Using Outlook for Android in business environments for email and scheduling
I got the same email last year and today. This is most likely a "spoof" email scam. This is what I did:
When you open the email in Outlook, there are 3 dots in the top of the email, click it, and there are options. Click "View" then "Message Source".
https://learn-attachment.microsoft.com/api/attachments/47cadfd2-b992-4913-8701-df1ef245b0c3?platform=QnA
You'll then get a pop up with the email headers. The sender's IP address is in this. Scroll down just a little to find the words "Received: from" and there is the sender's IP address.
Here is my email header from the scam email:
Received: from DM8PR01MB6933.prod.exchangelabs.com (::1) by SJ0PR01MB6448.prod.exchangelabs.com with HTTPS; Thu, 10 Jul 2025 22:11:10 +0000 Received: from DU2PR04CA0357.eurprd04.prod.outlook.com (2603:10a6:10:2b4::32) by DM8PR01MB6933.prod.exchangelabs.com (2603:10b6:8:12::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8901.28; Thu, 10 Jul 2025 22:11:09 +0000 Received: from DB3PEPF00008859.eurprd02.prod.outlook.com (2603:10a6:10:2b4:cafe::de) by DU2PR04CA0357.outlook.office365.com (2603:10a6:10:2b4::32) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.8922.24 via Frontend Transport; Thu, 10 Jul 2025 22:11:08 +0000 Authentication-Results: spf=softfail (sender IP is 156.246.234.106) smtp.mailfrom=live.com; dkim=none (message not signed) header.d=none;dmarc=fail action=none header.from=live.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning live.com discourages use of 156.246.234.106 as permitted sender) **Received: from (156.246.234.106)**Go to an IP address lookup site, I used https://www.ip-lookup.org/ scroll down a little until you see where you can search for IP address. The IP address from my sender is from 156.246.234.106 and is from Hong Kong.
Next go to your recent sign in activity for your Microsoft Account. These are instructions for a personal account, if you have a business account, you may have to contact the Admin of the business account (if it's not you).
Go to account.microsoft.com.
- Sign in with your Microsoft credentials.
- Click on Security in the top menu.
- Select Review recent activity.
- You'll see a list of sign-ins from the past 30 days, including:
- Location and IP address
- Device and browser used
- Whether the sign-in was successful or blocked
- Any security challenges (like two-factor authentication
If all looks okay, no need to worry. No one has accessed your Microsoft Account. Then this is a fake scam email.
You can always change your password and make sure you have multi-factor set up, just in case.
I f you're in the US, you can also file a complaint for the email with Internet Crime Complaint Center https://www.ic3.gov/