I've disabled auto-forwarding as of today, but the NDR part confuses me:
- A NDR is sent back to the mailbox that configured auto forwarding to external user if the policy is set to block automatic forwarding for that mailbox. The NDR will contain the following diagnostic information:
Remote Server returned '550 5.7.520 Access denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7550)'
The NDR isn't send to the user that has configured the forwarding. It's send to the original e-mail sender.. And that sender is confused, because he hasn't setup any forwarding.
To be clear:
Person B has forwarding to external enabled.
Person A sends mail to Person B --> Person A gets the NDR, that's meant for Person B (with the rule).