Skip to content
4 min fix 4 min read Recently reviewedBeginner
Quick Answer

Go to myaccount.microsoft.com and check the Recent activity page to look for unfamiliar sign-ins or locations you do not recognize.

How to Check If Your Email Was Compromised

Applies to: Microsoft 365 (Outlook, Azure AD)
Article Type: How-To
Last Updated: 2026-03-09

Summary

If you suspect your Microsoft 365 email account has been compromised — such as receiving unexpected password reset emails, seeing sent messages you did not write, or receiving alerts about unfamiliar sign-ins — you can investigate by reviewing your recent sign-in activity and security settings. This article shows how to check your account for signs of compromise and take immediate action.

Prerequisites

  • A Microsoft 365 account.
  • Access to the Microsoft 365 portal (myaccount.microsoft.com).
  • No admin rights required.

Instructions

1. Review Your Recent Sign-In Activity

Check for unfamiliar logins to your account.

  1. Open a browser and go to myaccount.microsoft.com.
  2. Sign in with your Microsoft 365 credentials.
  3. Click My Sign-ins in the left navigation (or go directly to mysignins.microsoft.com).
  4. Review the list of recent sign-in attempts, checking for:
    • Unfamiliar locations — Sign-ins from cities or countries you have not visited.
    • Unfamiliar devices — Sign-ins from devices you do not recognise.
    • Unusual times — Sign-ins at hours you would not normally be active.
    • Failed attempts — Multiple failed sign-in attempts may indicate a brute-force attack.
  5. If you see suspicious activity, proceed to Step 2 immediately.

2. Change Your Password Immediately

Secure your account by resetting your password.

  1. Go to myaccount.microsoft.com > Security info.
  2. Click Change password (or go to Settings > Password).
  3. Enter your current password.
  4. Create a new, strong password that:
    • Is at least 12 characters long.
    • Includes uppercase, lowercase, numbers, and symbols.
    • Is not reused from any other account.
  5. Click Submit to save the new password.

3. Check for Unauthorised Email Rules

Attackers often create hidden mail rules to forward your emails.

  1. Open Outlook (desktop or web).
  2. Go to Settings (gear icon) > View all Outlook settings > Mail > Rules.
  3. Review all rules in the list.
  4. Look for rules you did not create, especially those that:
    • Forward emails to an external address.
    • Delete or move incoming messages automatically.
    • Mark messages as read without your knowledge.
  5. Delete any suspicious rules immediately.

4. Review Connected Apps and Permissions

Revoke access for any unfamiliar applications.

  1. Go to myaccount.microsoft.com > Privacy or myapps.microsoft.com.
  2. Review the list of apps that have access to your account.
  3. If you see an app you do not recognise, click on it and select Revoke access or Remove.

5. Report the Compromise

Notify your IT department so they can take additional security measures.

  1. Contact your IT help desk immediately and report the suspected compromise. Phone them if you can — an attacker with mailbox access has minutes, not hours, and a queued email sits behind everyone else's.
  2. Tell them what you found: the sign-in locations and times you did not recognise, any forwarding or inbox rule that appeared, the recipients of anything sent from your account, and whether a new MFA method is registered.
  3. If an unfamiliar phone number or authenticator device is listed as an MFA method, report it — do not remove it yourself. It shows IT how the attacker kept access, and deleting it destroys that evidence. IT will clear it once they have recorded it.
  4. Your IT team may:
    • Force-sign you out of all active sessions.
    • Review your account logs for additional suspicious activity.
    • Enable additional security controls on your account.

Troubleshooting

WARNING

If you confirm your account was compromised, change your password and enable MFA immediately. Do not delay — attackers often set up persistence mechanisms (mail rules, app permissions) within minutes of gaining access.

Symptom / ErrorPotential CauseSolution
Sent folder contains messages you did not writeAccount compromisedChange your password and review email rules for hidden forwarding rules. Report to IT.
Unable to sign in to your accountAttacker changed the passwordUse self-service password reset at passwordreset.microsoftonline.com. If that fails, phone your IT help desk rather than emailing — ask them to reset your password and sign out every active session, and tell them when you last signed in successfully.
MFA prompts appearing that you did not initiateSomeone is attempting to sign in with your passwordDo not approve the prompt. Change your password immediately and report to IT.