hotmail forwarded to mystery account

DP 20 Reputation points
2026-06-18T15:29:22.74+00:00

When people send me an email message to

my hotmail

 postmaster sends a message

SN1PEPF0002BA4B.mail.protection.outlook.com

rejected your message to the following email addresses:

carter x200 at hotmail

 

 

The email was not sent to this address

 

I do not want this address to receive my email

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-18T15:29:39.98+00:00

    The behavior described strongly suggests that the Hotmail/Outlook.com mailbox has been compromised and/or has a hidden rule or forwarding configured so that messages to the account are being redirected or processed in a way that involves the “mystery” address.

    To stop another address from receiving mail and to regain control, take these steps in order:

    1. Secure the Microsoft account first
      Follow the compromised-account guidance (password reset, malware scan, and security review) as described in the Microsoft account recovery and hacked-account articles referenced in the Q&A threads:
      • Reset the Microsoft account password to a strong, unique one.
      • Ensure multi-factor authentication (Authenticator app, phone, or email) is enabled and that only trusted devices/methods are listed.
      • From Microsoft Account Security, use the option to sign out of all sessions to disconnect any attacker sessions.
    2. Check Outlook.com rules and forwarding
      Sign in to Outlook.com / Outlook on the web and review:
      • Settings → Mail → Rules: Delete any rule that forwards, redirects, or copies messages to the unknown address, or that moves messages in unexpected ways. The Q&A example shows that malicious rules can be created and hidden; remove anything suspicious.
      • Settings → Mail → Forwarding: Remove any forwarding address that is not recognized.
    3. Review mailbox for other compromise artifacts
      Based on the similar “continuous draft ransomware email” case:
      • Remove any suspicious add-ins or connectors.
      • If using Microsoft 365 with admin access, review Exchange mail flow rules and inbox rules (for example, via Get-InboxRule) to ensure there are no hidden rules that forward mail to the mystery address.
    4. Re-run security checks and monitor
      • Run antivirus/anti-malware scans on all devices used to access the account.
      • Monitor sign-in logs and mailbox activity for any further suspicious behavior.
      • Inform contacts that the account may have been compromised so they can ignore any unusual messages.

    If, after removing all rules and forwarding and securing the account, messages still appear to involve the unwanted address, use the Outlook.com support options (Help → Still need help?) to contact support and have them review the account’s configuration and delivery path.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.