How to Remove Suspicious Outlook Rules
Suspicious Outlook rules can quietly move, forward, or delete messages before you ever see them.
This guide shows how to identify rule abuse, remove unwanted rules in Outlook and Microsoft 365, and harden your mailbox against repeat attacks.
What suspicious Outlook rules do
Outlook rules are automation tools that sort incoming email, but attackers often abuse them after stealing a password or session token.
A malicious rule may forward messages to an external address, delete security alerts, hide messages in RSS or archive folders, or mark them as read so you miss them.
- Forwarding rules: send copies of mail to an unfamiliar external mailbox.
- Delete rules: remove alerts from banks, payroll, or Microsoft.
- Move rules: file messages into obscure folders to delay detection.
- Mark-as-read rules: make new mail look like it was already opened.
- Admin-level mailbox rules: can be created in Microsoft 365, Exchange Online, or via compromised clients.
Signs your Outlook rules may be compromised
If you suspect compromise, look for patterns that do not match your normal workflow.
Attackers often create rules after a phishing attack, credential theft, or OAuth consent abuse, then keep the mailbox quiet while they monitor responses.
- You stop receiving expected messages from trusted senders.
- Unread counts look lower than usual despite heavy email activity.
- Security notices are missing from your inbox.
- Rules appear that you did not create.
- Mail is being forwarded outside your organization or to a personal account.
How to remove suspicious Outlook rules in Outlook on the web
Outlook on the web is often the fastest place to inspect mailbox rules because it reflects server-side rules stored in Microsoft 365 or Exchange Online.
If you have access, review the full list and delete anything unfamiliar.
- Sign in to Outlook on the web.
- Select Settings, then Mail, and open Rules.
- Review each rule name, condition, and action carefully.
- Delete rules that forward mail, remove alerts, or use suspicious addresses.
- Check for hidden variations such as rules with vague names like “Update,” “Invoice,” or “Sync.”
After deleting suspicious rules, send a test message to your account and verify that it arrives normally.
If messages still disappear, check other mail flow settings and connected inboxes.
How to remove suspicious Outlook rules in the desktop app
If you use the classic Outlook desktop app, rules may be stored locally, on the server, or both.
Removing them from the desktop client is useful, but you should still confirm the mailbox rules in Outlook on the web.
- Open Outlook.
- Go to File and select Manage Rules & Alerts.
- Review all active rules in the list.
- Clear the check box next to suspicious rules or select Delete.
- Check rule order, because earlier rules can override later ones.
If a rule returns after removal, the attacker may still have access through another device, a malicious add-in, or an authenticated app.
In that case, move quickly to account and tenant-level investigation.
How to check for hidden forwarding and inbox settings?
Some compromises do not rely on Outlook rules alone.
In Microsoft 365 and Exchange, attackers may configure mailbox forwarding, client-side filters, or inbox delegates that redirect mail without an obvious rule entry.
- Mail forwarding: verify that no external forwarding address is enabled.
- Inbox and sweep settings: check whether mail is being auto-archived or deleted.
- Delegated access: confirm that no unauthorized users can read the mailbox.
- Connected accounts: review POP, IMAP, or other linked mail systems.
For business accounts, administrators can inspect Exchange Online settings, mail flow rules, and audit logs in the Microsoft 365 admin center and Microsoft Purview.
These records can help distinguish a user-created rule from one injected by an attacker.
How to secure the account after deleting suspicious rules
Removing the rules is only one step.
If an attacker created them, they may still control the account through a stolen password, active session, or malicious app consent.
- Change the Microsoft account or work account password immediately.
- Enable multi-factor authentication if it is not already active.
- Sign out of all sessions and revoke unknown devices.
- Review recent sign-ins for impossible travel, odd IP addresses, or unfamiliar locations.
- Remove suspicious OAuth app permissions and third-party mailbox connectors.
- Run a full endpoint scan on devices used to access email.
In Microsoft 365, security teams often pair these steps with Conditional Access policies, session controls, and mailbox audit review to stop reinfection.
If a phishing email caused the issue, report and block the sender at the organization level.
How to investigate repeated rule creation?
Repeatedly recreated rules are a strong indicator of persistent compromise.
Attackers may use scripts, compromised automation, or admin privileges to reapply a mailbox rule after it is removed.
Look for the following in audit logs and account history:
- Rule creation timestamps that match suspicious login events.
- Changes from unfamiliar devices, IPs, or mail clients.
- Admin actions affecting transport rules or mailbox delegation.
- Signs of token theft, such as access without a corresponding password reset.
For enterprises, Microsoft Defender for Office 365, Microsoft Defender XDR, and Exchange admin audit logs can show whether the rule was created through Outlook, EWS, PowerShell, or the web interface.
That detail matters because each path suggests a different response.
How to prevent suspicious Outlook rules in the future?
Prevention depends on reducing the chances that an attacker can log in or silently change mailbox settings.
Strong account hygiene and monitoring are more effective than manually checking rules after every alert.
- Use phishing-resistant MFA where possible, such as FIDO2 security keys.
- Block external auto-forwarding unless it is business-approved.
- Restrict legacy authentication protocols like basic auth where supported.
- Train users to recognize consent phishing and fake Microsoft sign-in pages.
- Monitor for new rules that contain forwarding, deletion, or unread actions.
- Alert on mailbox configuration changes in Microsoft 365.
For organizations, a simple policy can go a long way: require approval for new forwarding rules, regularly review privileged access, and send alerts when inbox rules change.
For individuals, periodic rule checks and MFA provide the best balance of effort and protection.
When to escalate to IT or Microsoft support
If you cannot remove the suspicious Outlook rules, or if they reappear after deletion, escalate immediately.
The issue may involve malware, delegated access, compromised admin credentials, or a larger identity breach.
Contact IT or Microsoft support when you see any of the following:
- Rules that cannot be deleted.
- Unrecognized sign-ins or password resets.
- Mailbox forwarding outside approved domains.
- Evidence of mail theft from finance, HR, or executive accounts.
- Multiple users experiencing similar rule changes.
Quick escalation helps preserve logs, contain access, and prevent further loss of messages.
In a business environment, preserving the timeline of mailbox changes is often as important as removing the rule itself.