Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP)
Description
This query summarises automatic external email forwarding across the tenant by forwarding type (mailbox rule versus SMTP forwarding), using the EmailEvents table.
Query · kql
EmailEvents
| where Timestamp > ago(30d)
| where EmailDirection == "Outbound" and isnotempty(ForwardingInformation)
| extend Key = strcat(NetworkMessageId, '-', RecipientEmailAddress)
| summarize arg_max(Timestamp, *) by Key
| extend FwdInfo = parse_json(ForwardingInformation)
| extend ForwardingType = tostring(FwdInfo.ForwardingType),
ForwardingUser = tostring(FwdInfo.ForwardingUser),
RecipientDomain = tostring(split(RecipientEmailAddress, '@')[1])
| summarize ForwardedMessages = count(),
ForwardingUsers = dcount(ForwardingUser),
ExternalRecipients = dcount(RecipientEmailAddress),
ExternalDomains = dcount(RecipientDomain)
by ForwardingType
| sort by ForwardedMessages desc