Microsoft 365

Get-InboxRule

SafeInbox rules audit

Get-InboxRule -Mailbox <user>

Lists a mailbox's rules — attackers plant forward-and-hide rules, so this is mandatory in compromise triage.

Examples

  • Get-InboxRule -Mailbox taro | ? {$_.ForwardTo -or $_.RedirectTo}Just the forwarding rules

Syntax

Get-InboxRule -Mailbox id / Remove-InboxRule -Mailbox id -Identity rule

Before you run it

Reads are safe; confirm before removals.

Related commands

The same reference, with no signal at all

Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.

Get it free on the App Store