Appearance
How to Check If Your Email Was Compromised
Applies to: Microsoft 365 (Outlook, Azure AD)
Article Type: How-To
Last Updated: 2026-03-09
Summary
If you suspect your Microsoft 365 email account has been compromised — such as receiving unexpected password reset emails, seeing sent messages you did not write, or receiving alerts about unfamiliar sign-ins — you can investigate by reviewing your recent sign-in activity and security settings. This article shows how to check your account for signs of compromise and take immediate action.
Prerequisites
- A Microsoft 365 account.
- Access to the Microsoft 365 portal (myaccount.microsoft.com).
- No admin rights required.
Instructions
1. Review Your Recent Sign-In Activity
Check for unfamiliar logins to your account.
- Open a browser and go to myaccount.microsoft.com.
- Sign in with your Microsoft 365 credentials.
- Click My Sign-ins in the left navigation (or go directly to mysignins.microsoft.com).
- Review the list of recent sign-in attempts, checking for:
- Unfamiliar locations — Sign-ins from cities or countries you have not visited.
- Unfamiliar devices — Sign-ins from devices you do not recognise.
- Unusual times — Sign-ins at hours you would not normally be active.
- Failed attempts — Multiple failed sign-in attempts may indicate a brute-force attack.
- If you see suspicious activity, proceed to Step 2 immediately.
2. Change Your Password Immediately
Secure your account by resetting your password.
- Go to myaccount.microsoft.com > Security info.
- Click Change password (or go to Settings > Password).
- Enter your current password.
- Create a new, strong password that:
- Is at least 12 characters long.
- Includes uppercase, lowercase, numbers, and symbols.
- Is not reused from any other account.
- Click Submit to save the new password.
3. Check for Unauthorised Email Rules
Attackers often create hidden mail rules to forward your emails.
- Open Outlook (desktop or web).
- Go to Settings (gear icon) > View all Outlook settings > Mail > Rules.
- Review all rules in the list.
- Look for rules you did not create, especially those that:
- Forward emails to an external address.
- Delete or move incoming messages automatically.
- Mark messages as read without your knowledge.
- Delete any suspicious rules immediately.
4. Review Connected Apps and Permissions
Revoke access for any unfamiliar applications.
- Go to myaccount.microsoft.com > Privacy or myapps.microsoft.com.
- Review the list of apps that have access to your account.
- If you see an app you do not recognise, click on it and select Revoke access or Remove.
5. Report the Compromise
Notify your IT department so they can take additional security measures.
- Contact your IT help desk immediately and report the suspected compromise. Phone them if you can — an attacker with mailbox access has minutes, not hours, and a queued email sits behind everyone else's.
- Tell them what you found: the sign-in locations and times you did not recognise, any forwarding or inbox rule that appeared, the recipients of anything sent from your account, and whether a new MFA method is registered.
- If an unfamiliar phone number or authenticator device is listed as an MFA method, report it — do not remove it yourself. It shows IT how the attacker kept access, and deleting it destroys that evidence. IT will clear it once they have recorded it.
- Your IT team may:
- Force-sign you out of all active sessions.
- Review your account logs for additional suspicious activity.
- Enable additional security controls on your account.
Troubleshooting
WARNING
If you confirm your account was compromised, change your password and enable MFA immediately. Do not delay — attackers often set up persistence mechanisms (mail rules, app permissions) within minutes of gaining access.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Sent folder contains messages you did not write | Account compromised | Change your password and review email rules for hidden forwarding rules. Report to IT. |
| Unable to sign in to your account | Attacker changed the password | Use self-service password reset at passwordreset.microsoftonline.com. If that fails, phone your IT help desk rather than emailing — ask them to reset your password and sign out every active session, and tell them when you last signed in successfully. |
| MFA prompts appearing that you did not initiate | Someone is attempting to sign in with your password | Do not approve the prompt. Change your password immediately and report to IT. |