I configured an Exchange Online mail flow rule to prevent automatic forwarding outside the organization, but some users already enabled forwarding directly in their mailbox settings. Will the tenant-level rule also stop those existing forwarding configurations, or can mailbox forwarding bypass the rule? Are there any remote-domain or outbound-spam-policy settings I should check, and how can I audit or remove the existing forwards?
2 Answers
Existing mailbox forwarding generally isn’t exempt just because it was configured before the rule. Outbound messages created by automatic forwarding are still subject to Exchange Online’s outbound controls, so a properly configured block should stop them. However, the exact result depends on whether you’re using a mail flow rule, the outbound spam policy, or remote-domain settings. Check all three rather than assuming mailbox rules take precedence. Blocked messages may generate an NDR or other delivery failure.
Be careful with the claim that one rule always overrides everything else. Exchange has several forwarding mechanisms, and their processing order can vary. The recommended approach is to disable external automatic forwarding in the outbound spam policy, verify the default remote domain doesn’t allow it, and use message tracing to test a mailbox that still has forwarding enabled. You can also audit and remove legacy settings with Exchange Online PowerShell, including mailbox properties such as ForwardingSmtpAddress and DeliverToMailboxAndForward.

That makes sense. I’ll test the different forwarding methods and review the outbound policy and remote-domain configuration instead of relying on the mail flow rule alone.