Email Security

Control External Email Forwarding

For Exchange Online teams: prevent unapproved automatic forwarding while preserving explicitly approved business workflows.

Content review: 2026-09-22 · Estimated effort: Medium

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: identify the Exchange administrator, mail-flow owner, and business approver. Record current policies and forwarding settings in a protected location. Ask about ticketing, finance, and outsourced support workflows before changing them.

Put it into practice

  1. Review mailbox-level forwarding and user inbox rules, including shared mailboxes. Also inspect mail-flow rules and connectors separately: one forwarding control does not cover every route mail can take. Record each external destination, business purpose, data sensitivity, owner, and approval; investigate unexpected rules as possible compromise.
  2. Prefer access to a controlled shared mailbox or an approved collaboration workflow over forwarding business mail to personal inboxes. Obtain data-owner approval before retaining an external destination. Preserve relevant evidence before removing suspicious rules and follow your incident response process if compromise is suspected.
  3. In Microsoft Defender, review the applicable outbound anti-spam policy's Automatic forwarding rules setting and explicitly disable unapproved external automatic forwarding. Check policy scope and precedence. This control is available with built-in cloud-mailbox protection; it is not a blanket requirement to buy Defender for Office 365.
  4. If an exception is necessary, restrict it to approved senders and destinations using the applicable policy and remote-domain controls. Record an expiry and reviewer. Other blocking controls can override an allow setting; test the effective combination rather than assuming the exception works. This does not prevent a user manually sending mail externally.
  5. Verify: with synthetic messages and test mailboxes you control, confirm unapproved forwarding is blocked, approved workflows function, and ordinary mail delivery continues. Inspect message trace or non-delivery reports and check the destination inbox. Keep an evidence summary, not real customer email.
  6. If a business workflow fails: contact its owner and restore only an approved, narrow route while correcting the dependency. Avoid enabling unrestricted forwarding for the entire organization. Repeat the review after mailbox ownership changes and investigate newly created unexpected forwarding rules.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.

Start without another software subscription

Use the outbound forwarding controls included with an eligible Microsoft cloud mailbox service and the free change worksheet.

Where this stops: Basic desktop Office alone does not include Exchange Online. If mail is hosted elsewhere, use that provider’s controls; no free desktop app can enforce forwarding policy for a hosted mailbox.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

Microsoft Defender outbound anti-spam policies

Included cloud-mailbox protection; no Defender for Office 365 upgrade needed for this control

Review Automatic forwarding rules in the applicable outbound anti-spam policy, alongside inbox rules and mailbox forwarding.

Limits: Requires administrative permissions and an applicable Microsoft cloud mailbox service. Other mail-flow controls can override exceptions; this does not block manual external sending.

Your information: Policies and message trace are in your existing Microsoft service. Record test summaries rather than customer messages.

Official instructions: Microsoft Defender outbound anti-spam policies ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

A team wants to prevent a mailbox automatically forwarding customer messages externally.

Use the Security change and verification record template.

What to enter before testing

Change ID
EXAMPLE-FORWARD-01
Service and scoped recipients
Authorized test mailbox and controlled external destination
Expected allowed and blocked behavior
Normal mail works; unapproved automatic external forwarding is blocked
Actual test results
Not tested

How to verify

With approval, use harmless mail and controlled accounts to test applicable forwarding rules, mailbox forwarding and policy behavior. Inspect trace or failure evidence and confirm normal mail delivery. Clean up temporary test rules afterward.

If the result is unexpected

If forwarding succeeds, check which policy applies and other mail-flow controls. If legitimate workflows fail, review a narrowly scoped approved exception. Automatic-forwarding controls do not prevent a person manually sending mail externally.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: PR.DS-02: protecting confidentiality of data in transit by controlling forwarding
  • NIST CSF 2.0: PR.PS-01: managed mail configuration
How this guidance is prepared