Podcast/Episode 2026-3

This Is the First Thing a Hacker Does to Your Inbox

Episode 2026-3

Key Takeaways

  • Email forwarding is one of the first things a threat actor sets up after gaining access to an account, allowing them to monitor communications without staying inside the compromised mailbox.
  • Business email compromise is more prevalent than ransomware and is the primary attack method where inbox forwarding rules are exploited.
  • The recommended alternative to forwarding is adding the work email as an additional account using official apps such as Microsoft 365 Mobile or Google Enterprise, not a third-party application.
  • Organizations can disable email forwarding at the tenant level so no user can create forwarding rules, eliminating the risk across the board.
  • DaZZee IT receives immediate alerts when a forwarding rule is created or when an account is accessed by an unrecognized user, enabling rapid response before damage is done.

Full Transcript

Welcome and Introduction

Shane Naugher: Well, hey, guys, and welcome back to Give IT To Me Straight, where we dive into IT issues and questions that we typically get in terms of serving our clients here at DaZZee IT. I am extremely excited to have Dom Maxwell joining us today. Dom sits on our rapid response team. Dom's been with us now a little over three years and is one of our client favorites when they call in and ask for support. Dom, thank you for hopping on with me. I'm excited for the conversation today.

Dom Maxwell: Of course, Shane, thank you for having me. I have been seeing some of the podcasts with some of my coworkers on there, and I'm excited I got a chance to hop on and be a part of it.

Why Is Email Forwarding a Security Risk?

Shane Naugher: Absolutely. We're going to continue those discussions. Dom, I thought today we would dive into the subject of email forwarding. This is something I think we see from a variety of our clients, and while the intentions are typically good, there are some risks. In terms of best practices, we recommend disabling forwarding of email as a general practice, even at the tenant level so that no one can do that. If you don't mind, Dom, dive into why that is, what we see when it comes to email forwarding, and why we recommend that it not be a general policy.

Dom Maxwell: Yeah. Typically email forwarding is the primary method of getting communications outside of channel. If there were a threat actor involved and they wanted to have a whole list of correspondence with other emails, or they're trying to exfiltrate information or data, getting that outside of the original mailbox and into one of their own choosing would be the first step to take.

How Does This Connect to Business Email Compromise?

Shane Naugher: Absolutely. And that's key because everyone's at least somewhat familiar with and worried about ransomware. But quite often we see business email compromise as the larger threat and the more frequent threat. To that point, that's kind of the first step that a threat actor would take, right?

Dom Maxwell: Yep. And like you said, with business email compromise being more prevalent, it is again probably the primary method being employed that I see more often than not on the desk right now.

Shane Naugher: Yep. So in those scenarios, the bad guys get access to an email account, and the typical flow of actions is they get in and they want to make sure that the original account owner is not aware of what's going on. A lot of times they'll set up forwarding to an outside email address. That way they don't have to stay inside the account, but all that mail flows out to an external account. They do that for several reasons: monitoring what's coming in, identifying who the vendors are, what projects are going on, what the high-value items are being processed back and forth. In terms of a threat, that gives them credible information they can then use for malicious purposes, right?

Dom Maxwell: Yep. Again, whether it be proprietary information that comes into that mailbox, PCI data, or numerous other things that can be compromising, not just for the user whose mailbox they have but for their company, other users, or clients they may have.

Shane Naugher: Absolutely. And in that business email compromise scenario, that type of information is what really creates the risk and makes those emails they can send and invoices they can modify really ramp up in terms of severity. I know we get those requests quite frequently from people who really have not thought that far into it. What are the options to enable what they're looking for, which is getting that email beyond just their desktop?

What Are the Secure Alternatives to Email Forwarding?

Dom Maxwell: I think primarily what we push to do, and it remains within best practices, is use the official applications that are tied to those email addresses. Whether it's a Microsoft tenant and we're using Microsoft 365 Mobile, or a Google Suite with a Google Enterprise account, those are the two primary methods we would want them to stick with. As soon as you start getting into third-party applications, you're opening yourself up to the risk of that forwarding happening.

Shane Naugher: Yeah. And I think people, we get this a lot with our city council members for the clients that we serve. They need to get that email, they've got their own personal email address, and they say, "Well, it's already set up on my phone. Can't we just forward it there?" So your recommendation would be not to forward it but to actually set it up as an additional account?

Dom Maxwell: Completely set up as an additional account. Another acceptable solution, more secure than a third-party mailbox but still less secure than using those official apps, would be web portal access for those applications. A lot of those accounts are still going to be behind multi-factor authentication, in which case they're protected in that manner. That's something we can enable and go down that route, but only in situations where they can't use a Microsoft 365 application or Outlook on their mobile phone. We also see a lot of Chromebook users, and in that case it has to be the web browser since it's not a native Chromebook application at this time.

Can Organizations Lock Down Forwarding Across the Entire Tenant?

Shane Naugher: Got it. Makes sense. As organizational leaders, we've gotten this question before: now that we understand the risk, can we keep our employees or team members from doing that as a whole?

Dom Maxwell: You can apply that across the entire tenant. If it's a city, for example, you can apply it across the whole city tenant so that mail forwarding is not a rule that's able to be set up. We also use a security tool set here at DaZZee IT where if a mail forwarding rule is employed, we will get a notification. There are those rare situations where somebody has set up a mail rule purposefully because they're doing some sort of testing or enabling a specific Microsoft application that requires it. Even in that case, we still get that notification, and we can reach out to the user and say, "Was this intentional or was it not?" to help keep them further secured.

How Quickly Does DaZZee IT Detect a Threat Actor Setting Up Forwarding?

Shane Naugher: That's great. And you hit on a key point that I think is crucial. Going back to what happens in a real-life threat scenario, setting up forwarding is one of the first things a threat actor will do after getting in. So for our clients, you guys have an alerting system set up and you know immediately, right?

Dom Maxwell: Yep. We know immediately. And even before that, if it is a situation where a threat actor has gained access to the account, we're going to get a notification on that front too. So it's two ways: we'll get the notification that the account has been signed into and it's not necessarily the user in question, and then also a flag to look at the mail forwarding rules because that was set up before the account was resecured.

Final Recommendations for Clients

Shane Naugher: This makes a lot of sense, and I know some of our clients approach it from a purely intentional perspective. They're not trying to do anything outside the normal bounds. They just don't understand that it can be an additional risk. The best thing I can recommend for clients or others is to have that communication with you all. If you've got specific needs to get email outside of the normal bounds, reach out. We'll be happy to discuss that and give solutions and recommendations. Are there any other thoughts you have around making sure we have complete control over this and are locking it down as tight as possible?

Dom Maxwell: Yeah. Email is the primary form of communication for internal and external use. It's used for everything. It is one of the top things we want to push to ensure safety and security by managing that. The second that you lose visibility on any incoming or outgoing emails, whether they be malicious or otherwise, it's too late.

Shane Naugher: That's great. I appreciate the fact that you guys have put in all the work to help establish those policies. I really appreciate the fact that you're watching over our client base, know immediately when those things go on, and take decisive action to keep them secure. Dom, I very much enjoyed the conversation. I appreciate you taking the time with me today. I look forward to having you on again and talking about the next topic. Thanks for being on. I know our listeners will appreciate it as well as our clients.

Dom Maxwell: Of course. Thank you for having me. I'm glad I got to be a part of this, and I'm excited to be part of more episodes going forward.

Shane Naugher: Awesome. Thanks, Dom.

Ready to Stop Worrying About IT?

Join hundreds of Missouri organizations who trust DaZZee IT as their technology partner. 25+ years, 80% same-day resolution.

60-day trial
100% satisfaction guarantee
No setup fees