Using Classic Outlook on Windows for personal email, calendar, and contact management
For a consumer Outlook.com/Microsoft account, direct manual “full security reviews” or per-account investigations are not available, but several built‑in tools and steps can address the concerns described.
- Review and report unusual sign‑ins
- Go to the Microsoft account Security basics page.
- Select Review activity to open the Recent activity page.
- Review all sign‑ins and security events. For any activity that is not recognized:
- If it appears under Unusual activity, expand it and select This wasn’t me.
- If it appears under Recent activity, expand it and select Secure your account.
- This both flags the activity to Microsoft and walks through additional securing steps.
- Force sign‑out of sessions and secure the account
- From the Security basics page, change the password again to a strong, unique password (different from any previously used).
- After securing devices (see step 4), use the Sign out everywhere option (available under Microsoft account security) to invalidate active sessions and tokens so any attacker is forced to re‑authenticate.
- Check Outlook.com account configuration again In Outlook on the web:
- Go to Settings → Mail → Rules and delete any rule that is not explicitly recognized.
- Go to Mail → Forwarding and ensure no forwarding address is configured.
- Review any connected apps or permissions (Manage app permissions) and revoke anything not recognized. These are common persistence methods when an account has been compromised.
- Check for compromise on devices Because drafts are being created and old passwords are referenced, devices used to access the account should be treated as potentially compromised:
- Run a full, up‑to‑date antivirus scan on all PCs and phones used with this account.
- Ensure the operating system on each device has the latest security updates installed.
- If malware is suspected and cannot be removed, consider backing up data and performing a factory reset (especially on recently added or suspicious devices).
- Monitor Outlook.com and Microsoft account security
- Use the recent activity page at https://account.live.com/activity to continue monitoring sign‑ins and security challenges.
- If any new suspicious activity appears, mark it as not yours as described above and follow the secure‑account flow.
- If access is lost or password stops working If sign‑in becomes impossible or the password appears to have been changed again:
- Follow the guidance in When you can’t sign in to your Microsoft account and use the account recovery process.
- On the sign‑in page, use Forgot my password and choose I think someone else is using my Microsoft account if compromise is suspected.
- Get additional Outlook.com support If the suspicious drafts or behavior persist after these steps:
- In Outlook.com, select Help on the menu bar, describe the issue, then scroll down to Still need help? and choose Yes to start a chat with a support agent (requires being signed in). If sign‑in is not possible, use the alternative help link provided in the Outlook.com phishing/suspicious behavior article.
These steps collectively provide: review of unauthorized activity, forced sign‑out of sessions, verification and cleanup of rules/forwarding/connected apps, and device‑level checks to remove any malware that could be generating drafts.
References:
- What happens if there's an unusual sign-in to your account
- Help protect your Outlook.com email account
- Respond to a compromised cloud email account
- Phishing and suspicious behavior in Outlook
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Need to speak to a agent I am getting pop up draft scam emails - Microsoft Q&A