Attackers hide inside
your mailboxes.
IRM finds them.
The most dangerous inbox rule attacks don't forward email externally — they hide it. IRM monitors every rule change across every mailbox and raises an alert the moment something suspicious appears.
From suspicious rule to alert — in minutes.
IRM connects directly to Microsoft 365 using certificate-based authentication. No passwords. No agents. No complex setup.
Connect your tenant
Sign in as Global Admin once. IRM creates the app registration, uploads the certificate, and configures Exchange access automatically — under 5 minutes per tenant.
Continuous monitoring
IRM scans every mailbox across all configured tenants on a schedule you control. Every rule is compared to the previous snapshot — detecting any change the moment it happens.
Alert raised
Suspicious changes raise an alert on your dashboard and by email. Each alert includes the affected mailbox, what changed, risk level, and recommended action — no log-digging required.
The most dangerous inbox rule attacks
don't forward email externally. They hide it.
Sophisticated attackers use hidden folder rules to intercept conversations without ever touching the outbox. Here's how it happens.
Sarah is the Accounts Payable manager at Acme Corporation. She receives what looks like a DocuSign request from a vendor. She clicks the link, enters her Microsoft 365 credentials.
The attacker creates one rule: emails from Supplier B — Vantage's primary vendor — move silently to a folder called "Archive2." Marked as read. Sarah never sees them.
The attacker monitors Archive2 and replies as Sarah — impersonating her to Supplier B. They explain that Acme Corporation has switched banks and provide new wire transfer details.
Supplier B processes the next invoice. $94,000 is wired to the attacker's account. Acme Corporation discovers the fraud six weeks later when Supplier B calls about the overdue payment.
The moment the Archive2 rule was created, IRM flagged it — full rule details, the affected mailbox, and risk level. IT investigates. The rule is removed. Sarah's password is reset. No money moves.
Rule: "Archive2"
Action: Move to folder "Archive2" · Mark as read
From filter: supplier.example.com
Rule: "Payment Received"
ForwardTo changed: none → external address
Rule: "Newsletter Archive"
Priority changed: 5 → 8
Your tenant has inbox rules
you've never seen. Now you can.
Before you can monitor for changes — you need to know what's already there. Rule Analyzer gives you a complete picture of every inbox rule across your entire Microsoft 365 tenant. Most organizations discover rules they never knew existed.
Attackers plant rules and walk away. Rule Analyzer finds rules that have been sitting in mailboxes for months — hidden folder rules, silent forwards. Most clients find something on day one.
See all inbox rules across your entire tenant organized by user — not one mailbox at a time. Filter by risk, search by name, group by mailbox. Export to CSV for compliance reporting.
Switch to Flag View to see only rules that warrant review — external forwards, hidden folder rules, delete-on-arrival rules. Cut through the noise in seconds.
As you work through rules with your client, mark each one reviewed. Build a documented audit trail of your inbox rule environment for compliance and security reporting.
Built for the people responsible
for keeping email secure.
Whether you're an in-house IT admin or managing dozens of client tenants, IRM gives you the visibility that Microsoft 365 doesn't provide out of the box.
Real-time rule detection
Every mailbox, every scan. IRM compares rule snapshots across all tenants and flags any created, modified, or deleted rule — with full before/after details in every alert.
Rule Analyzer
A live view of every inbox rule across every mailbox. Search, filter by risk, group by mailbox, and expand any rule to see exactly what it does. Ideal for baseline audits of new clients.
Auth Monitor
Detect new device sign-ins, failed MFA attempts, foreign logins, and brute force patterns across all monitored tenants — sourced from Microsoft 365 audit logs and may be delayed.
Rich alert emails
Every alert includes the affected mailbox, the rule name, what changed, risk level, and recommended action. Before/after comparison included. No log-digging required.
Multi-tenant dashboard
Monitor all tenants from one interface. Each client gets independent scan schedules, alert recipients, and rule history. Scales from single-org IT to a 25-tenant MSP operation.
Zero credentials stored
Certificate-based Azure AD authentication only. No passwords, no OAuth tokens on disk. IRM reads inbox rule configurations and mailbox lists only — it never accesses email content, attachments, calendar data, or any other mailbox data. It cannot modify rules or settings.
Every alert tells the full story.
Right in your inbox.
When IRM detects a suspicious rule change, a detailed HTML alert is delivered instantly — with everything you need to investigate and act, no dashboard login required.
HIGH, MEDIUM, or LOW displayed prominently so you know at a glance whether to act now or review later.
Every field of the affected rule — move to folder, forwarding address, from filter, mark as read — all shown in the email body. No login required to see what changed.
For modified rules, the email shows exactly what changed — old value crossed out, new value highlighted in green. Spot the difference instantly.
Every alert includes clear next steps — verify with the user, review related rules, check sign-in activity. Actionable guidance, not just raw data.
All your tenants.
One dashboard.
Add a new tenant in under 5 minutes. Monitor indefinitely. Each organization gets its own scan schedule, alert configuration, and rule history.
Simple annual pricing.
No per-seat surprises.
All plans include inbox rule monitoring, Rule Analyzer, real-time email alerts with full rule details, daily digest reports, multi-tenant dashboard, certificate-based authentication, CSV export, and software updates. Contact us for pricing tailored to your organization.
Start monitoring in under 10 minutes.
No cloud infrastructure required. Installs on any Windows desktop or server. Free trial available.