Open PowerShell as Administrator:
Many attackers set DeliverToMailboxAndForward = $true to keep the user unaware. active office 365 cmd