With the increase attack on 365 subscriptions without two factor enabled its good to check when a rule actually got added. This cannot be done with powershell you will need to perform with MFCMAPI
Download the latest MFCMAPI of 32bit or 64bit ( depending on your Office/Outlook version ) release here
You can do this on the User’s computer who should already have Outlook installed or you can create an Outlook profile as the user you would like to check the rule for on another PC. You can also create an Outlook Profile as an Administrator and give yourself full access to the User’s
Open MFCMAPI , Open the Profile , then go to Session and Logon
Double click on the account
Open the Root Folder and Navigate to here and right click on Inbox and Choose Open Associated Contents Table
The rule will look something like this , Message Class : IPM.Rule.Verson2.Message
Then find the following Name and check the value to confirm its the right Rule