I received an email about updating your Terms of Service, Security Policy, and Privacy Policy.

Helen Allen 20 Reputation points
2026-09-04T13:16:10.96+00:00

There is a button to click on telling me to update now.

Complete email below.

Hello, User. Last week, we announced significant changes to our Terms of Service, Security Policy, and Privacy Policy. We are eliminating all previous versions of our email. As a result, you must upgrade to the most recent version and use our secure email service. As part of these improvements, previous versions of your mailbox will be phased out on September 3rd, 2026. Please see the link provided below for information on how to remedy this issue.

UPDATE NOW

Failure to fix this issue will result in the immediate termination of your email account. This is an automated message from a third-party email coordinating service. Regards, Email Coordination OutIook.com Service© 2026

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

Answer accepted by question author
Victor1-V 13,020 Reputation points Microsoft External Staff Moderator
2026-09-05T07:01:32.89+00:00

Hi Helen Allen,

This message is a phishing attempt. Please do not select UPDATE NOW, reply to the sender, or provide any account information. Microsoft does not require an “email version” upgrade through an email link to prevent an Outlook.com mailbox from being terminated.

You can also check the actual sender in the message header:

  1. Open the message without selecting any links.
  2. Select More actions (...) > View > View message details.
  3. Find the From and Return-Path fields and check whether the addresses match the displayed sender.
  4. Review Authentication-Results. Results such as spf=fail, dkim=fail, or dmarc=fail, or an unrelated sending domain, are additional warning signs. However, a “pass” result alone does not prove that the message is trustworthy. View internet message headers in Outlook.

In Outlook.com, select the message and choose Report > Report phishing, then delete it. Reporting the message does not automatically block the sender, so the sender can also be added to the blocked senders list. See how to report phishing in Outlook.

If you selected the link or entered information, go directly to the Microsoft account Security page, change the password, review Recent activity and security information, enable two-step verification, and run a full security scan. Help protect your Outlook.com email account | Microsoft Support 

If you did not open the link or provide information, reporting and deleting the message should be sufficient.

Please note that this is a user-to-user forum, so contributors cannot inspect the original message or verify its headers directly. I hope the above steps help you report the message and keep your account secure.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.