A message that looks like it came from Microsoft can feel urgent, especially when it mentions a locked account, a failed payment, or unusual sign-in activity. Before you click anything, check whether the message is actually connected to your real Microsoft account.
Does this affect you?
Use this for any email claiming to be from Microsoft, Outlook, Office 365, Microsoft Account, or Xbox, no matter which email service you use to read it.
Check the warning signs before clicking anything
Inspect the message without pressing links, opening attachments, or replying.
- Open the sender details and read the real email address behind the display name. A legitimate Microsoft message should come from a Microsoft-controlled domain, not a free mailbox, a random domain, or a lookalike spelling such as micros0ft.
- Treat urgent threats as suspicious. Messages that say your account will be deleted, suspended, or locked unless you verify immediately are trying to rush you.
- Hover over links on a computer, or long-press carefully on mobile without opening them, to preview the destination. Real Microsoft account links should lead to microsoft.com or account.microsoft.com.
- Watch for vague greetings, inconsistent formatting, and awkward wording. These clues are common in phishing, though polished scams may avoid them.
- Look at the request itself. Microsoft will not ask you to email back your password, read out a text-message code, or pay a recovery fee with gift cards, cryptocurrency, wire transfer, or payment apps.
If the sender, link, wording, or request feels wrong, stop using the email and check your account from the real Microsoft site instead.
Verify your account status directly, safely
This avoids the phishing link completely and checks the genuine account.
- Close or leave the suspicious email without clicking inside it.
- Open a new browser tab and type account.microsoft.com yourself.
- Sign in with your normal Microsoft account credentials.
- Open the Security area and review sign-in activity, recovery methods, and alerts.
- Open Billing or subscriptions if the email claimed a payment failed or an invoice is due.
- If the real account shows no matching issue, delete the email or report it as phishing.
The same verification habit works for other impersonated brands too: leave the message, go to the official site yourself, and check from inside the real account.
More control
If you entered your password
Change the Microsoft account password immediately from account.microsoft.com on a device you trust. Use a password you have not used on any other account, then update any place where the old password was reused.
Turn on extra sign-in protection
Enable two-step verification in the Microsoft account Security settings if it is not already active. A stolen password is much less useful when another sign-in approval is required.
Check for mailbox rules and malware
If attackers got into Outlook, look under Outlook Settings > Mail > Rules for forwarding or deletion rules you did not create. If you opened an attachment, run a full Windows Security or antivirus scan before continuing normal work on that computer.
Sources
- Microsoft – How to recognize phishing (2025)
- Microsoft Support – Protect yourself from phishing (2025)
- CISA – Avoiding Social Engineering and Phishing Attacks (2025)
