{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
        "slug": "dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/"
        },
        "title": "Replace ambiguous automatic-forwarding settings with an explicit decision",
        "summary": "Does Automatic - System-controlled reliably mean that external automatic forwarding is disabled?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:04+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 251,
        "potentially_affected": "Exchange Online outbound spam policies controlling automatic forwarding to external recipients.",
        "dse_recommendation": "Choose an explicit forwarding value and test both the forwarding method and sender location.",
        "primary_source": {
            "name": "Configure outbound spam policies - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For Exchange Online outbound spam policies, Automatic &#8211; System-controlled is not a uniform assurance that external forwarding is blocked. Microsoft documents that its historical behavior can remain enabled in some existing organizations and recommends choosing an explicit On or Off value. Off disables external redirection through both Inbox rules and mailbox forwarding; internal forwarding is outside this control. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Failure notifications also differ: external senders receive non-delivery reports for either method, but an internal sender does not receive one when an Inbox rule performs the blocked forwarding. Internal senders receive a report for blocked mailbox forwarding. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Exchange Online outbound spam policies controlling automatic forwarding to external recipients. This decision concerns automatic redirection, not an assumption that every kind of message forwarding shares the same control.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends replacing an ambiguous inherited value with the explicitly approved behavior after identifying legitimate external forwarding requirements. Record the effective policy and the affected mailboxes before changing it. If forwarding is intentionally permitted, state that decision directly instead of relying on the interpretation of Automatic. Keep the approval separate from evidence that a particular delivery succeeded.</p>\n<h2>Verification</h2>\n<p>Use approved test recipients to exercise Inbox-rule and mailbox forwarding with both internal and external senders. Compare the actual destination result with the expected notification for each combination. Do not interpret the absence of a non-delivery report as proof of successful forwarding. Retain the four-case result with the selected policy value.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure outbound spam policies</a>.</p>",
        "content_text": "Source facts\nFor Exchange Online outbound spam policies, Automatic – System-controlled is not a uniform assurance that external forwarding is blocked. Microsoft documents that its historical behavior can remain enabled in some existing organizations and recommends choosing an explicit On or Off value. Off disables external redirection through both Inbox rules and mailbox forwarding; internal forwarding is outside this control. Microsoft Learn.\nFailure notifications also differ: external senders receive non-delivery reports for either method, but an internal sender does not receive one when an Inbox rule performs the blocked forwarding. Internal senders receive a report for blocked mailbox forwarding. Microsoft Learn.\nApplicability\nReview Exchange Online outbound spam policies controlling automatic forwarding to external recipients. This decision concerns automatic redirection, not an assumption that every kind of message forwarding shares the same control.\nDSE recommendation\nDSE recommends replacing an ambiguous inherited value with the explicitly approved behavior after identifying legitimate external forwarding requirements. Record the effective policy and the affected mailboxes before changing it. If forwarding is intentionally permitted, state that decision directly instead of relying on the interpretation of Automatic. Keep the approval separate from evidence that a particular delivery succeeded.\nVerification\nUse approved test recipients to exercise Inbox-rule and mailbox forwarding with both internal and external senders. Compare the actual destination result with the expected notification for each combination. Do not interpret the absence of a non-delivery report as proof of successful forwarding. Retain the four-case result with the selected policy value.\nOfficial references\nMicrosoft Learn: Configure outbound spam policies.",
        "content_markdown": "## Source facts\n\nFor Exchange Online outbound spam policies, Automatic – System-controlled is not a uniform assurance that external forwarding is blocked. Microsoft documents that its historical behavior can remain enabled in some existing organizations and recommends choosing an explicit On or Off value. Off disables external redirection through both Inbox rules and mailbox forwarding; internal forwarding is outside this control. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure).\n\nFailure notifications also differ: external senders receive non-delivery reports for either method, but an internal sender does not receive one when an Inbox rule performs the blocked forwarding. Internal senders receive a report for blocked mailbox forwarding. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure).\n\n## Applicability\n\nReview Exchange Online outbound spam policies controlling automatic forwarding to external recipients. This decision concerns automatic redirection, not an assumption that every kind of message forwarding shares the same control.\n\n## DSE recommendation\n\nDSE recommends replacing an ambiguous inherited value with the explicitly approved behavior after identifying legitimate external forwarding requirements. Record the effective policy and the affected mailboxes before changing it. If forwarding is intentionally permitted, state that decision directly instead of relying on the interpretation of Automatic. Keep the approval separate from evidence that a particular delivery succeeded.\n\n## Verification\n\nUse approved test recipients to exercise Inbox-rule and mailbox forwarding with both internal and external senders. Compare the actual destination result with the expected notification for each combination. Do not interpret the absence of a non-delivery report as proof of successful forwarding. Retain the four-case result with the selected policy value.\n\n## Official references\n\n[Microsoft Learn: Configure outbound spam policies](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Replace ambiguous automatic-forwarding settings with an explicit decision",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/",
                "headline": "Replace ambiguous automatic-forwarding settings with an explicit decision",
                "description": "Does Automatic - System-controlled reliably mean that external automatic forwarding is disabled?",
                "abstract": "Does Automatic - System-controlled reliably mean that external automatic forwarding is disabled?",
                "articleBody": "Source facts\nFor Exchange Online outbound spam policies, Automatic – System-controlled is not a uniform assurance that external forwarding is blocked. Microsoft documents that its historical behavior can remain enabled in some existing organizations and recommends choosing an explicit On or Off value. Off disables external redirection through both Inbox rules and mailbox forwarding; internal forwarding is outside this control. Microsoft Learn.\nFailure notifications also differ: external senders receive non-delivery reports for either method, but an internal sender does not receive one when an Inbox rule performs the blocked forwarding. Internal senders receive a report for blocked mailbox forwarding. Microsoft Learn.\nApplicability\nReview Exchange Online outbound spam policies controlling automatic forwarding to external recipients. This decision concerns automatic redirection, not an assumption that every kind of message forwarding shares the same control.\nDSE recommendation\nDSE recommends replacing an ambiguous inherited value with the explicitly approved behavior after identifying legitimate external forwarding requirements. Record the effective policy and the affected mailboxes before changing it. If forwarding is intentionally permitted, state that decision directly instead of relying on the interpretation of Automatic. Keep the approval separate from evidence that a particular delivery succeeded.\nVerification\nUse approved test recipients to exercise Inbox-rule and mailbox forwarding with both internal and external senders. Compare the actual destination result with the expected notification for each combination. Do not interpret the absence of a non-delivery report as proof of successful forwarding. Retain the four-case result with the selected policy value.\nOfficial references\nMicrosoft Learn: Configure outbound spam policies.",
                "datePublished": "2026-09-10T00:25:04+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Replace ambiguous automatic-forwarding settings with an explicit decision"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 251,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure outbound spam policies - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure"
                }
            }
        ]
    }
}