Sending, receiving, and organizing email in Outlook.com
This usually means something in the account is still generating or redirecting mail items, even after the password was changed and devices were signed out.
Do these checks again in this order:
- Scan the PC for malware before changing anything else
In Windows Security go to Virus and threat protection > Scan options > Full scan > Scan now.
This matters because Microsoft recommends a full malware scan before changing the password, so a still-infected device does not keep re-creating the problem. - Change the Microsoft account password again
After the malware scan finishes, change or reset the password again and make sure it is a strong password. - Check Outlook.com account settings that attackers commonly change
Review these areas and remove anything unfamiliar:- Connected accounts
- Forwarding
- Automatic replies
- Check for suspicious mail rules again
Attackers commonly create rules that move or redirect messages. In similar Outlook.com cases, accepted fixes were to open Outlook on the web and review Mail > Rules, then delete any rule not created intentionally. - Check sign-in methods and recent activity
- Review the recent activity page and look for sign-ins or security challenges that are not recognized.
- Make sure all recovery methods and security info belong to the account owner.
- Sign out everywhere again
This helps terminate any remaining active sessions. - Turn on two-step verification if not already enabled
This helps prevent the attacker from getting back in after cleanup.
If the drafts still keep appearing after the malware scan, password reset, and removal of suspicious rules/forwarding/settings, use the Microsoft account recovery/sign-in helper flow for a compromised account.
Also watch for these compromise signs while checking the mailbox:
- suspicious Inbox rules
- messages moved to Junk Email, Notes, or RSS Subscriptions
- suspicious items in Sent Items or Deleted Items
- external forwarding that was recently added