4 Sep 20264 minutes read
Waseem OsmanDMARC EnthusiastEmail Compromise Indicators: Confirming an Account Takeover

Email compromise overview:
- A compromised mailbox passes standard email authentication checks, so the account itself needs checking, not the domain.
- Mailbox forwarding rules give attackers continued access to an account after a password reset.
- Anomalous sign-in activity, especially failed attempts immediately followed by a success, is one of the few consistent traces a takeover leaves behind.
- Multiple indicators appearing together justify moving straight to containment rather than continuing to investigate.
A compromised mailbox doesn't fail standard email authentication checks. It sends through real, authenticated infrastructure using a real, valid credential, so every check an email server performs passes. Confirming an email compromise means examining the account itself, not the domain's authentication configuration.
That distinction matters because investigations often start in the wrong place and miss the evidence a genuinely compromised account actually leaves behind. The indicators of email compromise that confirm an account takeover live inside the mailbox: its rules, its app permissions, and its sign-in history.
If any of the indicators below are already present in your environment, treat this as an active email compromise and move straight to containment: reset the credential, revoke active sessions, and lock down mailbox access before finishing the rest of this checklist.
Four Indicators of Email Compromise
Work through these four checks in order. Each one lives inside the mailbox itself since that is the only place a genuine email compromise leaves a trace.
Indicator 1: Mailbox Forwarding Rules
Attackers who gain access to a mailbox often set up a forwarding rule so they keep receiving copies of incoming email even after the account owner changes their password. This preserves visibility into invoice threads, password reset emails, and internal communications without requiring another login.
What to check:
- Review every inbox rule on the account, not just forwarding rules. Attackers also create rules that move or delete messages containing words like invoice, payment, or suspicious to hide evidence from the account owner.
- Check for forwarding rules pointing to an external domain, especially a free email address.
- Check for rules created outside the account owner's normal working hours or from an unfamiliar location.
- Confirm the rule was created by the account owner, not an administrator or automated process.
Indicator 2: OAuth App Grants
Account compromise increasingly bypasses passwords entirely. An attacker who tricks a user into approving a malicious OAuth application gains a token that survives a password reset.
What to check:
- Review every third-party app permission.
- Flag any application with permission to read mail or access files.
- Check the grant issued date and time.
- Revoke any unrecognized or unnecessary access immediately.
Indicator 3: Anomalous Sign-In Activity
Sign-in logs capture the location, device, and time of every attempt, and they are one of the few places a compromised account leaves a consistent trace.
What to check:
- Look for sign-ins from an unfamiliar country or region.
- Check for sign-ins from an unfamiliar device.
- Look for a pattern of failed sign-in attempts immediately followed by a successful one.
Indicator 4: Mailbox and Delegate Changes
Attackers with access sometimes add themselves as a delegate on the account or exploit an existing delegate relationship, so they retain access even if the primary credential gets secured.
What to check:
- Review the list of mailbox delegates and confirm every entry is expected and currently authorized.
- Check for changes to the account's recovery email address or recovery phone number.
- Review the Sent and Deleted Items folders for messages the account owner does not recognize.
What to Do When You Confirm Email Compromise
Any single indicator on its own might have an innocent explanation. Multiple indicators appearing together, especially a new OAuth grant combined with an unfamiliar sign-in and a hidden inbox rule, is a strong signal of an active email compromise.
At that point, move directly to containment: reset the credential, revoke all active sessions, remove the OAuth grant, and delete the malicious inbox rule, in that order, so the attacker loses access at every layer at once rather than one at a time.
How Sendmarc Can Help
The indicators above confirm an email compromise that has already happened. Sendmarc's Breach Detection intervenes earlier: it continuously monitors multiple sources, including the dark web, for employee credentials exposed in a data breach, and alerts your security team when a credential appears in a leaked dataset. That gives you the chance to reset the credential and review the account before an attacker acts on it.
For stretched security and IT teams, this removes a layer of manual investigation. Credential exposure gets flagged before it becomes an active email compromise, which cuts both the investigative workload and the window an attacker has to act.
Don't wait for the indicators above to show up before acting. Explore Breach Detection to get visibility into exposed employee credentials before they turn into an incident.



Leave a reply Cancel reply
Your email address will not be published. Required fields are marked *