Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
The email address and the type of information requested are consistent with how Microsoft Support handles compromised-account investigations, but only the official security and recovery flows and the sender domain can be used to judge legitimacy.
Key points based on Microsoft guidance:
- How to check if the email is genuine
- Microsoft support uses
microsoft.comand related domains for support mail. The domain list in the guidance includesmicrosoft.comas a valid support domain. - For security alerts about unusual sign-in, legitimate messages come from the Microsoft account team at
******@accountprotection.microsoft.com. - For OneDrive and some consumer notifications, legitimate domains include
@notificationmail.microsoft.comand@infomail.microsoft.com. - For general support, Microsoft documents that genuine support mail comes from domains such as:
-
microsoft.com -
microsoftsupport.com -
mail.support.microsoft.com -
office365support.com -
techsupport.microsoft.com
-
- If the message is really from
…@microsoft.comand passes normal mail checks in the mail client (no spoofing indicators, no “?” unverified sender icon in Outlook, no suspicious “via” domain), that aligns with a genuine Microsoft support email.
- Microsoft support uses
- The type of data they are asking for
- For hacked or taken-over accounts, Microsoft uses an account recovery form and then validates ownership using historic data: profile details, contacts, message subjects, billing fragments, Xbox details, etc. This matches the pattern in the email: they are asking for information that only the real owner is likely to know.
- The guidance for compromised accounts and recovery emphasizes that the “key to passing the validation process is to provide as much information as possible” and that the process is automated and based on data associated with the account before it was changed. The email text mirrors that process.
- Billing information: Microsoft’s documented recovery flows may use partial billing details (for example, last four digits of a card, name, expiry) as proof of ownership. Providing only the last four digits and expiry date is standard in verification flows and does not allow new charges to be made by itself.
- IP addresses: Microsoft’s recovery guidance also uses sign-in history and locations. Supplying IPs from locations where the account was legitimately used is consistent with that.
- How to protect against phishing while proceeding
- Do not click any new or unfamiliar links in the email body. Instead, access Microsoft resources directly via known URLs such as the Microsoft account security page or the account recovery form referenced in official documentation.
- Compare the links in the email with the official ones used in Microsoft documentation, such as:
-
https://account.microsoft.com/security -
https://account.live.com/acsr -
https://account.live.com/password/reset
-
- If the email’s links differ from these official patterns, ignore the links and instead reply only via the email channel (if the sender domain is verified) or work only through the web flows reached by typing the URLs manually.
- In Outlook, if available, check for the unverified sender “?” icon or a suspicious “via” tag that shows a different underlying sending domain. Legitimate Microsoft mail should not show a mismatched or obviously unrelated “via” domain.
- Whether it is possible to avoid sharing “vulnerable” information
- Microsoft’s own guidance for hacked or compromised accounts and for failed automated recovery states that if sufficient correct information cannot be provided, the account may not be recoverable. The moderators in similar cases explicitly note that if the recovery form and manual validation do not succeed, the account cannot be recovered and support cannot override this.
- That means:
- The more accurate historical information is provided (contacts, subjects, billing fragments, Xbox details), the higher the chance of success.
- Withholding key data (such as billing fragments that are actually on the account) reduces the likelihood of passing validation.
- To minimize risk while still cooperating:
- Provide only the partial billing details requested (for example, last four digits and expiry), never full card numbers or CVV.
- Provide IP addresses only from networks that were used to sign in legitimately.
- Do not send any passwords or full payment data; Microsoft’s process does not require those.
- How to double-check the case and the agent
- Microsoft does not provide a public directory to look up individual support agents by name, but the existence of a service request ID and continued correspondence from a
…@microsoft.comaddress is consistent with a real case. - To confirm the case without relying on links in the email:
- Go to the official Microsoft Support site directly (by typing the URL from documentation into the browser, not by clicking the email link).
- Use the “Contact Support” or “Get Help” flow documented for account recovery and provide the service request number there. Support can confirm whether the case and email thread are genuine.
- Microsoft does not provide a public directory to look up individual support agents by name, but the existence of a service request ID and continued correspondence from a
If the sender domain is truly microsoft.com, the content matches the documented recovery process, and the service request ID is recognized when contacting Microsoft Support through the official site, then the email is consistent with a legitimate Microsoft support communication. In that case, providing the requested historical account information (in the limited form described above) is the documented path to attempt to regain access.
References:
- How to determine if an email from Microsoft support is genuine
- What happens if there's an unusual sign-in to your account
- Why did I get a message saying my files will be erased?
- Phishing and suspicious behavior in Outlook
- How to recover a hacked or compromised Microsoft account - Microsoft Support
- Help with the Microsoft account recovery form - Microsoft Support
- Your Microsoft account recovery request wasn’t granted - Microsoft Support
- My account got hacked - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- Need help with hacked microsoft account - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Is this legit email also? - Microsoft Q&A