• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCTS
    • Platforms
      • NoSpamProxy Cloud
      • NoSpamProxy Server
      • NoSpamProxy 25Reports
  • SOLUTIONS
    • Threat Protection
      • Protection against Spam, Phishing & Malware
      • AI Threat Detection
      • Isolated File Analysis
      • Microsoft 365 Mail Security
    • Secure Email Communication
      • Email Encryption
      • Automatic Certificate Management
      • Search for Public Keys
    • Productivity & Compliance
      • Sending Large Files
      • Email Disclaimer
  • INDUSTRIES
    • By Company Size
      • Large Companies
      • Small and Medium-Sized Enterprises
    • Regulated Industries
      • Public Institutions
      • Healthcare
      • Finance
      • Law
    • Success Stories
      • Testimonials
      • Awards
  • PARTNERS
    • Resellers
      • Finding Resellers
      • Become a Reseller
      • Become an MSP Partner
    • For Existing Partners
      • Partner Portal
      • Partner Trainings
      • NFR Licenses
  • RESOURCES
    • Support
      • Online Documentation
      • Forum
      • Support
    • Continuing Education
      • Training Courses
      • Webcasts
    • Knowledge
      • Blog
      • Newsletter
    • Downloads
      • NoSpamProxy Server
    • Events
      • Events
      • Webcasts
  • PRICING
  • CONTACT
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Email Rules as a Point of Entry: How Attackers Take Control of Microsoft 365 After Compromising an Account

Stefan Feist | Technischer Redakteur
Author: Stefan FeistTechnical Writerhttps://www.linkedin.com/in/stefan-feist-23b257b0/–Connect on LinkedIn

Email rules are actually designed to organize your inbox: automatically moving, forwarding, or marking messages as read. It is precisely these functions that make them attractive to attackers once an account has been compromised. In many cases, at least one malicious email rule is created shortly after the initial access, sometimes within seconds of the unauthorized login. We’ll show you how these attacks work and how you can protect yourself.

24.07.2026|Last edited:23.07.2026

What types of malicious rules are created?

Email rules can be created or modified in several ways: via the Microsoft Graph API, using PowerShell, through the web interface for Outlook, or via the desktop client.

The most common types are forwarding rules to external addresses and rules that manipulate messages to hide them from the user’s view. The next section explains the specific goals attackers pursue with these tactics. A third, much rarer variant involves the mass creation of rules via compromised administrator accounts.

In practice, this poses a challenge for IT security professionals: Since users constantly forward emails or organize folders for entirely legitimate reasons, it is difficult to filter out which rules are actually malicious from the sheer volume of alerts.

It is therefore advisable to limit the content of out-of-office messages to the bare essentials and, whenever possible, to avoid automatically sharing internal details such as the names of substitutes or contact information with external parties.

What are the objectives of rule abuse?

Four recurring objectives can be identified from documented attack cases:

  • Covert Data Exfiltration

    Forwarding or rerouting rules automatically send copies of relevant emails to externally managed mailboxes, often filtered by keywords such as “invoice,” “bank transfer,” or “contract.”

  • Cover-up of the attack

    Rules that delete, mark as read, or move messages suppress security alerts, password reset emails, and MFA notifications, in other words, exactly the kinds of notifications that could reveal a security breach.

  • Persistence Without Malware

    An active forwarding rule survives a password change. As long as it is not removed, information continues to be leaked, even if access to the actual account has long since been terminated.

  • Manipulation of Communication

    If certain emails are deliberately redirected to hidden folders, attackers can intercept messages from suppliers or customers, impersonate account holders, or infiltrate existing email threads, with effects similar to those of a classic man-in-the-middle attack, but without needing a foothold in the network.

How a Real Attack Might Unfold

A documented case shows how rule abuse and internal phishing can be combined to carry out a targeted payroll fraud:

After taking over an accounting employee’s account, the attackers created a rule that automatically moved emails with a specific subject line to the archive. They then used the same subject line in an internal phishing campaign targeting 45 other employees, including the executive assistant, whose account was also compromised. There, the pattern repeated itself with a second, thematically matching rule, before a fraudulent payment instruction was sent to the payroll department. Because the rules suppressed follow-up inquiries and warning messages, the entire process initially remained invisible to those affected.

What to Look Out For

There are a number of typical warning signs that indicate an attack using email rules:

  • Automatic Forwarding to Unknown Addresses

  • Rules that move messages to folders such as Notes, Junk Email, or RSS Feeds

  • Unusual entries in the “Sent Items” or “Deleted Items” folders.

  • Changes to contact information in the global address book or unusually frequent password changes

For the specific evaluation of an alarm related to a forwarding rule, Microsoft recommends, among other things, the following steps:

  • Recipient of the rule

    Is this an external address not associated with the company, or is it another legitimate email address belonging to the same person?

  • Filter Criteria

    Does the rule target suspicious keywords such as “finance” or “login credentials,” or does it forward all messages without exception?

  • Context of the Application

    Do the IP address, internet service provider, and location match the user’s previous behavior, or were there any other suspicious login attempts beforehand?

Larger organizations can further automate such criteria through targeted log queries, for example, to determine whether multiple users have created rules with the same suspicious target, a possible indication of a widespread campaign.

Key Immediate Steps

If an account is suspected of being compromised, Microsoft recommends a multi-step approach:

  • Deactivate the account or, if that is not possible, reset the password. Important: Do not send the new password to the user via email, as the attacker may still have access to the email account at that point.

  • Revoke active sessions and tokens so that stolen credentials are immediately invalidated.

  • Check MFA devices and app permissions, and remove unknown devices or permissions.

  • Check assigned admin roles and revoke any permissions that are no longer needed.

  • Check email forwarding settings and mailbox rule both at the mailbox level (SMTP forwarding) and at the rule level, including hidden rules, and remove any unauthorized ones.

Simply changing a password is not enough, since an existing redirect rule remains active regardless of the password, and session tokens must be revoked separately.

The risk can be reduced primarily through three measures: disabling automatic redirection to external addresses by default, consistently enforcing multi-factor authentication and conditional access, and actively monitoring new OAuth consents and application permissions.

How NoSpamProxy Protects You

The most effective defense against the attacks described begins even before a malicious rule can be created: during the account takeover itself, that is, at the points in the attack chain that involve email traffic.

Preventing Initial Access

Since the attacks described typically begin with methods such as credential phishing, reliably blocking such emails is the most effective way to counter the entire attack chain. NoSpamProxy’s URL Safeguard checks links not only upon delivery but also when they are actually clicked, thereby detecting phishing sites that are activated only after the fact. This delayed activation is a tactic that bypasses many traditional filters, which only check once at the time of delivery. With NoSpamProxy, you’re protected.

A multi-step verification of sender reputation using SPF, DKIM, and DMARC makes it more difficult to use spoofed sender addresses and significantly hinders attackers’ ability to impersonate a trusted contact.

Heuristic and AI-powered analysis methods in 32Guards identify suspicious patterns even in novel, previously unknown campaigns. Content Disarm and Reconstruction (CDR) automatically neutralizes Office and PDF attachments, regardless of whether a matching signature is already known, and a sandbox analysis checks potentially malicious files before they even reach the inbox.

Limiting Internal Spread

In documented cases, attackers use an already compromised account to send an internal phishing email to numerous colleagues—often the step that causes the actual damage. Whether NoSpamProxy also captures these messages depends on the integration: If only traffic to and from external sources passes through the gateway, purely internal email is not included.

If internal email traffic is also routed through NoSpamProxy, the same scanning mechanisms — link analysis, attachment scanning, and behavioral patterns — are applied to messages sent within the organization as well. For companies that take this risk seriously, it is therefore worth taking a close look at their own email flow architecture.

Protecting Domain Reputation Externally

Consistent enforcement of SPF, DKIM, and DMARC also makes it easier for customers and suppliers to detect forged messages sent in the name of their own domain, or to prevent them from being delivered in the first place. This protects not only your own organization but also your business partners, who would otherwise become targets of fraud attempts using a forged sender domain, for example, in downstream attacks such as the payroll fraud described above.

One Component of a Multi-Layered Security Strategy

NoSpamProxy reliably covers the part of the attack chain that most often serves as the starting point in practice: initial access via a phishing email. If this access is prevented, the malicious mailbox rule is never created in the first place, and this is the most effective and cost-efficient form of protection. In addition, consistent identity verification through MFA and conditional access, as well as ongoing monitoring of rule changes and login behavior, remain important so that a rapid response is possible in the event of an incident.

Not yet using NoSpamProxy?

NoSpamProxy provides reliable protection for your business against dangerous emails. Request your free trial now!

Get your free NoSpamProxy trial
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

NoSpamProxy Newsletter

Subscribe to Newsletter

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • News
  • Product
  • Product
  • Tech & Support
  • Tech & Support
  • Events
  • Events
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • About us
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Finding resellers
  • Becoming a reseller
  • Becoming a MSP Partner
  • Newsletter Subscription
  • Order Certificates

Categories

  • All topics
  • News
  • Support
  • Product
  • Events
  • Updates

Latest News

  • Info Icon
    Action Required: Renew Permissions for the Entra ID User Import14.08.2026 - 13:59
  • info icon
    NoSpamProxy and TLS Certificates: What Will Change by 202907.08.2026 - 10:00
  • NoSpamProxy Update
    Security Enhancement: Optimized Sender Verification for the Microsoft 365 Connector05.08.2026 - 13:05
IMPRINT • EULA • Privacy Policy • • © 2026 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: NoSpamProxy Server 16.1 is now available Link to: NoSpamProxy Server 16.1 is now available NoSpamProxy Server 16.1 is now availableNoSpamProxy Server 16.1 Link to: Understanding DMARC Reports and Making the Most of Them Link to: Understanding DMARC Reports and Making the Most of Them DMARC-Reports verstehen und wirklich nutzen 800x800Understanding DMARC Reports and Making the Most of Them
Scroll to top Scroll to top Scroll to top