If you suspect your Outlook email is being forwarded to an unknown address, the issue may be a hidden rule, mailbox setting, or account compromise.
This guide explains how to remove unknown forwarding address from Outlook and secure the account before more mail is exposed.
What an unknown Outlook forwarding address usually means
An unknown forwarding address is typically an email address set to receive copies of your incoming messages without your approval.
In Microsoft Outlook and Microsoft 365, forwarding can be configured in several places, including inbox rules, mailbox settings, Exchange admin settings, and even account-level permissions.
Because forwarding can happen silently, you may not notice it until messages start disappearing, replies look odd, or you receive login alerts from Microsoft.
In many cases, the forwarding was added by malware, a malicious actor, or a legitimate rule created long ago and forgotten.
Check Outlook rules first
Inbox rules are one of the most common ways email is forwarded automatically.
These rules can be created in Outlook desktop, Outlook on the web, or by server-side mailbox settings, and they often run without showing obvious warnings.
How to review rules in Outlook desktop
- Open Outlook.
- Go to File and select Manage Rules & Alerts.
- Review every rule carefully, especially rules that mention forwarding, redirecting, moving, deleting, or marking messages as read.
- Delete any rule that sends messages to an unfamiliar email address.
How to review rules in Outlook on the web
- Sign in to Outlook on the web.
- Select the Settings gear icon.
- Go to Mail > Rules.
- Look for rules that forward or redirect mail to addresses you do not recognize.
- Remove suspicious rules and save your changes.
If you see a rule that looks legitimate but forwards mail externally, verify who created it and whether it is still needed.
Old auto-forwarding rules are a common cause of mail being sent to a forgotten address after a job change or domain migration.
Inspect mailbox forwarding settings
Some forwarding is not caused by a rule at all.
Outlook may show normal behavior while the mailbox itself forwards mail at the server level, especially in Microsoft 365, Exchange Online, or Exchange Server environments.
Where to look for mailbox forwarding
- Mailbox forwarding: A setting that sends all incoming mail to another address.
- Forwarding SMTP address: A specific external destination assigned to the mailbox.
- POP/IMAP client rules: Client-side sync or automation settings that trigger forwarding behavior.
If you use a work account, your IT or Microsoft 365 administrator may need to check the Exchange admin center or Exchange Online PowerShell.
In many organizations, external auto-forwarding is restricted because it is a common exfiltration method used in phishing and business email compromise attacks.
Remove forwarding in Microsoft 365 or Exchange
For Microsoft 365 users, forwarding can be configured outside the Outlook interface.
If you are an admin, verify the mailbox itself rather than relying only on the user’s Outlook view.
Admin areas to review
- Exchange admin center: Check mailbox forwarding and mail flow rules.
- Inbox rules: Review server-side rules that may redirect messages.
- Mail flow rules: Look for transport rules that copy or redirect messages externally.
- Azure AD / Microsoft Entra ID: Review suspicious sign-ins and app consent.
If you find an unknown forwarding address, remove it immediately and document the change.
Then check whether the address appears in any transport rules, delegated access settings, or automated workflows such as Power Automate flows that interact with email.
Check whether your account is compromised
Unknown forwarding is often a sign that someone has access to your account.
Changing one setting is not enough if the attacker still has a password, active session, or app token.
Signs of account compromise
- Unexpected sign-in alerts from Microsoft
- Unread messages you did not open
- Sent items you do not recognize
- Rules that delete, archive, or forward mail secretly
- Changes to recovery email or phone number
Security steps to take immediately
- Change your Outlook/Microsoft password.
- Enable multi-factor authentication if it is not already active.
- Sign out of all sessions and revoke unknown devices.
- Review recovery email addresses and phone numbers.
- Remove unfamiliar connected apps and OAuth permissions.
Microsoft Defender for Office 365, Microsoft Entra sign-in logs, and account security history can help identify how the forwarding was added.
If a malicious login occurred, focus on containment first and cleanup second.
Look for hidden forwarding in other places
Forwarding can be hidden in less obvious places, especially in mixed environments where users access the same mailbox through multiple clients.
Check every layer that could influence mail delivery.
Common locations to verify
- Outlook mobile app: Some settings are controlled at the account level and may not be obvious in the app.
- Third-party mail apps: Apple Mail, Thunderbird, or mobile clients may apply their own rules.
- Email signatures and add-ins: Malicious add-ins can alter mail behavior.
- Shared mailboxes: Delegates may have configured forwarding from a shared account.
If you use an IMAP account, the provider’s webmail interface is often the best place to confirm forwarding, because Outlook desktop may not show every server-side setting.
For Exchange and Microsoft 365 accounts, webmail plus admin tools usually provide the clearest view.
How to prevent forwarding from coming back
Once the unknown forwarding address is removed, harden the account so it cannot be restored easily.
This is especially important after phishing, credential theft, or a security incident involving Microsoft accounts.
Best prevention practices
- Use a strong, unique password stored in a password manager.
- Turn on multi-factor authentication for Outlook and Microsoft 365.
- Review inbox rules regularly, especially after password resets.
- Disable external auto-forwarding unless your organization truly needs it.
- Audit mailbox permissions and delegate access periodically.
- Watch for new rules that move messages to RSS, archive, or junk folders.
For business tenants, consider alerting on suspicious forwarding rules and outbound mail to external recipients.
Security monitoring can catch exfiltration patterns faster than manual checks.
When to contact Microsoft support or your IT team
Contact support if the forwarding setting keeps reappearing, if you cannot delete it, or if the account behaves differently after each change.
Recurrent forwarding often indicates a broader compromise, policy enforcement, or administrative control you do not see in the Outlook interface.
In a workplace environment, ask IT to review mailbox audit logs, sign-in history, transport rules, delegated permissions, and any security alerts from Microsoft Defender or Entra ID.
In a personal account, Microsoft Support can help if the problem is tied to account recovery or unauthorized access.
Quick checklist for removing unknown forwarding in Outlook
- Review Outlook inbox rules.
- Check mailbox forwarding settings in Outlook on the web.
- Inspect Microsoft 365 or Exchange admin settings.
- Change your password and enable MFA.
- Sign out of all sessions and remove unknown devices.
- Delete suspicious rules, add-ins, and connected apps.
- Monitor the account for repeated changes or login alerts.
Following these steps gives you the fastest path to remove unknown forwarding address from Outlook and reduce the chance of future email interception.