Skip to content

How to Check If Your Email Was Compromised

Applies toMicrosoft 365OutlookEntra ID
4 min fix Updated 9 Mar 2026 · 6 months ago
Quick Answer

Go to myaccount.microsoft.com and check the Recent activity page to look for unfamiliar sign-ins or locations you do not recognize.

Checked against Microsoft Learn - end of support and retirement, Microsoft 365 Roadmap and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.

Summary

If you suspect your Microsoft 365 email account has been compromised — such as receiving unexpected password reset emails, seeing sent messages you did not write, or receiving alerts about unfamiliar sign-ins — you can investigate by reviewing your recent sign-in activity and security settings. This article shows how to check your account for signs of compromise and take immediate action.

Before You Start

  • A Microsoft 365 account.
  • Access to the Microsoft 365 portal (myaccount.microsoft.com).
  • No admin rights required.

Instructions

1. Review Your Recent Sign-In Activity

Check for unfamiliar logins to your account.

  1. Open a browser and go to myaccount.microsoft.com.
  2. Sign in with your Microsoft 365 credentials.
  3. Click My Sign-ins in the left navigation (or go directly to mysignins.microsoft.com).
  4. Review the list of recent sign-in attempts, checking for:
    • Unfamiliar locations — Sign-ins from cities or countries you have not visited.
    • Unfamiliar devices — Sign-ins from devices you do not recognise.
    • Unusual times — Sign-ins at hours you would not normally be active.
    • Failed attempts — Multiple failed sign-in attempts may indicate a brute-force attack.
  5. If you see suspicious activity, proceed to Step 2 immediately.

2. Change Your Password Immediately

Secure your account by resetting your password.

  1. Go to myaccount.microsoft.com > Security info.
  2. Click Change password (or go to Settings > Password).
  3. Enter your current password.
  4. Create a new, strong password that:
    • Is at least 12 characters long.
    • Includes uppercase, lowercase, numbers, and symbols.
    • Is not reused from any other account.
  5. Click Submit to save the new password.

3. Check for Unauthorised Email Rules

Attackers often create hidden mail rules to forward your emails.

  1. Open Outlook (desktop or web).
  2. Go to Settings (gear icon) > View all Outlook settings > Mail > Rules.
  3. Review all rules in the list.
  4. Look for rules you did not create, especially those that:
    • Forward emails to an external address.
    • Delete or move incoming messages automatically.
    • Mark messages as read without your knowledge.
  5. Delete any suspicious rules immediately.

4. Review Connected Apps and Permissions

Revoke access for any unfamiliar applications.

  1. Go to myaccount.microsoft.com > Privacy or myapps.microsoft.com.
  2. Review the list of apps that have access to your account.
  3. If you see an app you do not recognise, click on it and select Revoke access or Remove. To tell a legitimate app from a suspicious one before you revoke it, see How to Manage App Permissions and Connected Apps in Microsoft 365.

5. Report the Compromise

Notify your IT department so they can take additional security measures.

  1. Contact your IT help desk immediately and report the suspected compromise. Phone them if you can — an attacker with mailbox access has minutes, not hours, and a queued email sits behind everyone else's.
  2. Tell them what you found: the sign-in locations and times you did not recognise, any forwarding or inbox rule that appeared, the recipients of anything sent from your account, and whether a new MFA method is registered.
  3. If an unfamiliar phone number or authenticator device is listed as an MFA method, report it — do not remove it yourself. It shows IT how the attacker kept access, and deleting it destroys that evidence. IT will clear it once they have recorded it.
  4. Your IT team may:
    • Force-sign you out of all active sessions.
    • Review your account logs for additional suspicious activity.
    • Enable additional security controls on your account.

Troubleshooting

WARNING

If you confirm your account was compromised, change your password and enable MFA immediately. Do not delay — attackers often set up persistence mechanisms (mail rules, app permissions) within minutes of gaining access.

Symptom / ErrorPotential CauseSolution
Sent folder contains messages you did not writeAccount compromisedChange your password and review email rules for hidden forwarding rules. Report to IT.
Unable to sign in to your accountAttacker changed the passwordUse self-service password reset at passwordreset.microsoftonline.com. If that fails, phone your IT help desk rather than emailing — ask them to reset your password and sign out every active session, and tell them when you last signed in successfully.
MFA prompts appearing that you did not initiateSomeone is attempting to sign in with your passwordDo not approve the prompt. Change your password immediately and report to IT.

Last updated:

Frequently asked questions

What should I do if I see a login from another country?
Change your password immediately, ensure two-factor authentication is active, and contact your IT help desk to report the unauthorized access.
Will Microsoft notify me if my account is compromised?
Microsoft often flags suspicious logins and may force a password reset, but you should regularly check your sign-in activity to be proactive.