How to Check Outlook Rules for Hackers: A Practical Security Guide for 2026

Written by: Abigail Ivy
Published on:

How to Check Outlook Rules for Hackers

If your emails are disappearing, forwarding unexpectedly, or being marked as read without your input, Outlook rules may be involved.

This guide explains how to check Outlook rules for hackers, what suspicious rule behavior looks like, and how to remove unauthorized access quickly.

Attackers often abuse Outlook rules to hide security alerts, auto-forward messages, or move sensitive mail into obscure folders.

Knowing where to look can reveal compromise faster than a password reset alone.

Why Outlook rules are a common attack target

Microsoft Outlook rules are designed to automate inbox management, but they can also be abused after an email account takeover.

Once a threat actor gains access to Microsoft 365, Outlook.com, or an Exchange mailbox, rules can help them stay hidden and collect valuable messages.

Common attacker goals include:

  • Suppressing security notifications from Microsoft, banks, or identity providers
  • Auto-forwarding messages to an external address controlled by the attacker
  • Moving mail with keywords like “password,” “invoice,” or “verification” into a hidden folder
  • Marking messages as read so the mailbox owner does not notice them
  • Deleting evidence of login alerts, reset links, or suspicious activity warnings

These tactics are widely associated with business email compromise, credential theft, and post-compromise persistence in Microsoft 365 environments.

How to check Outlook rules for hackers in Outlook desktop

In the Outlook desktop app, you can inspect both inbox rules and advanced rules that may not be obvious at first glance.

  1. Open Outlook and select File.
  2. Choose Manage Rules & Alerts.
  3. Review every listed rule carefully.
  4. Look for rules that you do not recognize, especially those created recently.
  5. Inspect the Apply changes to this folder setting if multiple mailboxes are configured.

Pay special attention to the rule actions.

Suspicious actions often include moving mail to a non-obvious folder, forwarding to an external address, deleting messages, or marking items as read.

Also review the order of rules, because attackers may place hidden rules above legitimate ones so their actions happen first.

What Outlook desktop rule red flags should you look for?

  • Rules with generic names such as “Update,” “System,” or “Inbox cleanup”
  • Rules created when you were not actively using the account
  • Conditions that trigger on financial, security, or executive keywords
  • Actions that forward, redirect, or delete mail
  • Rules that apply to all messages without a clear reason

How to check Outlook rules for hackers in Outlook on the web

Outlook on the web is often easier to audit because Microsoft places rule controls in a central settings area.

This is especially useful if you suspect mailbox compromise in Microsoft 365.

  1. Sign in to Outlook on the web.
  2. Select the Settings gear icon.
  3. Go to Mail and then Rules.
  4. Review each inbox rule for unfamiliar names, actions, and recipients.
  5. Check whether a rule automatically forwards, redirects, or deletes messages.

Also review related mail settings, not just rules.

Attackers sometimes use multiple persistence methods at once, including automatic forwarding, blocked senders, and delegate access.

What should you check beyond inbox rules?

  • Forwarding settings: confirm no external address has been added
  • Blocked and safe senders: make sure security alerts are not being filtered out
  • Delegate access: remove any person or app you do not recognize
  • Connected accounts: verify no other mailbox is pulling your mail
  • Mail flow rules: in business environments, check Exchange transport rules through admin tools

Signs that Outlook rules may have been tampered with

Unauthorized rules are often discovered after the account owner notices small but important symptoms.

These signs do not prove compromise on their own, but they should trigger immediate review.

  • Missing emails from Microsoft, Apple, Google, your bank, or your HR platform
  • Messages marked as read even though you never opened them
  • Items appearing in folders you do not remember creating
  • Unexpected “forwarded” behavior or replies you did not send
  • Security alerts that arrive late or not at all
  • Changes in mailbox behavior after a phishing email or password reset

In Microsoft environments, mailbox auditing, sign-in logs, and audit logs can help confirm whether a rule was created during suspicious activity.

How hackers use rules to hide their tracks

Threat actors usually do not rely on one simple rule.

They combine multiple actions to make detection harder and maintain access longer.

Common patterns include:

  • Keyword-based filtering: Rules target subjects like “invoice,” “security alert,” or “verification code.”
  • Silent forwarding: Mail is copied to an external inbox so the attacker can monitor resets and conversations.
  • Auto-deletion: Alerts are deleted before the owner notices them.
  • Folder redirection: Messages are sent into a low-traffic folder and left unread or marked read.
  • Reply manipulation: In more advanced cases, rules are paired with mailbox delegation or malicious OAuth app access.

Because of this, checking only the visible inbox is not enough.

You need to review the rule logic, the destination addresses, and the surrounding account settings.

How to remove suspicious Outlook rules safely

If you find rules you did not create, remove them immediately and treat the account as potentially compromised.

  1. Delete any suspicious rules.
  2. Remove unauthorized forwarding addresses.
  3. Change the account password.
  4. Sign out of all sessions if your provider supports it.
  5. Enable or reset multi-factor authentication.
  6. Review recent sign-ins and revoke unknown devices or app access.

If this is a work account, alert your IT or security team before making major changes.

They may need to preserve logs, investigate adjacent accounts, and check for malicious forwarding at the tenant level in Microsoft 365 or Exchange Online.

How to harden Outlook against future rule abuse

After cleanup, focus on reducing the chance of repeat compromise.

Outlook rules are only dangerous when an attacker can access the account or apply mailbox changes.

  • Use a strong, unique password stored in a password manager
  • Enable phishing-resistant multi-factor authentication where possible
  • Review rules regularly, especially after travel or password changes
  • Disable automatic forwarding to external domains unless business policy requires it
  • Restrict OAuth app consent in Microsoft 365 environments
  • Monitor for impossible travel, unfamiliar devices, and suspicious sign-ins

Organizations should also use Microsoft Defender for Office 365, Exchange audit logging, and alerts for inbox rule creation, especially for executive, finance, and help desk mailboxes.

When to escalate to incident response

If you see suspicious rules alongside password resets you did not request, mailbox login alerts, or evidence of sent mail you did not author, treat the issue as an active security incident.

That is especially important if the mailbox contains payment approvals, customer data, or access to other services.

Escalate immediately when:

  • Rules keep reappearing after deletion
  • Messages are being forwarded externally without authorization
  • Multiple accounts show similar rule changes
  • You suspect business email compromise or credential theft
  • The mailbox is tied to administrative or financial systems

Quick inspection, log review, and account containment are the fastest way to stop further abuse and recover control of the mailbox.