Why Microsoft 365 Blocks Email Auto-Forwarding, and How to Allow It Safely
A forward to Gmail or to the bookkeeper has stopped, or a customer has had a 5.7.520 bounce. That is Microsoft 365's external forwarding control at work. What it blocks, why it exists, and how to make one narrow exception.
Months ago, someone set up a rule so their work email would also land in their personal Gmail. Or the office manager arranged for every supplier invoice to go straight on to the external bookkeeper. Now it has stopped. Nothing arrives at the other end, or a customer rings to ask why their email bounced with a line about “external forwarding”.
Nothing has broken. Microsoft 365 refuses to forward mail automatically to addresses outside your organisation unless an administrator has allowed it, and in most tenants that permission is off. It can be switched back on for a named person. It shouldn’t be switched on for everyone, and there is usually a better tool than a forward anyway.
The switch sits in the outbound spam policy
Microsoft controls this through the outbound spam filter policy in the Microsoft Defender portal, among the anti-spam policies. The setting is called Automatic forwarding rules and has three values:
- Automatic – System-controlled, which is the default
- On – Forwarding is enabled
- Off – Forwarding is disabled
The default is the troublesome one. When Microsoft introduced it, “Automatic” behaved like On. In 2021 it began behaving like Off for new tenants, and for existing tenants that weren’t actively relying on it, while some older tenants where forwarding was already in use kept the permissive behaviour. Two businesses can show identical settings and get different results. A forward that has run for years proves nothing about whether forwarding is allowed in principle.
Microsoft’s documentation now tells administrators to stop leaving it on Automatic and to choose On or Off deliberately. Its recommended value, at both its Standard and Strict security levels, is Off.
The policy has two limits worth knowing. It only governs mail leaving the organisation, so a rule forwarding from one member of staff to another keeps working. And it only governs automatic forwarding. Someone opening a message and pressing Forward is sending an ordinary email.
What the bounce says, and who receives it
A blocked forward produces a non-delivery report containing this line:
5.7.520 Access denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance.
Where it lands is what confuses people. Microsoft’s Exchange team has explained that the bounce goes back to the original sender, not to the mailbox doing the forwarding. So a customer who emailed your office manager can receive a note saying their organisation doesn’t allow external forwarding, about an organisation that isn’t theirs. The office manager sees nothing wrong, because the message is sitting in their inbox as normal. And when the message came from a colleague and the forward was an inbox rule, Microsoft generates no bounce at all. The copy simply never leaves.
That combination is why the problem so often surfaces as “it just stopped”, weeks after the fact.
Three ways to forward, and which the policy catches
Inbox rules. A rule with a forward or redirect action, built in Outlook or Outlook on the web. That includes a forwarding rule tucked inside the out-of-office settings in desktop Outlook, which forwards every incoming message for as long as the out-of-office is switched on. The policy blocks all of these once forwarding is off.
Mailbox forwarding. Sometimes called SMTP forwarding, this is a property of the mailbox rather than a rule. A user can set it on the Forwarding page of Outlook on the web’s mail settings, and an administrator can set it from the Microsoft 365 or Exchange admin centre. Both routes write to the same setting, and the policy blocks it.
Mail flow rules. Also called transport rules, these are built by administrators and act on mail as it passes through the whole tenant. Microsoft documents them, alongside remote domain settings, as an extra layer for detecting and blocking forwarded mail. When one layer allows forwarding and another blocks it, the block generally wins.
When a member of staff says “my forward has stopped”, it is nearly always one of the first two.
Why Microsoft closed it by default
A silent forward is one of the most valuable things an attacker can plant after getting into a mailbox. One rule, and every invoice, remittance and password-reset email is copied to an inbox they control, while the owner’s own view looks untouched. Microsoft’s Exchange team describes it as a very common tactic in compromised accounts. It is also the quiet groundwork behind much business email compromise and invoice fraud. The fraudster reads along for weeks, learns who pays whom, then sends the “our bank details have changed” email just as a real payment falls due.
Legitimate forwards carry a smaller, duller risk. Company mail copied into a personal account is company data you can’t search, secure or retrieve, and it stays there after the person leaves.
Making one exception without opening the door
Sometimes there is a real, ongoing reason: an external bookkeeper who must receive everything sent to a supplier-invoices mailbox, say. Even then, resist changing the default policy to On. That re-enables forwarding for every mailbox in the business, including whichever one is compromised next.
Pin the default to Off. Set it explicitly, so you are no longer relying on whatever “Automatic” happens to mean in your tenant.
Create a custom outbound policy for the exception. In the Defender portal, add a new outbound anti-spam policy and scope it to the one mailbox, or to a small mail-enabled group. Custom policies are applied ahead of the default, which always sits at the lowest priority.
Set forwarding to On in that policy only. Everyone outside its scope stays blocked.
Restrict the destination too. Remote domain settings in the Exchange admin centre control automatic forwarding per destination domain. Microsoft describes combining the two, with the policy deciding who may forward and remote domains deciding where to. Used together, the invoices mailbox can forward to the bookkeeper’s domain and nowhere else.
Record the reason and a review date. An exception set up for one year-end has a way of still running five years later.
Most of the time, a forward is the wrong tool
“I want my work email on my phone.” Add the work account to the Outlook app, or use Outlook on the web. The mail stays in Microsoft 365 under your security settings, and access ends when the account is disabled.
“The bookkeeper needs to see invoices.” If they are on the payroll, give them access to an accounts@ shared mailbox. Microsoft doesn’t let people outside your organisation into a shared mailbox, so an external firm needs either the scoped exception above or invoices sent on to them deliberately.
“Someone needs to watch my inbox while I’m away.” Grant a colleague access to the mailbox itself. An internal forward would still work, but access keeps everything in one thread instead of scattering copies.
While you’re in the admin centres, look at the rest of the tenant too: multi-factor authentication, who holds admin roles, whether audit logging is on. Our guide to securing your Microsoft 365 tenant covers the layers around this one. And if you find a forward nobody admits to creating, treat it as a possible break-in rather than a quirk, and get cyber security help before you tidy anything away.
Frequently asked questions
We've found a forwarding rule that nobody remembers creating. What should we do?
Don't delete it straight away. First write down where it forwards to and which messages it matches, because that tells you what may already have left the business. Then treat the mailbox as compromised. Reset the password, sign the account out of every session, check which multi-factor methods are registered and look over recent sign-ins. Microsoft 365 logs changes to inbox rules in the mailbox audit log by default, so an administrator can usually establish when the rule appeared. Remove it only after that, and check the other mailboxes while you're there.
Our sister company is on a different Microsoft 365 account. Does forwarding to them count as external?
Yes. The policy treats anyone outside your own organisation as external, even when both businesses have the same owners. If the two companies share one tenant, with both domains added to it, forwarding between them is internal and the policy leaves it alone. If they are separate tenants and a forward between them is genuinely needed, handle it as a named exception with a custom policy rather than switching forwarding on across the board.
How can we see who is forwarding mail outside the company right now?
The Exchange admin centre has an auto-forwarded messages report listing mail automatically forwarded from your organisation to external domains. It shows the last seven days by default and can summarise up to 90 days. Run it before you set forwarding to Off and you'll know in advance whose forwards are about to stop. It only reflects forwards that are actually sending mail, so an administrator should also check forwarding settings and inbox rules directly on finance and director mailboxes.
Related services
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
