Microsoft Account Suspended Scam Email: How to Spot It
Microsoft gives `micros0ft.com`, with a zero replacing the second “o”, as an example of a lookalike domain used in phishing.
What the scam looks like
The email claims unusual sign-in activity, a security hold or an imminent suspension affecting a Microsoft, Outlook or Xbox account. It creates urgency and links to a page made to resemble a Microsoft sign-in. A fraudulent page may steal the credentials entered into it. A phone call or pop-up claiming to be Microsoft technical support is a different pattern; see Microsoft Support Scam UK: Spot Fake PC Virus Calls.
Microsoft's published warning signs
Microsoft advises users to watch for urgent demands, unexpected senders, generic greetings, poor spelling or grammar, mismatched links and lookalike domains. Its examples include micros0ft.com and rnicrosoft.com. None of those signs is conclusive on its own, and polished phishing emails may contain no language errors.
Outlook indicators
Outlook may show a question-mark icon for an unverified sender, an underlined “via” label when the visible From address differs from the authenticated sending domain, or a warning that it could not verify the sender. Microsoft cautions that not every unverified message or “via” label is malicious.
Check the account safely
Do not use the email link. Open a new tab and type account.microsoft.com, then review security and recent activity. Microsoft says that if an unusual-activity email is uncertain, you can safely sign in directly without clicking the email.
If credentials were entered
Use Microsoft's compromised-account guidance. Scan the affected computer for malware, change or reset the password, review recent activity and account settings, and enable two-step verification. Change the password on other accounts if it was reused. For a work or school account, notify the organisation's IT administrator as well.
Report the phishing email
In Microsoft 365 Outlook or Outlook.com, select the message and choose Report > Report phishing. If you use another email client, Microsoft says to send the phishing message as an attachment in a new email to phish@office365.microsoft.com — attach the original rather than forwarding it, so the technical headers are preserved. A Microsoft 365 administrator can also use the Submissions page in the Microsoft Defender portal. UK readers should additionally forward the email to the NCSC at report@phishing.gov.uk.
If money was lost or an account was hacked, report the crime to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland; in Scotland, call Police Scotland on 101.
Frequently asked questions
Where should I check a claimed suspension?
Go directly to account.microsoft.com; do not follow the email link.
Does an Outlook warning prove the email is malicious?
No. It is a reason for caution, not proof. Verify the claim by signing in directly.
Sources checked
- Microsoft Support: Protect yourself from phishing
- Microsoft Support: Phishing and suspicious behaviour in Outlook
- Microsoft Support: Check recent Microsoft-account sign-in activity
- Microsoft Support: Recover a hacked or compromised account
- NCSC: Report a scam email
- Microsoft Learn: Report spam, non-spam, phishing, suspicious emails, Teams messages, and files to Microsoft
- Report Fraud: reporting cyber crime and fraud