# Replace ambiguous automatic-forwarding settings with an explicit decision

> Does Automatic - System-controlled reliably mean that external automatic forwarding is disabled?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:04+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does Automatic - System-controlled reliably mean that external automatic forwarding is disabled?

## Potentially affected

Exchange Online outbound spam policies controlling automatic forwarding to external recipients.

## DSE recommendation

Choose an explicit forwarding value and test both the forwarding method and sender location.

## Article

## Source facts

For Exchange Online outbound spam policies, Automatic – System-controlled is not a uniform assurance that external forwarding is blocked. Microsoft documents that its historical behavior can remain enabled in some existing organizations and recommends choosing an explicit On or Off value. Off disables external redirection through both Inbox rules and mailbox forwarding; internal forwarding is outside this control. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure).

Failure notifications also differ: external senders receive non-delivery reports for either method, but an internal sender does not receive one when an Inbox rule performs the blocked forwarding. Internal senders receive a report for blocked mailbox forwarding. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure).

## Applicability

Review Exchange Online outbound spam policies controlling automatic forwarding to external recipients. This decision concerns automatic redirection, not an assumption that every kind of message forwarding shares the same control.

## DSE recommendation

DSE recommends replacing an ambiguous inherited value with the explicitly approved behavior after identifying legitimate external forwarding requirements. Record the effective policy and the affected mailboxes before changing it. If forwarding is intentionally permitted, state that decision directly instead of relying on the interpretation of Automatic. Keep the approval separate from evidence that a particular delivery succeeded.

## Verification

Use approved test recipients to exercise Inbox-rule and mailbox forwarding with both internal and external senders. Compare the actual destination result with the expected notification for each combination. Do not interpret the absence of a non-delivery report as proof of successful forwarding. Retain the four-case result with the selected policy value.

## Official references

[Microsoft Learn: Configure outbound spam policies](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure).

## Primary reference

- Name: Configure outbound spam policies - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Replace ambiguous automatic-forwarding settings with an explicit decision,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-412-replace-ambiguous-automatic-forwarding-settings-with-an-explicit-decision/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
