How to Allow External Email Forwarding for One Microsoft 365 Mailbox
Question details
An administrator needs to enable automatic external email forwarding for a single Microsoft 365 mailbox without modifying the default block for the rest of the organization.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Configuring outbound spam filter policies and mail flow rules to selectively allow external forwarding for specific users.
- Observed behavior
- External email forwarding is blocked by default across the Microsoft 365 organization, preventing individual users from automatically routing emails to external addresses.
Ensure you have global administrator or Exchange administrator privileges in Microsoft 365, and verify that allowing external forwarding for this specific mailbox complies with your organization's data protection policies.
Create a Custom Outbound Spam Filter Policy
Modify the Microsoft Defender threat policies by creating a custom outbound spam policy targeted specifically at the required mailbox.
By default, Microsoft 365 disables external forwarding to protect against data exfiltration. Instead of modifying the default policy that affects everyone, the safest method is to create a custom policy assigned only to the approved user.
Log in to the Microsoft 365 Defender portal using your administrator credentials.
In the left navigation menu, go to 'Email & collaboration' > 'Policies & rules', then click on 'Threat policies'.
Under the Policies section, select 'Anti-spam' to view the list of spam filter policies.
Click on 'Create policy' and select 'Outbound'. Give the policy a descriptive name, such as 'Allow External Forwarding - Specific User'.
In the 'Users, groups, and domains' section, add the specific mailbox. Proceed to 'Protection settings', change 'Automatic forwarding rules' to 'On - Forwarding is enabled', and save the policy.
Review Exchange Mail Flow Rules
Ensure no existing Exchange admin center rules are overriding your spam policy and blocking the forwarded emails.
Contact Microsoft Support for Persistent Blocks
If the policies and rules are configured correctly but forwarding still fails, Microsoft 365 support can inspect backend logs.
Discover WPS Office: A Lightweight and Free Alternative
While configuring Microsoft 365 administrative settings requires navigating advanced technical portals, your daily office tasks don't have to be complicated. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office, offering an intuitive interface for managing your Word, Excel, and PowerPoint files effortlessly.
- 1. Visit the Official Website: Navigate to the official WPS Office website to access the latest version.
- 2. Download the Installer: Click the 'Free Download' button to get the installation package for your operating system.
- 3. Install and Launch: Run the installer, follow the on-screen instructions, and start editing your documents instantly.

Frequently Asked Questions
Why is external email forwarding blocked by default in Microsoft 365?
Microsoft disables automatic external forwarding by default as a security measure to protect organizational data and prevent unauthorized data exfiltration if an account is compromised.
Can a user enable external forwarding on their own?
Users can set up personal forwarding rules in Outlook, but if the outbound spam filter policy restricts it at the tenant level, the emails will be blocked by the server and a non-delivery report (NDR) will be generated.
How long does it take for the outbound spam filter policy changes to take effect?
Policy changes made in the Microsoft Defender portal typically take effect within an hour, but in some cases, it can take up to 24 hours to fully propagate across the Microsoft 365 environment.
Does external forwarding bypass data loss prevention (DLP) policies?
No. Forwarded emails are still subject to your organization's active Data Loss Prevention (DLP) policies and mail flow rules configured in the Exchange admin center.




