I keep getting emails for a single-use code.

Anonymous
2023-08-07T16:14:20+00:00

Hi,

I keep getting emails for a single use code in my email. I probably receive 10 emails a day for the past few weeks. And I haven't been trying to request a code.

Email says:

We received your request for a single-use code to use with your Microsoft account.

Your single-use code is: 4*****7

If you didn't request this code, you can safely ignore this email. Someone else might have typed your email address by mistake.

Thanks,

The Microsoft account team

It's quite annoying. The email sender is from ___@___.___

I would like to stop getting these emails as I'm not trying request a code.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-08-07T16:45:37+00:00

Hello Priscilla_A,

Welcome to the Microsoft community.

I'm a Microsoft user like you, I hope you're doing well?

I understand how discomforting it can be to receive a one-time security code for your account when you didn't initiate.

However, it's a good idea to ignore this code if you haven't requested it.

One-time code is an essential security feature that prevents unauthorized access to your account. One-time code is required to access your account. These codes can be used only once and has expiration time for their usage.

You may receive one-time code emails if:

  1. Signing into your Microsoft account from a new device or browser.
  2. Resetting your Microsoft account password.
  3. Making changes to your Microsoft account security information.
  4. Signing into your Microsoft account from a new location.
  5. Unusual and suspicious activity is detected on your Microsoft account.

If someone mistakenly enters your account email ID, you can't stop them, that's out of your control (you don't know who it is), All you can do is ignore it, as suggested in the email.

The same applies if someone may be trying to intentionally access your Microsoft account, a one-time code is a security feature that prevents this unauthorised access.

You don't control the actions of others, hence you can't stop it.

If there was a way to stop it, Microsoft would state it in an email rather than suggesting you to ignore it any one-time code you did not initiate.

I will suggest you check your Microsoft account sign-in activity to make sure there are no unauthorised access. You can see a list of devices and browsers that have accessed your account recently.

Microsoft account management website: https://account.live.com/Activity

Here are a few things you can do to make your Microsoft account more secured:

  1. Create a strong password for your account
  2. Use the Microsoft Authenticator phone app to sign in without a password
  3. Make your account easier to recover
  4. Make sure your operating system has the latest updates
  5. Never reply to email asking for your password
  6. Check your recent activity
  7. Keep your devices safe

Click link below for more information:

https://support.microsoft.com/help/628538c2-7006-33bb-5ef4-c917657362b9

If you are receiving blackmail emails, please report this issue to the nearest authorities.

Please let me know if you need any further assistance.

Give back to the community, help the next person who has this problem by pointing out if this answer solved your problem. Click "Yes" or "No" below.

Warm Regards

Was this answer helpful?

500+ people found this answer helpful.
0 comments No comments

137 additional answers

Sort by: Newest
  1. Anonymous
    2024-05-02T16:47:58+00:00

    It would certainly help if MSFT improved the wording of the message. Instead of "Someone else might have typed your email address by mistake", it should say "Someone is trying to break into your account". Of course they won't do this, because users would panic (and would be justified in doing so), and try to call MSFT for help (which MSFT doesn't want to happen). They are not totally averse to accurate wording -- I just added an authenticator login method and received an email stating "If this wasn't you, a malicious user has access to your account".

    The real problem is that authentication codes are only six digits. If the attacker attempts to crack one account per second and simply guesses a six-digit number, on average they will crack an account every eleven days. And surely they can make far faster attempts using botnets -- cracking several accounts per day is not out of reach. Authentication codes should be expanded to at least twelve digits. Unfortunately, even authentication apps and devices generally use six-digit codes, or eight digits at most.

    Since I have added an authenticator app, I should be able to remove the other methods of receiving a code. Currently I'm only receiving codes at one email, but I suspect that if I remove that method, I'll start getting that at another email or a text. I think I'll have to remove all three and leave just the authenticator app.

    But that still leaves the danger from the six-digit codes. If the attacker is hitting my account ten times a day -- a rate that some people have seen, though mine is less -- it would be about 300 years ON AVERAGE before my account is compromised. I might be able to live with that -- me and the internet will change a bit in that time -- but that comes out to several hundred people in my city being compromised annually.

    So I may eventually remove all recovery methods. This of course requires being absolutely certain that I can always find my password. I've worked in Information Technology for over 50 years, and even I have to think hard before saying I'm totally certain. I'm certain but I don't want to count on it in a hurry ...

    Stanivuk Bujas wrote: "it's plainly obvious that someone is using a VPN while trying to brute force the single-use code. IP address that has made the unsuccessful login attempt changes from country to country". Actually, I think what this says is that someone is using botnets for the attack. Most email providers are by now mostly successful in blocking traffic from known botnet nodes, including surely Outlook. So MSFT should be blocking login attempts from known botnet nodes. Maybe they are and this is just the remnants that haven't been cataloged yet. Or maybe as part of their push to have all Windows users sign in to microsoft.com just to use their own Windows computer, they are forced to accept connections from botnets.

    "IP address is never from MY country, so I am clearly not targeted in any intelligent way.. it's just brute force and scripts". I agree, and this is important. Attempt a login, and after entering a password that's expected to fail, ask for a code. A few seconds later, enter a random six-digit number. This will only succeed one time in a million (annoying a million users in the process), but that's enough for a script kiddie with a botnet. What I do not know is whether guessing the code is sufficient to crack the account if two-factor authentication (2FA) is set -- perhaps account recovery requires access to two methods -- say two email accounts, or SMS plus authenticator code, etc.

    "I understand the low probability of attackers guessing a 6-digit number". Yep, but one in a million ...

    So in closing: I think (not yet verified) the way to stop these cracking attempts is to remove all account recovery methods from one's MSFT account, other than authenticator apps. Of course, before doing this, be very certain that your password is very secure (see https://lowe.github.io/tryzxcvbn/) and that you can always figure out where you saved it. Use a password manager, and print a copy of the password manager's login info and put it in a safe deposit box. Or something like that.

    Was this answer helpful?

    0 comments No comments
  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Anonymous
    2024-05-01T12:34:44+00:00

    MICROSOFT SHOULD DO SOMETHING. ANYTHING!!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-04-30T20:55:03+00:00

    I have the same problem as the person who posted this question. Someone keeps trying to access my account, it happens very very often, for over a year. Also on top of this, I am never allowed to log into my main microsoft account, on any new device or website, because "someone has recently been trying to log in using the wrong password too many times" and I have a new phone which I can't connect the account to. And I can't really sign in anywhere. This account is important to me I've had it for over 15 years and I need it for many things, I can't just change to a new one. Even when I'm writing the right password it never lets me log in. Because it's always blocked from attempting to log in due to too many recent incorrect attempts (which isn't even me) I've tried many times over the last few months. But I'm still signed in on my old phone which is my only access to that account. If that phone ever breaks I'm afraid I'll never have access to it again.

    Was this answer helpful?

    0 comments No comments