Appearance
How to Spot Fake Microsoft Login Pages
Applies to: All Platforms (Windows, macOS, Mobile)
Article Type: Informational
Last Updated: 2026-03-09
Summary
Attackers frequently create fake Microsoft login pages that look identical to the real sign-in screen to steal your credentials. Learning how to verify the authenticity of a login page is one of the most effective ways to protect your account. This article teaches you the key indicators of a fake login page and what to do if you encounter one.
Prerequisites
- None. These tips apply to all users on any device.
Instructions
1. Check the URL Carefully
The address bar is the most reliable indicator of a fake page.
- Before entering any credentials, look at the URL in the address bar.
- A legitimate Microsoft login page will always use one of these domains:
login.microsoftonline.comlogin.live.comlogin.microsoft.comaccount.microsoft.com
- Watch for common tricks:
- Misspellings:
login.micros0ft.com(zero instead of "o"). - Extra words:
login.microsoftonline.com.secure-verify.com(the real domain issecure-verify.com, not Microsoft). - Different domain extensions:
login.microsoftonline.netor.info.
- Misspellings:
- The domain you need to check is the part immediately before the first single
/— everything after the/is a page path and can say anything.
2. Look for HTTPS and the Lock Icon
Verify the connection is encrypted.
- Check that the URL starts with
https://(nothttp://). - Look for a lock icon in the address bar.
- Click the lock to view the security certificate — verify it is issued to
Microsoft Corporation. - Important: HTTPS alone does not guarantee a site is legitimate — attackers can obtain certificates too. Always verify the domain as well.
3. Watch for Urgency and Fear Tactics
Phishing pages often create artificial pressure.
- Be suspicious if you are told:
- "Your account will be locked in 24 hours."
- "Unusual activity detected — sign in immediately."
- "Verify your identity now or lose access."
- Microsoft will never threaten account closure through a pop-up or unsolicited email.
- If you receive such a message, navigate to myaccount.microsoft.com manually — do not click any links in the message.
4. Check How You Arrived at the Page
Consider the context of why you are seeing a login prompt.
- Did you click a link in an unexpected email?
- Did a pop-up redirect you to a login page?
- Were you redirected from a search engine result?
- If you did not deliberately navigate to a Microsoft service, treat the login page with suspicion.
- When in doubt, close the browser tab and go directly to the Microsoft service by typing the URL manually.
5. Report a Suspicious Page
Help protect others by reporting fake login pages.
- Do not enter your credentials on the suspicious page.
- Copy the URL of the fake page.
- Report it to your IT department.
- Additionally, report the URL to Microsoft at microsoft.com/wdsi/support/report-unsafe-site.
- If you already entered your password, change it immediately and report the incident to IT.
Troubleshooting
WARNING
If you suspect you have entered your credentials on a fake page, change your Microsoft 365 password immediately and report the incident to your IT department. Enable MFA if it is not already active.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Login page looks correct but the URL is wrong | Phishing site cloning Microsoft's UI | Do not enter credentials. Close the tab and navigate directly to the Microsoft service. |
| Entered credentials on a fake page | Account may be compromised | Change your password at myaccount.microsoft.com immediately. Notify your IT department. |
| Repeated redirects to unfamiliar login pages | Malware or browser hijacking | Run a full antivirus scan and check browser extensions for anything unfamiliar. |