I keep getting emails for a single-use code.

Anonymous
2023-08-07T16:14:20+00:00

Hi,

I keep getting emails for a single use code in my email. I probably receive 10 emails a day for the past few weeks. And I haven't been trying to request a code.

Email says:

We received your request for a single-use code to use with your Microsoft account.

Your single-use code is: 4*****7

If you didn't request this code, you can safely ignore this email. Someone else might have typed your email address by mistake.

Thanks,

The Microsoft account team

It's quite annoying. The email sender is from ___@___.___

I would like to stop getting these emails as I'm not trying request a code.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-08-07T16:45:37+00:00

Hello Priscilla_A,

Welcome to the Microsoft community.

I'm a Microsoft user like you, I hope you're doing well?

I understand how discomforting it can be to receive a one-time security code for your account when you didn't initiate.

However, it's a good idea to ignore this code if you haven't requested it.

One-time code is an essential security feature that prevents unauthorized access to your account. One-time code is required to access your account. These codes can be used only once and has expiration time for their usage.

You may receive one-time code emails if:

  1. Signing into your Microsoft account from a new device or browser.
  2. Resetting your Microsoft account password.
  3. Making changes to your Microsoft account security information.
  4. Signing into your Microsoft account from a new location.
  5. Unusual and suspicious activity is detected on your Microsoft account.

If someone mistakenly enters your account email ID, you can't stop them, that's out of your control (you don't know who it is), All you can do is ignore it, as suggested in the email.

The same applies if someone may be trying to intentionally access your Microsoft account, a one-time code is a security feature that prevents this unauthorised access.

You don't control the actions of others, hence you can't stop it.

If there was a way to stop it, Microsoft would state it in an email rather than suggesting you to ignore it any one-time code you did not initiate.

I will suggest you check your Microsoft account sign-in activity to make sure there are no unauthorised access. You can see a list of devices and browsers that have accessed your account recently.

Microsoft account management website: https://account.live.com/Activity

Here are a few things you can do to make your Microsoft account more secured:

  1. Create a strong password for your account
  2. Use the Microsoft Authenticator phone app to sign in without a password
  3. Make your account easier to recover
  4. Make sure your operating system has the latest updates
  5. Never reply to email asking for your password
  6. Check your recent activity
  7. Keep your devices safe

Click link below for more information:

https://support.microsoft.com/help/628538c2-7006-33bb-5ef4-c917657362b9

If you are receiving blackmail emails, please report this issue to the nearest authorities.

Please let me know if you need any further assistance.

Give back to the community, help the next person who has this problem by pointing out if this answer solved your problem. Click "Yes" or "No" below.

Warm Regards

Was this answer helpful?

500+ people found this answer helpful.
0 comments No comments

137 additional answers

Sort by: Most helpful
  1. Anonymous
    2024-02-17T00:02:13+00:00

    Set up a Rule in outlook to forward these emails to Junk. I've been getting them for several months, and today was a bit extra with them, so I set up that rule.

    I was going to say I hope that helps, but it just did. Another email just ended up in my Junk folder. And no notification on my phone, which was starting to drive me nuts!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-02-16T21:53:03+00:00

    For anyone reading this, this is an attempt to get into your account. This is how it works and why you are getting so many:

    Bad actors have massive lists of emails, they will send a login request to each and the code is a number less than 10million. If hackers have a list of 10million accounts, odds are, they will access one of them if they guess a random number within that (law of averages). They can then repeat these 10million login requests multiple times per day and will have a successfully hijacked account each time. They will use proxy servers to rotate their IP address on each request to evade being blocked.

    I'm a full stack engineer who has worked in software security for 15 years and even I am getting these with no way to stop the emails, however you can enable 2 factor authentication which can help.

    If Microsoft simply increase the type or amount of characters to an amount that's actually secure, it would certainly stop these spam emails overnight.

    It's possible that these emails mean that someone is trying to log into a *different* account than the one which receives the email, right? As in, if you have an account that has two-factor on and uses this email as the backup contact method, then these emails we're getting could mean the threat is somewhere else? Is that right or does that make sense?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-02-04T03:25:24+00:00

    Thank you, it's sad that Microsoft doesn't wanna admit that we're being hacked.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-02-04T02:13:16+00:00

    For anyone reading this, this is an attempt to get into your account. This is how it works and why you are getting so many:

    Bad actors have massive lists of emails, they will send a login request to each and the code is a number less than 10million. If hackers have a list of 10million accounts, odds are, they will access one of them if they guess a random number within that (law of averages). They can then repeat these 10million login requests multiple times per day and will have a successfully hijacked account each time. They will use proxy servers to rotate their IP address on each request to evade being blocked.

    I'm a full stack engineer who has worked in software security for 15 years and even I am getting these with no way to stop the emails, however you can enable 2 factor authentication which can help.

    If Microsoft simply increase the type or amount of characters to an amount that's actually secure, it would certainly stop these spam emails overnight.

    Was this answer helpful?

    0 comments No comments