "payment," so the attacker gets financial information without the noise. Or the rule that auto-replies to certain senders with a message pretending to be an out-of-office notice, buying time while the attacker uses the account elsewhere. Mailbox rules are powerful, silent, and easy to miss if you do not know to look.
Where the rules hide in Microsoft 365
Log into outlook.office.com as the user, or log into admin.microsoft.com and use the "Log in as this user" feature if you have delegated access configured. Once in the mailbox, click the gear icon in the upper right, then "View all Outlook settings" at the bottom of the panel. Go to Mail, then Rules. Any forwarding rule will be listed there. Look for rules that forward to an external address, rules that delete messages automatically, or rules that move messages to folders the user does not recognize. Delete anything that does not belong.
If the account has been compromised, there may also be a forward configured at the mailbox level rather than as a rule. In the same settings panel, go to Mail, then Forwarding. If "Enable forwarding" is turned on and there is an address the user did not configure, turn it off.
For administrator-level checking across all mailboxes without logging into each one, use PowerShell with the Exchange Online module. Connect to Exchange Online, then run Get-Mailbox -ResultSize Unlimited | Get-InboxRule | Where-Object {$_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo} to list every rule in every mailbox that forwards mail. That command will show you which accounts have forwarding rules and where the mail is going. Run it once to audit, then decide if you want an alert every time a new forwarding rule is created.
Where the rules hide in Google Workspace
Log into Gmail as the user, or use delegated access if configured. Click the gear icon, then "See all settings." Go to the "Filters and Blocked Addresses" tab. Any rule that forwards, deletes, or skips the inbox will be listed there. Look for filters that forward to an external address or that apply a label and mark as read, which is a common way to hide forwarded messages. Delete anything the user did not create.
Google also allows a mailbox-level forward. In the same settings area, go to the "Forwarding and POP/IMAP" tab. If there is a forwarding address listed and the user did not add it, disable it.
For administrator-level visibility, log into admin.google.com, go to Reports, then Audit, then Email log search. You can filter by event type to see when forwarding addresses are added or when filters are created. Google Workspace does not have a single command to list all forwarding rules across all accounts the way Exchange Online does, but the audit log will show you when changes happen if you know to look.
Why an alert matters more than another password reset
Changing a password after a compromise stops the attacker from logging in again, but it does not remove the rules they already created. If you reset the password and do not check for forwarding rules, the attacker still gets a copy of every email. The rules persist until someone manually deletes them. That is why the first step after any suspected compromise is to check for rules, forwards, and delegates, not just to change the password.
The better approach is to configure an alert that notifies you when a new forwarding rule is created or when mailbox forwarding is enabled. In Microsoft 365, that is an alert policy in the Purview compliance portal. In Google Workspace, that is an alert rule in the admin console under Rules. Either way, the alert tells you the same day that something changed, and you can decide if the change was intentional. That alert catches compromises faster than waiting for someone to notice that email is missing.
This is part of what a Care plan includes: monitoring for forwarding rules, regular mailbox audits, and response when something does not match the pattern. If you are checking manually, put it on the calendar once a quarter. If you are not checking at all, start today.