Flag drafted emails on my account every second

Katherine Diaz 0 Reputation points
2026-05-01T03:24:22.84+00:00

Hi, I need help with a potential security issue on my Outlook account.

Over the past few days, I have received multiple suspicious messages that appear with no sender, and at least one of them showed up as a draft inside my account. The message included my name and an old password I used in the past, which is very concerning.

This does not appear to be normal spam because the message is appearing within my account (as a draft), not just in my inbox.

I have already taken the following steps:

  • Changed my password to a new, strong password
  • Enabled two-factor authentication
  • Checked and removed any suspicious rules
  • Verified that email forwarding is turned off

Despite this, I am still concerned that there may be unauthorized access or hidden sessions connected to my account.

I am requesting:

  • A full security review of my account
  • Confirmation of any unauthorized login activity
  • Forced sign-out of all active sessions and tokens
  • Verification that there are no hidden rules, forwarding settings, or connected apps causing this behaviorHi, I need help with a potential security issue on my Outlook account. Over the past few days, I have received multiple suspicious messages that appear with no sender, and at least one of them showed up as a draft inside my account. The message included my name and an old password I used in the past, which is very concerning. This does not appear to be normal spam because the message is appearing within my account (as a draft), not just in my inbox. I have already taken the following steps:
    • Changed my password to a new, strong password
    • Enabled two-factor authentication
    • Checked and removed any suspicious rules
    • Verified that email forwarding is turned off
    Despite this, I am still concerned that there may be unauthorized access or hidden sessions connected to my account. I am requesting:
    • A full security review of my account
    • Confirmation of any unauthorized login activity
    • Forced sign-out of all active sessions and tokens
    • Verification that there are no hidden rules, forwarding settings, or connected apps causing this behavior
Outlook | Windows | Classic Outlook for Windows | For home

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-01T03:24:42.7433333+00:00

    For a consumer Outlook.com/Microsoft account, direct manual “full security reviews” or per-account investigations are not available, but several built‑in tools and steps can address the concerns described.

    1. Review and report unusual sign‑ins
    • Go to the Microsoft account Security basics page.
    • Select Review activity to open the Recent activity page.
    • Review all sign‑ins and security events. For any activity that is not recognized:
      • If it appears under Unusual activity, expand it and select This wasn’t me.
      • If it appears under Recent activity, expand it and select Secure your account.
    • This both flags the activity to Microsoft and walks through additional securing steps.
    1. Force sign‑out of sessions and secure the account
    • From the Security basics page, change the password again to a strong, unique password (different from any previously used).
    • After securing devices (see step 4), use the Sign out everywhere option (available under Microsoft account security) to invalidate active sessions and tokens so any attacker is forced to re‑authenticate.
    1. Check Outlook.com account configuration again In Outlook on the web:
    • Go to Settings → Mail → Rules and delete any rule that is not explicitly recognized.
    • Go to Mail → Forwarding and ensure no forwarding address is configured.
    • Review any connected apps or permissions (Manage app permissions) and revoke anything not recognized. These are common persistence methods when an account has been compromised.
    1. Check for compromise on devices Because drafts are being created and old passwords are referenced, devices used to access the account should be treated as potentially compromised:
    • Run a full, up‑to‑date antivirus scan on all PCs and phones used with this account.
    • Ensure the operating system on each device has the latest security updates installed.
    • If malware is suspected and cannot be removed, consider backing up data and performing a factory reset (especially on recently added or suspicious devices).
    1. Monitor Outlook.com and Microsoft account security
    • Use the recent activity page at https://account.live.com/activity to continue monitoring sign‑ins and security challenges.
    • If any new suspicious activity appears, mark it as not yours as described above and follow the secure‑account flow.
    1. If access is lost or password stops working If sign‑in becomes impossible or the password appears to have been changed again:
    • Follow the guidance in When you can’t sign in to your Microsoft account and use the account recovery process.
    • On the sign‑in page, use Forgot my password and choose I think someone else is using my Microsoft account if compromise is suspected.
    1. Get additional Outlook.com support If the suspicious drafts or behavior persist after these steps:
    • In Outlook.com, select Help on the menu bar, describe the issue, then scroll down to Still need help? and choose Yes to start a chat with a support agent (requires being signed in). If sign‑in is not possible, use the alternative help link provided in the Outlook.com phishing/suspicious behavior article.

    These steps collectively provide: review of unauthorized activity, forced sign‑out of sessions, verification and cleanup of rules/forwarding/connected apps, and device‑level checks to remove any malware that could be generating drafts.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.