Impersonation Scams

Microsoft Account Scam Emails: How to Spot Them

Fake Microsoft security alerts and 'your PC is infected' pop-ups both lead to the same place. Here is how to check what is real.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Verify sign-in claims yourself: type account.microsoft.com into your browser, sign in, and open the Recent activity page — every genuine security alert is listed there. Microsoft does not send unsolicited emails or make unsolicited phone calls asking for personal or financial information, and error messages from Microsoft never include a phone number to call. Any pop-up that gives you a support number is a scam.

Warning signs to look for

  • 'Unusual sign-in activity' emails with a link to review rather than a prompt in your account
  • Notices that your Outlook or Microsoft 365 mailbox will be closed unless you verify
  • A full-screen browser warning with a Microsoft logo and a support telephone number
  • Sender domains that are not microsoft.com or outlook.com
  • A shared document notification from someone you do not know
  • An unexpected multi-factor prompt arriving repeatedly on your phone

The security-alert lure

Fake 'unusual sign-in activity' emails work because Microsoft genuinely sends similar notices. The forgery adds a link to a lookalike sign-in page that captures your password and then triggers a real multi-factor prompt on your phone, hoping you approve it out of habit. A related tactic is prompt bombing: repeated approval requests sent late at night until someone taps Approve to stop the noise. If a prompt arrives when you are not signing in, always deny it and change your password.

The fake tech-support pop-up

The other major Microsoft impersonation is not email at all. A browser page locks up with alarming text, a siren, and a number for 'Microsoft Support'. Calling connects you to an operation that asks for remote access, shows you harmless system logs presented as infections, and charges for a fictional repair — sometimes returning months later offering a refund that is itself a second scam. Microsoft states clearly that its error and warning messages never include a phone number.

How to check what is actually happening

Type account.microsoft.com yourself and sign in, then open Security and Recent activity. Genuine sign-in alerts appear there with device and location detail. For work or school accounts, contact your IT team rather than acting on the email. To clear a locked browser page, close the tab or quit the browser entirely — using Task Manager on Windows or Force Quit on a Mac if needed — and never call the number shown.

What Microsoft asks you to do

Microsoft asks customers to report phishing through the Report Message option in Outlook and through its reporting page, and publishes guidance on avoiding technical-support scams. It reiterates that unsolicited contact asking for payment or personal details is not from Microsoft. Reporting in Outlook also improves filtering for everyone else.

If you already entered your password or approved a prompt

Change your Microsoft account password from a device you trust and sign out everywhere from the security settings. Review recent activity, connected devices, app passwords, and mailbox forwarding rules — attackers frequently add a rule that quietly copies your mail. Re-register your authentication method. If it was a work account, tell IT immediately. If you allowed remote access, disconnect the machine, uninstall the tool, run a full scan, and contact your bank if payment details were shared.

Check before you click

If a security alert looks plausible but you are unsure, forward the original message to check@spamcheck.com. SpamCheck will explain what the sender and links actually are, in plain English, so you can act with confidence rather than guessing.

SpamCheck is not affiliated with or endorsed by the companies mentioned in this guide. Brand names are used only to help consumers identify potential impersonation scams.

Frequently asked questions

I keep getting multi-factor prompts I did not request. What should I do?
Deny every one, then change your password immediately — someone already has it. Report it to your IT team if it is a work account.
Does Microsoft ever call customers?
Not out of the blue. Microsoft does not make unsolicited calls about viruses, licences, or refunds. Hang up on anyone who does.
My browser is frozen on a warning page. How do I close it?
Force the browser to quit rather than interacting with the page: Task Manager on Windows, Force Quit on a Mac. Then reopen without restoring tabs and run an antivirus scan.
Is SpamCheck affiliated with Microsoft?
No. SpamCheck is independent and is not affiliated with, sponsored by, or endorsed by Microsoft. The brand is referenced only to help identify impersonation.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides