• Home
  • FAQ
  • French
  • Blog
  • Features
  • DNS toolbox
  • …  
    • Home
    • FAQ
    • French
    • Blog
    • Features
    • DNS toolbox

  • Home
  • FAQ
  • French
  • Blog
  • Features
  • DNS toolbox
  • …  
    • Home
    • FAQ
    • French
    • Blog
    • Features
    • DNS toolbox
Request a Free Trial
  • Home
  • FAQ
  • French
  • Blog
  • Features
  • DNS toolbox
  • …  
    • Home
    • FAQ
    • French
    • Blog
    • Features
    • DNS toolbox

  • Home
  • FAQ
  • French
  • Blog
  • Features
  • DNS toolbox
  • …  
    • Home
    • FAQ
    • French
    • Blog
    • Features
    • DNS toolbox
Request a Free Trial

Securing Email Forwarding in Exchange Online

Best Practices for Administrators

The 2 types of e-mails forwarding

Email forwarding in Exchange Online can be configured in two places:


1) Inbox Rules Forwarding (Outlook)

Normal Users can configure forwarding by creating inbox rules to automatically forward emails to another address directly from the Outlook application :

Section image

 

2) SMTP Forwarding (Exchange Admin Portal)

Administrative users can set up SMTP forwarding to redirect emails to another address directly from the Exchange Admin Center.

Section image

How to audit e-mails forwarding in your organization?

To audit e-mails forwarding in your organization you can connect to the new Exchange Online report showcasing all forwarded messages :

Auto forwarded messages
Section image

Or you could run some Powershell commands like the ones described in the article here :

Powershell commands

You can also set alerts to be alerted whenever a forwarding rule is configured :

Alert policies

From there, you might have noticed forwards that appear legitimate from a business perspective.

However, there might also be e-mail forwards to personal mailboxes or unknown domains that you wish to prevent.

How to restrict the domains that are allowed to received forwarded e-mails?

Here’s how you can manage and restrict such forwarding:

1- Configure the Default Outbound Anti-Spam Policy:

Enable automatic forwarding in the default outbound anti-spam policy.

Anti-spam policies
Section image

If automatic forwarding is blocked at this level, all forwarded emails will be stopped. Since it’s necessary to allow forwarding to certain domains (For example to forward invoices to the mailbox used by an automatic invoices management SaaS solution), this setting should be enabled.

2- Configure “Remote Domains” Rules:

Remote domains

Establish rules for “remote domains” to authorize the forwarding of emails to specific domains that are considered legitimate and safe for receiving forwarded emails :

Section image

3- Adjust the Default “Remote Domains” Rule:

Modify the default “remote domains” rule to block forwarded emails unless a domain has been specifically authorized as outlined in step 2 :

Section image

If you would like to further control who is authorized to forward emails to the approved remote domains, follow these two additional steps:

4- Create an outbound antispam policy to authorize a list of users to forward e-mails :

Anti-spam policies
Section image

5- Configure the “default” outbound antispam policy to disallow automatic forwarding :

Section image

By implementing these five steps, you will have effectively controlled automatic email forwarding within your organization.

Your organization is now protected against data leaks through the forwarding of emails to external entities over which you have no control.

Official documentation from Microsoft :

Configuring and controlling external email forwarding in Microsoft 365 | Microsoft Learn

Remote domains in Exchange Online | Microsoft Learn

Manage remote domains in Exchange Online | Microsoft Learn

All you need to know about automatic email forwarding in Exchange Online — Microsoft Community Hub

Alert policies in Exchange Online | Microsoft Learn

 

Previous
Beyond DMARC: Persistent Challenges in Combating Identity...
Next
SECOPS : Risks of using an antispam in front of Exchange...
 Return to site
Profile picture
Cancel
Cookie Use
We use cookies to improve browsing experience, security, and data collection. By accepting, you agree to the use of cookies for advertising and analytics. You can change your cookie settings at any time. Learn More
Accept all
Settings
Decline All
Cookie Settings
Necessary Cookies
These cookies enable core functionality such as security, network management, and accessibility. These cookies can’t be switched off.
Analytics Cookies
These cookies help us better understand how visitors interact with our website and help us discover errors.
Preferences Cookies
These cookies allow the website to remember choices you've made to provide enhanced functionality and personalization.
Save