Skip to main content
PVAVRT
Microsoft Unusual Sign-in Activity Email: Real or Phishing?

September 21, 2026

Microsoft Unusual Sign-in Activity Email: Real or Phishing?

Microsoft sends real unusual sign-in alerts and attackers copy them. Here is how to check the sender, read your Recent activity page yourself, and secure an Outlook.com or Hotmail inbox if a sign-in was not yours.

OutlookHotmailAccount SecurityPhishingHow-To
Table of contents
  1. The Microsoft account unusual sign-in activity email, explained
  2. Checking whether the email is genuine
  3. Reading your Microsoft account recent activity
  4. If an entry wasn’t you
  5. Hotmail account hacked: what to do when you can’t sign in
  6. When Microsoft blocks a sign-in
  7. Keeping future alerts useful
  8. Running separate Microsoft inboxes for your own projects

A Microsoft account unusual sign-in activity email lands in your inbox, and the safest first reaction is to treat it as unproven. Microsoft genuinely sends these warnings, and people who want your password copy them closely, so the message itself can never settle the question. Your account can. Open your own activity log, read the entries, and decide from what you find there. This guide covers how a real alert differs from a copy, how to read each line on the Recent activity page, what to secure on an Outlook.com or Hotmail inbox when a sign-in was not yours, and what to do when you cannot get in at all.

The Microsoft account unusual sign-in activity email, explained

Why Microsoft sends the alert

Microsoft watches for sign-in attempts that do not match your usual pattern. Its page on what happens if there’s an unusual sign-in to your account explains that when a sign-in comes from a new location or device, Microsoft sends an email message and an SMS alert, and may block the sign-in until it can confirm the attempt is yours.

The alert is a notification, not a verdict. It fires on a successful sign-in you made from a hotel network just as readily as on a stranger’s attempt.

What a genuine alert asks you to do

A real alert points you back at your own account. Microsoft’s instruction is to open the Security basics page and select Review activity, which takes you to the Recent activity page. From there you either confirm the entry or secure the account.

What a real alert never does is ask for your password. Microsoft’s Outlook.com protection guidance is blunt about it: Microsoft will never ask for your password in email, so never reply to any email asking for any personal information, even if it claims to be from Outlook.com or Microsoft.

Why phishing messages copy it

Security warnings work on the reader’s nerves, which is why they get imitated. A fake version borrows the layout, the wording and the urgency, then sends you to a sign-in box that harvests what you type. Some copies add a fabricated location to sharpen the panic. None of it is hard to produce, which is why the look of a message proves nothing.

Checking whether the email is genuine

The @accountprotection.microsoft.com sender domain

Microsoft’s page on whether you can trust email from the Microsoft account team gives one concrete test: if the email address domain is @accountprotection.microsoft.com, it is safe to trust the message and open it. The alert pictured on Microsoft’s unusual sign-in page arrives from account-security-noreply@accountprotection.microsoft.com.

Two cautions come with that. First, read the address itself, not the friendly name your mail app displays, since the name is free text an attacker chooses. Second, Microsoft’s same page adds a check unrelated to the sender: confirm the account mentioned is yours, and that you requested any code included.

What you seeWhat it means
Address ends @accountprotection.microsoft.comMatches the domain Microsoft names as trustworthy
Display name says Microsoft, address does not matchNothing is confirmed; the name is chosen by the sender
A code you never asked forSomeone is trying your account, or mistyped their own address
Any request for your passwordNot from Microsoft

Looking at the message headers

Microsoft suggests going a step further: you can view the email’s message headers to be sure the email is from Microsoft. Outlook.com and most desktop mail apps can show them, though the menu path differs by app. You are looking for the real sending domain in the delivery path rather than the friendly line at the top of the message.

Useful confirmation, not a substitute for the next step.

Going to your account directly instead of clicking

Whatever the headers say, do not use the links in the message. Type account.live.com/Activity into the address bar yourself, or use a bookmark you made earlier, and sign in from there. Microsoft’s Outlook.com guidance tells you what a correct sign-in page looks like: if the URL that appears in the address bar when you sign in doesn’t include login.live.com, you could be on a phishing site.

If the alert was genuine, the matching entry is waiting for you on the activity page. If nothing matching is there, the message is almost certainly a copy, with one caveat from Microsoft: the page does not show all account activity, only the significant events, so an empty list is strong evidence rather than proof. To dispose of a fake, Microsoft’s phishing guidance for Outlook says to select the message and, above the reading pane, select Report > Report phishing.

One situation changes that. If you already followed the link and typed your password or a security code into the page it opened, treat the account as compromised even when the activity log looks clean: whoever sent it holds the password and may simply not have used it yet. Work through the steps under “If an entry wasn’t you” below.

Reading your Microsoft account recent activity

The 30-day window

The Recent activity page lives at account.live.com/Activity and covers the last 30 days. Anything older has rolled off, so a monthly glance beats an annual audit.

Two sections can appear: Recent activity for ordinary account events, and Unusual activity, which shows only when Microsoft has flagged something.

Successful sign-ins and incorrect password attempts

Microsoft’s list of entry types is longer than most readers expect. The common ones are Successful sign-in, Incorrect password entered, Password changed, Account created, Two-step verification turned on or turned off, Unusual activity detected, and the two blocked labels, Sign-in blocked (Account compromised) and Sign-in blocked (Account temporarily suspended). Expanding an entry shows the location, the device, the IP address and the access method behind it.

The distinction that matters is simple. An incorrect password entered line is an attempt that failed. A successful sign-in is an attempt that worked. A long run of failures is unpleasant but survivable; one success you cannot place is the line to act on.

‘This was me’ and ‘This wasn’t me’

The two response buttons belong to the Unusual activity section. Expand a flagged entry and choose This was me to confirm it, or This wasn’t me when the activity is not yours or you are unsure. Choosing the second option starts Microsoft’s secure-the-account path.

Entries in the ordinary Recent activity section work differently. Microsoft’s instruction there is that if you see anything suspicious, such as multiple sign-in attempts or profile changes you didn’t make, select Secure your account.

Why a phone can show a distant location

Before you treat a strange city as proof, read Microsoft’s own caveat on the same page: mobile phone services route activity through different locations, so it may look like you signed in from somewhere that’s not your actual location. Corporate networks and VPNs do the same.

Judge the entry on the device and the time first. A location you do not recognize attached to a phone you do own is usually routing. A device you have never owned is a different matter.

If the Recent activity page is blank or won’t load

There is no Microsoft support page documenting a blank Recent activity page, so nothing below is an official instruction. As ordinary browser troubleshooting: confirm you are signed in to the account you meant to check, reload, try a private window, switch browsers, turn off extensions that block scripts, and try another device or network.

If it stays empty everywhere, contact Microsoft support. Do not hand your credentials to a third-party service offering to read the log.

If an entry wasn’t you

Scan for malware, then change the password

Microsoft’s guidance on recovering a hacked or compromised account puts the order plainly: clear your PC of viruses or malware before you change your password. A new password typed on a compromised machine is captured as easily as the old. In Windows Security, open the Virus and threat protection tab, then select Scan options > Full scan > Scan now, and follow the instructions on the screen.

Only after the machine is clean should you change or reset the password.

Review security info and remove what isn’t yours

Security info is the set of phone numbers and email addresses that can reset your account. If a stranger added one, the password change alone achieves little, because the reset path still leads back to them. Open your security settings and confirm every listed contact is yours and still reachable.

Readers who also use Gmail can run the same check for a Google account, which keeps its own device list and recovery options in a separate place.

Check forwarding, inbox rules and automatic replies

Microsoft’s recovery page names three settings to review after the password: connected accounts, forwarding and automatic replies. A quiet forwarding rule is the classic way to keep reading an inbox long after the password has moved on.

While you are in the mail settings, check inbox rules too, since a rule that files or deletes security mail hides the next alert from you. That one is a sensible habit rather than a Microsoft instruction.

Turn on two-step verification

Microsoft’s Outlook.com page is direct about the payoff: two-step verification helps protect your account by making it more difficult for a hacker to sign in, even if they have your password. It is the single change that survives a password leak.

Hotmail account hacked: what to do when you can’t sign in

The password reset tool

When the password no longer works, the reset tool is the front door. It uses the phone number or alternate email already on the account, which is why keeping those current matters.

‘I think someone else is using my Microsoft account’

Microsoft’s unusual sign-in page names the specific option to pick during recovery: I think someone else is using my Microsoft account. That choice routes you into the compromise path instead of a routine reset, and it is the right one whenever the account was taken rather than forgotten.

When the reset tool isn’t enough

If the contact methods are gone too, the reset tool cannot finish, and Microsoft’s order from there is its account Sign-in Helper tool first, then the account recovery form. Its guidance on that form states the limit plainly: if you have turned on two-step verification and cannot access any of the alternate methods to get a verification, we cannot help you, sorry.

When Microsoft blocks a sign-in

Security codes to your email or phone

A block is not a lockout. Microsoft may stop a sign-in from a new device, app or location and then send a security code to the phone number or email address already on the account. Entering the code releases it.

A code arriving unprompted deserves attention: someone reached the code step with your address in hand.

Signing in while traveling

Microsoft lists a few options for a traveler who cannot reach the phone or email on the account. The one that stays inside your own control is a device you already trust: if you brought a device you normally sign in to and had set it as trusted, sign in from that. Microsoft frames the general rule the same way, saying access returns once you sign in from a trusted device or a usual location, so the other answer is to wait until you are back somewhere familiar. This applies only to an account that is yours.

Keeping future alerts useful

Security info you can still reach

An alert is only useful if you can answer it. Microsoft’s advice is to add an alternate email address and mobile phone number to your account, because having a secondary email address and mobile phone number can help restore your access quickly. Check once a year that both still belong to you.

Microsoft’s sign-in rules for inactive inboxes and accounts

The Microsoft Services Agreement, at 4.a.ii, sets two clocks with two different consequences. The shorter one covers the mailbox: an Outlook.com inbox needs its own sign-in within any one-year stretch, as does a OneDrive, and Microsoft says it will close them for you otherwise. The longer one covers the account: a single sign-in within any two-year stretch keeps a Microsoft account active, unless the Microsoft account activity policy allows longer, and Microsoft says it will close an account that stays quiet past that point. Either outcome removes a recovery contact you may be relying on elsewhere.

Running separate Microsoft inboxes for your own projects

If you keep separate Microsoft inboxes for your own projects, PVAVRT sells Outlook.com accounts and Hotmail accounts, and its guide to how Hotmail grades and mail-app sign-in work sets out the four Hotmail rows with their prices and what the labels do and do not tell you. Be clear-eyed about the trade: the Microsoft Services Agreement says account credentials cannot be passed to another user or entity, so buying an account goes against Microsoft’s terms and Microsoft can close it at any time. Creating your own Outlook.com address, or paying for Microsoft 365, keeps you inside the rules and is the better answer for most projects.

Whichever route you take, the habit from this article carries over: check every alert on the account itself rather than through a link in an email, and make sure the security info on each inbox is something you can still reach. Questions about grades or ordering go to PVAVRT on Telegram @pvavrt or WhatsApp +1 (310) 460-9890, and common questions are answered in PVAVRT’s FAQ. Confirm anything that matters to your order, including the minimum and the payment route, in the chat before paying.

Got questions about your specific use case?

We answer pre-sales questions on Telegram in minutes — no form, no funnel.

Chat on Telegram

FAQ

FAQ

Is the Microsoft unusual sign-in activity email real or a scam?
It can be either, and the message alone cannot tell you. Microsoft does send these alerts, and its support page says mail from the domain @accountprotection.microsoft.com can be trusted. The alert shown on Microsoft's unusual sign-in page comes from account-security-noreply@accountprotection.microsoft.com. Because a display name is easy to imitate, open the address itself rather than the label, and then go to account.live.com/Activity by typing it in yourself. If nothing matching is there, the message is almost certainly a copy, though Microsoft says the page does not show every event, so change the password if you are still unsure.
What email address does a genuine Microsoft security alert come from?
Microsoft's page on unusual sign-ins shows the alert arriving from account-security-noreply@accountprotection.microsoft.com, and its separate guidance on trusting mail from the Microsoft account team says an address on the @accountprotection.microsoft.com domain is safe to open. Microsoft also suggests viewing the message headers to confirm the source. Even then, do not act inside the email. Nothing genuine from Microsoft asks for your password in a reply, so treat any such request as fake.
How do I check my Microsoft account recent activity?
Sign in and open the Recent activity page at account.live.com/Activity. It shows the last 30 days of account use. Microsoft's list of entry types is long; the common ones are Successful sign-in, Incorrect password entered, Password changed, Account created, Two-step verification turned on or turned off, Unusual activity detected, and Sign-in blocked (Account compromised) or Sign-in blocked (Account temporarily suspended). Expanding an entry reveals the location, device, IP address and access method. If a suspicious line appears in the Recent activity section, Microsoft's instruction is to select Secure your account.
Why is my Microsoft account recent activity page blank?
Microsoft does not publish a support page about a blank Recent activity page, so there is no official fix to quote. As general troubleshooting, confirm you are signed in to the account you meant to check, reload the page, try a different browser or a private window, turn off extensions that block scripts, and open it on another device or network. If the list stays empty on every attempt, contact Microsoft support rather than trusting any third-party tool that offers to read the log for you.
An entry says incorrect password entered. Should I worry?
Not by itself. Microsoft lists incorrect password entered as one of the entry types on the Recent activity page, and a failed attempt means the sign-in did not succeed. Common causes include your own typo, an old password still stored on a device, or a stranger guessing and failing. The line that matters is a successful sign-in you cannot place. Repeated failures from places you have never been are still worth a password change and two-step verification.
What should I do first if someone signed in to my Hotmail account?
Microsoft's recovery guidance puts the malware scan before anything else, because changing a password on an infected machine can hand the new one straight over. In Windows Security, open the Virus and threat protection tab, then select Scan options > Full scan > Scan now. Then change the password, review your security info so only contacts you control remain, and check connected accounts, forwarding and automatic replies. Finish by turning on two-step verification.
Why does my Microsoft account activity show a city I have never visited?
Microsoft addresses this on the Recent activity page directly: mobile phone services route activity through different locations, so it may look like you signed in from somewhere that is not your actual location. A work network, a company VPN or a home connection that exits elsewhere can do the same. Match the entry against the device and the time first. A location on its own is weak evidence, while a device you do not own is strong evidence.
I cannot sign in at all. How do I get a Hotmail account back?
Start with password recovery. Microsoft's unusual sign-in page says to choose the option I think someone else is using my Microsoft account, which routes you through the compromise path rather than a plain reset. If the phone number and alternate email are gone, Microsoft points you at its account Sign-in Helper tool first and the account recovery form after that, completed from a device you previously used to sign in. Note the limit Microsoft states: with two-step verification on and no alternate method reachable, it says it cannot help you.

Added to cart

Order confirmed