spam from <preview@***> where the *** part changes each time

Anonymous
2024-08-06T00:01:19+00:00

How can I get spam emails from these senders to stop? They are in the junk folder, so rules don't work.

Outlook | Windows | Classic Outlook for Windows | For business

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

68 answers

Sort by: Oldest
  1. Anonymous
    2024-09-19T15:26:15+00:00

    One more person here with the exact same issue.

    Since this seems to be an Outlook specific issue not happening anywhere else, it leads to the conclusion that Microsoft is either technically not able to, or (worse?) unwilling to resolve its customers problems?

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-09-19T22:06:09+00:00

    As someone who tests software for a living, I can say with certainty that this is an attack specifically aimed at Outlook and no other service. The reason for it is because of how Microsoft set up Outlook to only block domains on their Junk Folder. This means a botnet can send crazy amounts of phishing emails using phony domains without having to change the prefix on an email address and there's no way for users to block any of it. The fact that it goes directly into the Junk Folder is by design from this particular hacking group. What they're hoping for is someone will click on one of the two links they have in their emails accidentally when they go to try and delete them.

    It's clear to me that Microsoft doesn't seem to see this as a threat to their users and believe it to be an inconvenience that they can let go without consequence. Given the nature and danger of this particular attack, this is being grossly misjudged. These emails are dangerous and need to be blocked such that they never get to the Junk Folder. It does make me wonder if there's a way to get US federal regulators involved to force MS to do the right thing and protect its users from harm.

    Either way, this whole thing has been extremely disappointing to me. I've used Outlook and Microsoft 365 (PAID) for years and this is the first time I feel like I don't matter as a customer. It's not fun having to spend chunks of my day scanning through all those "preview" emails in my Junk Folder to make sure nothing legitimate has made it into there. It used to be about 4 emails per hour. It appears to have increased over the last week or so. Probably because this hacking group managed to increase the size of its botnet.

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-09-19T22:57:38+00:00

    Thanks for the excellent answer. And, as you may know, these emails go in cycles. I used to get hundreds of "renew@XXX". Those finally went away, followed by "Preview@XXX". Others with different sender name are dropping in to.

    Too bad Microsoft does nothing about it. But I also agree that the US Government needs to get involved. I spend a lot of time going through my junk email looking for legitimate emails mixed in with all the BOT emails.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-09-19T23:32:20+00:00

    Hey it's my pleasure. Someone earlier on said that this was a "hack". It's really an exploit that Microsoft doesn't feel the need to fix. The sheer volume of emails coming from this hacking group speaks to that. I've got email accounts with other services that don't generate even 5% of the total phishing spam emails that I'm getting through Outlook. Btw I got the renew ones as well earlier on. I'm sure the prefix will change again sometime soon, if it hasn't already for some folks (like you've been reporting).

    I wish someone from the Microsoft community team would acknowledge this as an exploit and at least say that they're working on it. I notice they stopped communicating to this thread when it was clear that their solutions weren't working.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-09-20T01:01:59+00:00

    Yes great points Josh. As I mentioned earlier being able to set a block filter of preview@*.* using wildcard characters for the domain would be a great solution.

    As someone who work MS Support when Windows 95 was released I can say that this kind of issue would have been resolved within a week. We live in a world of pay more and get nothing. The more this remains unresolved, the more upset users will get. To Microsoft, upset users leave and find alternatives.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments