hacker setup hidden forwarding rules

Jake Burfoot 0 Reputation points
2026-09-13T17:43:17.7866667+00:00

My account was compromised and the hacker has setup hidden forwarding rules, i need to know how to remove them

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. EmilyS726 266.1K Reputation points Independent Advisor
    2026-09-13T18:19:38.95+00:00

    Hello

    Do you use Outlook app to check your emails? If so, exit the app, hold down Win+R keys, type in

    outlook.exe /cleanrules
    

    Then press enter and let it run through. If that alone doesn't seem to help, I would recommend that you go through this list.

    This process can take 24 hours to take effect. So please do not expect immediate results.

    Please complete these steps on a computer, not on a smartphone or tablet.

    ====================

    First, go to https://www.outlook.com and sign in.

    Click the gear icon in the top right corner to open Settings.

    Under Mail, review the following areas:

    Rules

    If any rules are listed, delete all of them.

    Conditional formatting

    If anything is set up there, delete it.

    Forwarding and IMAP

    If you see any entries or settings you did not create, remove them. Turn off POP and IMAP.

    Junk

    Review Safe sender and blocked list. If you don't recognize any, remove them.

    After that, exit Settings and return to outlook.com.

    Open the To Do section by clicking the blue checkmark icon on the left side. Delete anything there that was not created by you.

    ====================

    Go to https://account.live.com.

    Under Your info > Sign-in preferences, review all aliases on the account. If you see any alias you do not recognize, remove it.

    Next, go to the Devices section of your Microsoft account and remove any devices you do not recognize.

    ====================

    Please also do the following in Security section

    Change your password

    Enable two-step verification

    ====================

    Go here https://account.microsoft.com/privacy/app-access Click on "Don't allow" for anything you don't recognize.

    =======================

    Then go to Security > Manage how I sign in and make sure all contact information belongs to you.

    On that same page, scroll down to App passwords and remove any existing app passwords.

    Also on the same page, click on Sign out everywhere. This is intended to disconnect any active sessions that may still be connected. Please note that this can take up to 24 hours to fully take effect.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-13T17:43:31.1366667+00:00

    Use this cleanup sequence:

    1. Treat the account as compromised. If an unrecognized forwarding rule points to an unknown internal or external address, assume the mailbox was compromised.
    2. Remove visible forwarding settings in Outlook.com:
      • Go to SettingsMailForwarding.
      • Remove any unknown forwarding address and turn forwarding off.
    3. Check mailbox rules:
      • Go to SettingsMailRules.
      • Delete suspicious rules, especially ones that forward, delete, move messages, mark mail as read, or use obscure names such as . or empty names.
    4. Reset the account password after scanning the PC for malware:
      • Run a full antivirus scan first.
      • Then change or reset the password.
    5. Review account settings changed by the attacker:
      • Check connected accounts, forwarding, and automatic replies.
    6. If the rule is hidden and not visible in Outlook.com, hidden or corrupted inbox rules can exist outside the normal UI. Microsoft documents removing corrupted hidden inbox rules by using MFCMAPI.
    7. Investigate for broader compromise:
      • Look for other suspicious inbox rules such as “delete all” or “move messages to another folder”.
      • Check for increased sent mail activity.
    8. If this is a Microsoft account/Outlook.com account, use the account recovery flow and security checks to complete recovery.

    If the malicious forwarding rule is confirmed, the documented remediation is to disable/remove the rule and reset credentials.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.