Is this the real CDOC email

ntskkstar 0 Reputation points
2026-05-13T11:03:07.1766667+00:00

My original Microsoft account was hacked a couple of days ago. The worst part is that when the hacker logged into my account, they deleted my linked email address and linked their own, so when I try to use something like https://account.live.com/acsr it just tells me that account with such email doesn't exist. I did fill Recover your Microsoft account from xbox support, so I am waiting for some kind of response. after that a normal email came in with just an ask of confirmation that it is in fact the email that they look for, and after that I got this from the same email
I believe the email is valid, it's cdoccm@microsoft.com , got sent from microsoft.com , and is signed by microsoft.com

Service request SIR[number]

Greetings,

This is Jayson again with Microsoft Support. I am committed to resolving this issue to the best of my ability. 

If the account was accessed and the information changed, we will attempt to validate the account based on the information associated with the account prior to the change. Please use the information that you believe has been associated with the account, even if it may have changed. Note: if you fail to provide any of this information, we will not able to proceed with your claim.  

The key to passing the validation process is to provide as much information as possible. For questions that have multiple answers, such names of Hotmail folders, subjects and contacts, provide 3 or 4 answers instead of 1. If the postal code could be one of 2 or 3, provide all of them. Provide precise information. For example, instead of saying that you have Facebook e-mail, give the exact text ‘Facebook Notification – Friend request from John Doe.’ The more information that you provide and the more accurate you are with it, the more likely you are to pass validation.  

 

Information submitted in your online questionnaire 

Please submit an Account Recovery form. If you submitted your information directly to Microsoft account access support and we are unable to successfully validate the account, you will receive a nine-digit reference number. If you received this number, please reply to this email with the following information.  

 

  • Account recovery reference number:
  • The alternate email address you supplied in your online account recovery form: 

  

Your profile information on the account 

Name: 

Birth date: 

Country/region:  

Region/state: 

Postal/ZIP code: 

 

The email addresses of several contacts from your address book or messenger list: 

Tip: Check with friends or family members for the spelling of their email addresses 

  1.  
  2.  
  3.  
  4.  

 

Recent subjects of email you've sent from the account: 

Tip: Check with friends or family members that recently received an email from this account 

  1.  
  2.  
  3.  
  4.  

 

IP address 

List your IP address from a location where you accessed the account successfully in the past. If you have accessed the account from multiple locations or devices/phones, you may want to provide more than one IP address for a better chance at validating the account. To gather this information, please type in "What is my IP" in your search browser. 

  1.  
  2.  
  3.  
  4.  

 

Account history questions 

  1. The date that the account was created:
  2. The date that you last successfully logged in to the account:
  3. The date that you last changed the password:
  4. Alternate email addresses or phone numbers that are associated with the account:
  5. Location where the account was created: 

 

Billing information used for recent purchases/subscriptions: 

Billing name: 

Last four digits of credit card: 

Expiration date: 

 

 

 

Any Xbox gamertag(s) associated with this account: 

Tip: If you have an Xbox gamertag associated with this account, please provide as much information as possible about the console and gamertag. 

  1.  
  2.  
  3.  
  4.  

 

 

Console serial number:   

This can be located on the console itself, listed on the service tag sticker. 

 

 

Xbox 360 console ID: 

To find your console ID navigate to the Xbox Dashboard: 

  1. Go to the Settings hub and choose System.
  2. Select Console Settings.
  3. Select System Info.
  4. The console ID is displayed on the screen, below the console serial number. 

 

 

Xbox One Device ID: 

To find your device ID navigate to the Xbox Dashboard: 

  1. Go to the Settings hub and choose System.
  2. Select Console Info.
  3. Xbox Live Device ID is displayed on the screen.  

 

 

Windows/PC Device ID

To find your device ID:

  1. From Settlings, select Privacy & Security
  2. Select Diagnostics and Feedback
  3. View Diagnostic Data
  4. Open Diagnostic Data Viewer
  5. In any of the event logs, search for "xbl" to find the Device ID labelled “did” (see screenshot below for example)

 

Once I receive your response with the requested information, I will review it in order to verify account ownership. I will provide an update once this has been completed. Please feel free to reply to this message if you have additional questions about your issue. 

 

Thank you for your understanding and patience during the investigation of your account. I look forward to your response. 

 

Have a great day! 

Sincerely,

 

Jayson

Microsoft Customer Support  Working hours: 8PM to 5AM PST

Microsoft Support | Manage Microsoft Devices | Microsoft Account Profile | Microsoft Privacy Statement  

Legal Disclaimer: The information contained in this message may be privileged and confidential. It is intended to be read only by the individual or entity to whom it is addressed or by their designee. If the reader of this message is not the intended recipient, you are on notice that any distribution of this message, in any form, is strictly prohibited. If you have received this message in error, please immediately notify the sender and delete or destroy any copy of this message.  Report a SCAM: http://support.microsoft.com/reportascam

 

Ref:[number]

I have seen on this forum that this is a pretty typical letter, but as for everyone else, the billing information and ip adress seems really scary to type. It feels like a pretty legit email, the person in question doesn't emotionally scare me with words "we will delete your account" or "click this or", but personal information really bugs me.
I really wanna get my account back, is there a way to find out if Jason is a real support worker or if my service request number does really exist? And if it is true, do you think it would be possible for me to prove my ownership of the account without giving vulnerable information? I am sorry for my paranoia and am thankful to everybody in advance.

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-13T11:04:08.6566667+00:00

    The email address and the type of information requested are consistent with how Microsoft Support handles compromised-account investigations, but only the official security and recovery flows and the sender domain can be used to judge legitimacy.

    Key points based on Microsoft guidance:

    1. How to check if the email is genuine
      • Microsoft support uses microsoft.com and related domains for support mail. The domain list in the guidance includes microsoft.com as a valid support domain.
      • For security alerts about unusual sign-in, legitimate messages come from the Microsoft account team at ******@accountprotection.microsoft.com.
      • For OneDrive and some consumer notifications, legitimate domains include @notificationmail.microsoft.com and @infomail.microsoft.com.
      • For general support, Microsoft documents that genuine support mail comes from domains such as:
        • microsoft.com
        • microsoftsupport.com
        • mail.support.microsoft.com
        • office365support.com
        • techsupport.microsoft.com
      • If the message is really from …@microsoft.com and passes normal mail checks in the mail client (no spoofing indicators, no “?” unverified sender icon in Outlook, no suspicious “via” domain), that aligns with a genuine Microsoft support email.
    2. The type of data they are asking for
      • For hacked or taken-over accounts, Microsoft uses an account recovery form and then validates ownership using historic data: profile details, contacts, message subjects, billing fragments, Xbox details, etc. This matches the pattern in the email: they are asking for information that only the real owner is likely to know.
      • The guidance for compromised accounts and recovery emphasizes that the “key to passing the validation process is to provide as much information as possible” and that the process is automated and based on data associated with the account before it was changed. The email text mirrors that process.
      • Billing information: Microsoft’s documented recovery flows may use partial billing details (for example, last four digits of a card, name, expiry) as proof of ownership. Providing only the last four digits and expiry date is standard in verification flows and does not allow new charges to be made by itself.
      • IP addresses: Microsoft’s recovery guidance also uses sign-in history and locations. Supplying IPs from locations where the account was legitimately used is consistent with that.
    3. How to protect against phishing while proceeding
      • Do not click any new or unfamiliar links in the email body. Instead, access Microsoft resources directly via known URLs such as the Microsoft account security page or the account recovery form referenced in official documentation.
      • Compare the links in the email with the official ones used in Microsoft documentation, such as:
        • https://account.microsoft.com/security
        • https://account.live.com/acsr
        • https://account.live.com/password/reset
      • If the email’s links differ from these official patterns, ignore the links and instead reply only via the email channel (if the sender domain is verified) or work only through the web flows reached by typing the URLs manually.
      • In Outlook, if available, check for the unverified sender “?” icon or a suspicious “via” tag that shows a different underlying sending domain. Legitimate Microsoft mail should not show a mismatched or obviously unrelated “via” domain.
    4. Whether it is possible to avoid sharing “vulnerable” information
      • Microsoft’s own guidance for hacked or compromised accounts and for failed automated recovery states that if sufficient correct information cannot be provided, the account may not be recoverable. The moderators in similar cases explicitly note that if the recovery form and manual validation do not succeed, the account cannot be recovered and support cannot override this.
      • That means:
        • The more accurate historical information is provided (contacts, subjects, billing fragments, Xbox details), the higher the chance of success.
        • Withholding key data (such as billing fragments that are actually on the account) reduces the likelihood of passing validation.
      • To minimize risk while still cooperating:
        • Provide only the partial billing details requested (for example, last four digits and expiry), never full card numbers or CVV.
        • Provide IP addresses only from networks that were used to sign in legitimately.
        • Do not send any passwords or full payment data; Microsoft’s process does not require those.
    5. How to double-check the case and the agent
      • Microsoft does not provide a public directory to look up individual support agents by name, but the existence of a service request ID and continued correspondence from a …@microsoft.com address is consistent with a real case.
      • To confirm the case without relying on links in the email:
        • Go to the official Microsoft Support site directly (by typing the URL from documentation into the browser, not by clicking the email link).
        • Use the “Contact Support” or “Get Help” flow documented for account recovery and provide the service request number there. Support can confirm whether the case and email thread are genuine.

    If the sender domain is truly microsoft.com, the content matches the documented recovery process, and the service request ID is recognized when contacting Microsoft Support through the official site, then the email is consistent with a legitimate Microsoft support communication. In that case, providing the requested historical account information (in the limited form described above) is the documented path to attempt to regain access.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.