Email rules are actually designed to organize your inbox: automatically moving, forwarding, or marking messages as read. It is precisely these functions that make them attractive to attackers once an account has been compromised. In many cases, at least one malicious email rule is created shortly after the initial access, sometimes within seconds of the unauthorized login. We’ll show you how these attacks work and how you can protect yourself.
What types of malicious rules are created?
Email rules can be created or modified in several ways: via the Microsoft Graph API, using PowerShell, through the web interface for Outlook, or via the desktop client.
The most common types are forwarding rules to external addresses and rules that manipulate messages to hide them from the user’s view. The next section explains the specific goals attackers pursue with these tactics. A third, much rarer variant involves the mass creation of rules via compromised administrator accounts.
In practice, this poses a challenge for IT security professionals: Since users constantly forward emails or organize folders for entirely legitimate reasons, it is difficult to filter out which rules are actually malicious from the sheer volume of alerts.
It is therefore advisable to limit the content of out-of-office messages to the bare essentials and, whenever possible, to avoid automatically sharing internal details such as the names of substitutes or contact information with external parties.
What are the objectives of rule abuse?
Four recurring objectives can be identified from documented attack cases:
How a Real Attack Might Unfold
A documented case shows how rule abuse and internal phishing can be combined to carry out a targeted payroll fraud:
After taking over an accounting employee’s account, the attackers created a rule that automatically moved emails with a specific subject line to the archive. They then used the same subject line in an internal phishing campaign targeting 45 other employees, including the executive assistant, whose account was also compromised. There, the pattern repeated itself with a second, thematically matching rule, before a fraudulent payment instruction was sent to the payroll department. Because the rules suppressed follow-up inquiries and warning messages, the entire process initially remained invisible to those affected.
What to Look Out For
There are a number of typical warning signs that indicate an attack using email rules:
For the specific evaluation of an alarm related to a forwarding rule, Microsoft recommends, among other things, the following steps:
Larger organizations can further automate such criteria through targeted log queries, for example, to determine whether multiple users have created rules with the same suspicious target, a possible indication of a widespread campaign.
Key Immediate Steps
If an account is suspected of being compromised, Microsoft recommends a multi-step approach:
Simply changing a password is not enough, since an existing redirect rule remains active regardless of the password, and session tokens must be revoked separately.
The risk can be reduced primarily through three measures: disabling automatic redirection to external addresses by default, consistently enforcing multi-factor authentication and conditional access, and actively monitoring new OAuth consents and application permissions.
How NoSpamProxy Protects You
The most effective defense against the attacks described begins even before a malicious rule can be created: during the account takeover itself, that is, at the points in the attack chain that involve email traffic.
Preventing Initial Access
Since the attacks described typically begin with methods such as credential phishing, reliably blocking such emails is the most effective way to counter the entire attack chain. NoSpamProxy’s URL Safeguard checks links not only upon delivery but also when they are actually clicked, thereby detecting phishing sites that are activated only after the fact. This delayed activation is a tactic that bypasses many traditional filters, which only check once at the time of delivery. With NoSpamProxy, you’re protected.
A multi-step verification of sender reputation using SPF, DKIM, and DMARC makes it more difficult to use spoofed sender addresses and significantly hinders attackers’ ability to impersonate a trusted contact.
Heuristic and AI-powered analysis methods in 32Guards identify suspicious patterns even in novel, previously unknown campaigns. Content Disarm and Reconstruction (CDR) automatically neutralizes Office and PDF attachments, regardless of whether a matching signature is already known, and a sandbox analysis checks potentially malicious files before they even reach the inbox.
Limiting Internal Spread
In documented cases, attackers use an already compromised account to send an internal phishing email to numerous colleagues—often the step that causes the actual damage. Whether NoSpamProxy also captures these messages depends on the integration: If only traffic to and from external sources passes through the gateway, purely internal email is not included.
If internal email traffic is also routed through NoSpamProxy, the same scanning mechanisms — link analysis, attachment scanning, and behavioral patterns — are applied to messages sent within the organization as well. For companies that take this risk seriously, it is therefore worth taking a close look at their own email flow architecture.
Protecting Domain Reputation Externally
Consistent enforcement of SPF, DKIM, and DMARC also makes it easier for customers and suppliers to detect forged messages sent in the name of their own domain, or to prevent them from being delivered in the first place. This protects not only your own organization but also your business partners, who would otherwise become targets of fraud attempts using a forged sender domain, for example, in downstream attacks such as the payroll fraud described above.
One Component of a Multi-Layered Security Strategy
NoSpamProxy reliably covers the part of the attack chain that most often serves as the starting point in practice: initial access via a phishing email. If this access is prevented, the malicious mailbox rule is never created in the first place, and this is the most effective and cost-efficient form of protection. In addition, consistent identity verification through MFA and conditional access, as well as ongoing monitoring of rule changes and login behavior, remain important so that a rapid response is possible in the event of an incident.
Not yet using NoSpamProxy?
NoSpamProxy provides reliable protection for your business against dangerous emails. Request your free trial now!




