How to check Outlook email forwarding after hack
If your Outlook account was compromised, one of the first things to verify is whether your email is being forwarded to an unfamiliar address.
Attackers often use forwarding rules to quietly copy messages, reset passwords on other accounts, and maintain access after you regain control.
This guide explains how to inspect Outlook forwarding settings in Outlook on the web and the desktop app, how to spot hidden rules, and what to do immediately if you find anything suspicious.
Why hackers set up email forwarding
Email forwarding gives an intruder ongoing visibility into your inbox without needing to stay signed in all the time.
In many Microsoft 365 and Outlook attacks, forwarding is used for persistence, data theft, and account recovery interception.
- They can read password reset emails from banks, shopping sites, and social networks.
- They can monitor replies and internal conversations in business accounts.
- They may use forwarding to hide evidence of the breach from the mailbox owner.
Because forwarding can be configured in several places, you need to check more than one setting.
Check Outlook forwarding in Outlook on the web
The fastest place to look is Outlook on the web, especially if your mailbox is hosted in Microsoft 365 or Exchange Online.
Open your mailbox in a browser and inspect the settings carefully.
Review mail forwarding settings
- Sign in to Outlook on the web.
- Select the Settings gear in the top-right corner.
- Choose Mail, then Forwarding.
- Look for any enabled forwarding address.
- If forwarding is turned on and you do not recognize the destination, disable it immediately.
Legitimate forwarding should be easy to explain.
If you see an unknown address, treat it as a security incident.
Check inbox rules and hidden redirects
Attackers often create rules that forward only specific messages, such as security alerts, invoices, or emails from a bank.
These rules can be harder to notice than basic forwarding.
- In Outlook on the web, open Settings.
- Go to Mail and then Rules.
- Review every rule for actions such as forward to, redirect to, delete, or mark as read.
- Delete any rule you did not create or cannot verify.
Also check for unusual conditions, such as rules that apply only to messages with attachments, subject-line keywords, or emails from a specific sender.
Check Outlook forwarding in the desktop app
If you use the Outlook desktop application, forwarding may be configured at the account level or through rules.
The location varies slightly by version, but the goal is the same: find any automatic mail handling you did not authorize.
Inspect account-level forwarding
Some Microsoft 365 accounts use server-side settings rather than local app settings.
If your account is connected to Exchange, changes made in Outlook desktop may sync to the server, but the web version is still the most reliable place to confirm forwarding.
In Outlook desktop, look for:
- File > Account Settings
- Rules and Alerts
- Manage Rules & Alerts
Review all active rules and disable anything suspicious.
If a rule forwards mail externally, consider it a high-priority issue.
Check automatic replies and delegation
Although automatic replies are not the same as forwarding, attackers sometimes alter related settings to support their access.
Also verify whether delegates or shared mailbox permissions were added without your consent.
- Review automatic replies for unexpected content or time frames.
- Check whether anyone has send-as or send-on-behalf permissions.
- Remove unknown delegates from your mailbox if your organization allows you to do so.
Look for signs of stealth forwarding
Some compromises are designed to stay hidden.
If a hacker has access, they may create a rule that forwards only a subset of messages or deletes the original after forwarding.
Warning signs include:
- Messages disappearing from your inbox or Sent Items.
- Unread messages suddenly marked as read.
- Password reset emails missing from the mailbox.
- Outlook settings changing back after you edit them.
- Unexpected login alerts from Microsoft or unfamiliar devices.
If you see these symptoms, forwarding may be only one part of the compromise.
Assume the account is actively being monitored until proven otherwise.
What to do if you find suspicious forwarding
Finding unknown forwarding is not just a cleanup task; it is evidence that your account may still be exposed.
Act quickly and in order.
- Delete the forwarding address and disable any unknown rules.
- Change your Microsoft account password immediately.
- Sign out of all sessions and revoke unfamiliar devices.
- Enable multifactor authentication with the Microsoft Authenticator app or another strong second factor.
- Check recovery email addresses and phone numbers for unauthorized changes.
- Review sent mail, deleted items, and mailbox audit logs if available.
If this is a work account managed by an organization, report it to your IT or security team right away.
They may need to investigate sign-in logs, mailbox rules, and conditional access events in Microsoft Entra ID and Microsoft Defender for Office 365.
How to verify the account is clean after removing forwarding
Removing forwarding is important, but you should confirm the attacker no longer has a path back into the mailbox.
A clean-up is only complete when the account is locked down and the settings remain stable.
Run through a post-breach checklist
- Change the password from a device you trust.
- Use a password manager to generate a unique password.
- Review connected apps and third-party access.
- Remove suspicious app passwords if your account uses them.
- Check mailbox rules again after several hours and again the next day.
- Monitor for new forwarding, filters, or login alerts.
If forwarding reappears after you remove it, the attacker still has access or another compromised device is syncing changes back to the account.
How to reduce the chance of future Outlook forwarding attacks
Preventive controls matter because email forwarding abuse is common in phishing, business email compromise, and credential-stuffing attacks.
Strong account hygiene makes it much harder for an intruder to keep control.
- Use unique passwords for every account.
- Enable multifactor authentication on Microsoft accounts and any linked services.
- Check Outlook rules and forwarding settings regularly.
- Be cautious with remote access tools and browser extensions.
- Keep Windows, macOS, Outlook, and browsers updated.
- Train teams to spot phishing emails that request sign-in or MFA codes.
For business environments, administrators should also monitor Exchange transport rules, mailbox auditing, external forwarding policies, and suspicious sign-in activity in Microsoft Entra and Defender portals.
When to escalate to Microsoft or your IT team
If you cannot remove forwarding, if changes keep coming back, or if your organization uses managed devices, escalation is the safest path.
Microsoft support or your internal security team can help identify whether the issue is caused by a compromised password, malicious inbox rule, OAuth app abuse, or a broader endpoint compromise.
Escalate immediately if:
- The account belongs to a business, school, or government organization.
- You see forwarding to an external address you do not control.
- Messages are being deleted, redirected, or marked read without your action.
- You cannot fully regain access after a password reset.
A quick response reduces the risk of data theft and stops the attacker from using your inbox as a recovery channel for other accounts.