Last updated: July 2026
A “Microsoft account security alert” email can be genuine — but a large share are a phishing scam. The safest way to know is to ignore the email’s links entirely and check your account yourself: open a browser, type account.microsoft.com, sign in, and look at your recent activity. If the alert is real, you’ll see it there. If nothing unusual shows up, the email was a scam. Never click “Review activity” or “Secure account” buttons inside a suspicious email.
Want to check the email now? Scan it with ScanTheSender first, then verify on Microsoft’s real site.
What this scam looks like
A Microsoft account security alert scam is a phishing email dressed up as a genuine security warning. It copies Microsoft’s branding and warns of an “unusual sign-in,” often from another country, or says your account will be locked unless you verify it now. It includes a button like “Review activity” or “Secure your account.”
That button leads to a fake Microsoft or Outlook sign-in page. If you enter your password — or approve a two-step verification prompt — the scammer captures it and can take over your account.
An illustrative example (a made-up sample, not a real message):
“Microsoft account unusual sign-in activity detected from [country]. If this wasn’t you, verify your account immediately: [Review activity]”
Genuine Microsoft security alerts do exist, which is what makes this scam effective — so the trick is to verify on Microsoft’s real site, not to judge the email itself.
How to tell if a Microsoft account security alert is a scam
- The sender isn’t Microsoft’s real address. Genuine account alerts come from account-security-noreply@accountprotection.microsoft.com. A different or misspelled domain means phishing.
- It pushes urgency — “verify now or your account will be locked.”
- The link doesn’t go to a genuine microsoft.com address. Hover to check before clicking (better still, don’t click at all).
- You check account.microsoft.com and there’s no matching activity. If the real site shows nothing unusual, the email was fake.
- It asks you to approve a login or enter a code you didn’t request.
What to do right now
- Don’t click any link or button in the email.
- Verify directly. Open a new browser tab, type account.microsoft.com (or account.live.com/activity), sign in, and check Recent activity. Real sign-in alerts will appear here.
- If you see genuine unusual activity, change your password from the Security basics page and turn on two-step verification.
- Report the phishing email. In Outlook, right-click the message and report it as phishing/junk. UK: forward to report@phishing.gov.uk. US: report to the FTC at ReportFraud.ftc.gov.
- If you already entered your password on a linked page, change your Microsoft password immediately from the real site and remove any recovery details you don’t recognise.
FAQ
Is a Microsoft “unusual sign-in” email always a scam? No — Microsoft does send real ones. But many fakes copy them exactly. Don’t trust or click the email. Instead, go to account.microsoft.com yourself and check Recent activity. If it’s real, it’ll show there; if not, the email was phishing.
How do I know a Microsoft security email is genuine? Genuine Microsoft account alerts come from account-security-noreply@accountprotection.microsoft.com. A different sender domain is a red flag. Even so, verify by checking your activity on Microsoft’s real site rather than relying on the email alone.
I clicked “Review activity” but didn’t enter anything — am I safe? Clicking is lower risk than entering your password, but close the page and don’t type anything. Then check your account at account.microsoft.com directly and, to be safe, change your password and enable two-step verification.
I entered my password on the page. What now? Go straight to account.microsoft.com, change your password, turn on two-step verification, and review your recovery email and phone for anything you didn’t add. Then report the phishing email.
Not sure about a Microsoft email?
Check a Microsoft security email free — paste or screenshot it into ScanTheSender, then verify on Microsoft’s real site.
Related reading: the same “your account has a problem” trick powers the Apple ID suspended email scam and the Amazon phishing email scam.
