Secure Outlook Calendar From Unwanted Entries

Tony Armalis 60 Reputation points
2026-03-07T19:07:58.9366667+00:00

I had a couple of events pop up in Outlook 365 that I know are scams. Is there a setting I over looked that stops others from adding to my calendar. I do not open any email that I don't recognize, or click on links I'm not sure of. Don't understand how they got entered. Be low is the text from one of the examples:

User's image

Microsoft 365 and Office | Other
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-07T19:08:16.8933333+00:00

    Those calendar entries are almost certainly phishing or scam invitations that arrived as meeting requests or auto-created events from email.

    To reduce this kind of abuse, use a combination of junk/phishing controls and calendar settings:

    1. Treat these as phishing
      • Do not click Join event, Cancel your registration, or call any phone numbers in the invite.
      • In Outlook, mark the message as Junk or Phishing so future messages from that sender/domain are filtered. Outlook’s junk filter and Spoof intelligence in Exchange Online Protection will then help prevent similar items from reaching the inbox or calendar.
      • Learn the signs of phishing: mismatched domains, urgent payment language, and Outlook banners that say the sender couldn’t be verified. See the guidance in Protect yourself from phishing.
    2. Block or restrict the sender/domain
      • In Outlook on the web: Settings → Mail → Junk email.
      • Under Blocked senders and domains, add the scammer’s email address or domain. Messages from them will go straight to Junk Email, and any associated calendar items will not clutter the main calendar.
    3. Use safe senders for legitimate sources
      • For organizations that should be allowed to create calendar events (airlines, trusted services), add them under Safe senders and domains in Settings → Mail → Junk email. This helps Outlook distinguish legitimate “events from email” from junk.
    4. Review calendar sharing and external access (admins)
      • If using Microsoft 365 for business, an admin can go to Microsoft 365 admin center → Settings → Org settings → Services → Calendar.
      • Under External sharing, restrict how much calendar information is shared externally. Recommended: disable broad external sharing, or at most allow Show calendar free/busy information with time only.
      • This does not stop email-based invites entirely, but it limits what external parties can see or do with shared calendars.
    5. Clean up existing scam events
      • Open each fraudulent calendar event and delete it from the calendar.
      • If prompted, choose not to send a response to the organizer.
    6. Continue to monitor for suspicious behavior
      • Watch for Outlook banners such as “we could not verify the sender,” mismatched email domains, or unexpected attachments/links, and handle them as junk or phishing.

    These steps use Outlook’s junk/phishing protections plus calendar sharing controls to minimize unwanted or scam entries appearing on the calendar.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.