Managing personal Outlook.com account settings, security, and privacy
Use this cleanup sequence:
- Treat the account as compromised. If an unrecognized forwarding rule points to an unknown internal or external address, assume the mailbox was compromised.
- Remove visible forwarding settings in Outlook.com:
- Go to Settings → Mail → Forwarding.
- Remove any unknown forwarding address and turn forwarding off.
- Check mailbox rules:
- Go to Settings → Mail → Rules.
- Delete suspicious rules, especially ones that forward, delete, move messages, mark mail as read, or use obscure names such as
.or empty names.
- Reset the account password after scanning the PC for malware:
- Run a full antivirus scan first.
- Then change or reset the password.
- Review account settings changed by the attacker:
- Check connected accounts, forwarding, and automatic replies.
- If the rule is hidden and not visible in Outlook.com, hidden or corrupted inbox rules can exist outside the normal UI. Microsoft documents removing corrupted hidden inbox rules by using MFCMAPI.
- Investigate for broader compromise:
- Look for other suspicious inbox rules such as “delete all” or “move messages to another folder”.
- Check for increased sent mail activity.
- If this is a Microsoft account/Outlook.com account, use the account recovery flow and security checks to complete recovery.
If the malicious forwarding rule is confirmed, the documented remediation is to disable/remove the rule and reset credentials.