An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Hi! Let me help you.
Microsoft would never send an email for Microsoft Defender updates.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I received emails about up dating "Update the Microsoft Defender app on your Windows device" is this a real update or a scam?
An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Hi! Let me help you.
Microsoft would never send an email for Microsoft Defender updates.
I received the same email this morning. Suspicious because I didn't see a reason why the PC's update process wouldn't take care of it so I didn't click the button, but looking at the email source suggests every step along the way is legitimate as originating from microsoft.com and the update button points to https://mydefender.microsoft.com. If it's a scam it's a very good one unless Microsoft's network has been penetrated.
I'm thinking it's more likely some kind of error.
I got one too. I reviewed my Windows Defender status from Microsoft's official page https://mydefender.microsoft.com/ and everything was good there.
I'm guessing this was sent in error.
I just got this email several hours ago, I never click on emails that look sketchy, but the email headers says you sent it, or it came through your mail servers.
So, if its a scam email then why is it coming from Microsofts servers?
As you can see below, it was signed by microsoft mail servers.
dkim=pass (1024-bit key; unprotected) header.d=sponaeop.onmicrosoft.com header.i=@sponaeop.onmicrosoft.com header.a=rsa-sha256 header.s=selector1-sponaeop-onmicrosoft-com header.b=jaTijtV1;
dkim=pass (2048-bit key; unprotected) header.d=OUTLOOK.MAIL.MICROSOFT header.i=@OUTLOOK.MAIL.MICROSOFT header.a=rsa-sha256 header.s=selector1 header.b=ZgXj7Efz;
dkim-atps=neutral
Authentication-Results: OpenDMARC; dmarc=pass (p=reject dis=none) header.from=outlook.mail.microsoft
Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=2a01:111:f403:c110::3; helo=bn8pr05cu002.outbound.protection.outlook.com; envelope-from=******@outlook.mail.microsoft; receiver=initcorp.co.uk
Received: from BN8PR05CU002.outbound.protection.outlook.com (mail-eastus2azlp170110003.outbound.protection.outlook.com [IPv6:2a01:111:f403:c110::3])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange ECDHE (secp384r1) server-signature ECDSA (prime256v1) server-digest SHA256)
(No client certificate requested)
by sambuca.psychonet.co.uk (Postfix) with ESMTPS id 216A32DC0FAA
for <--REMOVED-->; Fri, 18 Sep 2026 23:32:16 +0000 (UTC)
and
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=sponaeop.onmicrosoft.com; s=selector1-sponaeop-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=+41i0V9Ns2HWjGSlPIvpwyqdccm94h2CPMkVxgAkA34=;
b=jaTijtV1gzJ5eO5aGec6XbM0l0LPB2NtDt5D8567E+zZ/v0ABKJh2A7mTZ6KpNQLuIM6k1iwiOg9B918t9u/nzAN/rFpOliq7hPQg7cp+jXrjJvbuLvr8sAVefvxFd4X6t+opyA9E1i6A9Kz37yGTjMwYiYCLLxxxHpcUsHxYqU=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=OUTLOOK.MAIL.MICROSOFT; s=selector1;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=+41i0V9Ns2HWjGSlPIvpwyqdccm94h2CPMkVxgAkA34=;
b=ZgXj7EfzfYGnqWRUHJsdij5FU1L9mh4VqV6O3IJl1KwwPaXLPrcPsgjd7+HWh8lMWqlL+BT+0uIZYXU8ZFSYe6ZrC/sRJCL1qr8wgxPHappOXoMKCLLTsVYJRCilzg3+8kTF5qm9XX0YvbzAn8xj02S3dQbaWcscxLx2MGdCBO8xebksId3RxCSGxLPHdhsExBWPH3A4LeRJBtG46MMnjRED/e2bJtwfY9/SUbsOJrpjuie4PzQs80AmV/L2es8JJJV5JRXMoBd7Gp7DBhlzsrDTywXrZSnHUBxplw7jQLyAjNix06cQfwRQhrECjm7sl9QwGCGQvYZiBN+w7VJE0A==
Received: from substrate.office.com (2603:10b6:5:336::19) by
DSAPR10MB479029.namprd10.prod.outlook.com with HTTP via
DM6PR06CA0086.NAMPRD06.PROD.OUTLOOK.COM; Fri, 18 Sep 2026 23:32:13 +0000
Date: Fri, 18 Sep 2026 23:32:12 +0000
Subject: Action Required: Re-attest Your Network Access
So you or one of your employees sent it.
https://www.whois.com/whois/onmicrosoft.com
So can you confirm if this is a legit or scam email and if its a scam email then you have a breach on your servers.
AI answer
It is likely a scam if the email is asking to click a link to update Microsoft Defender.
Microsoft Defender protection updates are normally delivered through Microsoft Update, Automatic Updates, Windows Update, or WSUS, not through unsolicited email links. Microsoft also does not send unsolicited email or phone calls to fix a computer or request personal or financial information.
Key signs of a scam:
What to do instead:
A real Microsoft warning message does not include a phone number, and Microsoft does not cold email or call to tell someone there is a problem with a device.