My Outlook/Hotmail account has been compromised and is sending spam.

Henry Manfrediz 20 Reputation points
2026-05-29T14:33:03.72+00:00

I recovered my account, updated my password and signed off from every device. Hacker is still sending spam. How do I log every open session? i did that and it says 24 hours to take effect.

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

Answer accepted by question author
EmilyS726 266.6K Reputation points Independent Advisor
2026-05-29T15:17:40.6533333+00:00

Hello,

When you used the "sign out everywhere", it can take 24 hours for that to take full effect. There's no way to speed this up unfortunately.

In addition, please go through this full action list to make sure all possibe areas are checked. Please feel free to skip those you already did.

This process can take 24 hours to take effect. So please do not expect immediate results.

Please complete these steps on a computer, not on a smartphone or tablet.

====================

First, go to https://www.outlook.com and sign in.

Click the gear icon in the top right corner to open Settings.

Under Mail, review the following areas:

Rules

If any rules are listed, delete all of them.

Conditional formatting

If anything is set up there, delete it.

Forwarding and IMAP

If you see any entries or settings you did not create, remove them. Turn off POP and IMAP.

Junk

Review Safe sender and blocked list. If you don't recognize any, remove them.

After that, exit Settings and return to outlook.com.

Open the To Do section by clicking the blue checkmark icon on the left side. Delete anything there that was not created by you.

====================

Go to https://account.live.com.

Under Your info > Sign-in preferences, review all aliases on the account. If you see any alias you do not recognize, remove it.

Next, go to the Devices section of your Microsoft account and remove any devices you do not recognize.

====================

Please also do the following in Security section

Change your password

Enable two-step verification

====================

Go here https://account.microsoft.com/privacy/app-access Click on "Don't allow" for anything you don't recognize.

=======================

Then go to Security > Manage how I sign in and make sure all contact information belongs to you.

On that same page, scroll down to App passwords and remove any existing app passwords.

Also on the same page, click on Sign out everywhere. This is intended to disconnect any active sessions that may still be connected. Please note that this can take up to 24 hours to fully take effect.

====================

In addition, this problem can sometimes be caused by a malicious script or infection on one of your devices.

Are you using a Windows computer to check email? Do you use an email app such as Outlook Classic or New Outlook?

If so, please open the app and remove the account from the app settings.

Then go to the Microsoft Safety Scanner download page:

https://learn.microsoft.com/defender-endpoint/safety-scanner-download

Download the 64-bit version, run a full scan, and let me know what the final results say.

=====================

If after 24 hours it still doesn't work, please do this:

Go to your Microsoft account online https://account.live.com> Sign in > Your info > Sign in preference. Add an alias - You have two options here:

Create new: this will allow you to use the native domain outlook.com to create a new alias.

Add existing: this will allow you to add a 3rd party email address, such as yahoo, gmail, as long as they are not already associated with another Microsoft account.

Once added, make this new alias your primary alias, do NOT delete the old alias. Then at the bottom, click on "Change sign in preference". On the next page, uncheck the box for the old alias. This means, from now one, the old alias cannot be used to sign into your Microsoft account, but it can be still used to receive emails, etc.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-29T14:33:16.7333333+00:00

    To stop spam being sent from a recovered Outlook.com/Hotmail account, all security steps must be completed, not just signing out of sessions.

    1. Verify the account is really secure
    • Run a full malware/antivirus scan on every device that has accessed the account recently (PC, phone, tablet) before changing any more passwords. This prevents a keylogger or malware from immediately stealing the new password again.
    • Make sure operating systems and apps are fully updated.
    1. Change password again after scans
    • After devices are clean, sign in and change the Microsoft account password once more using the guidance in How to recover a hacked or compromised Microsoft account. Use a strong, unique password.
    1. Review recent sign-in activity
    • Go to the Recent activity page for the Microsoft account to see where and how the account has been accessed in the last 30 days. If any activity is not recognized, mark it accordingly and follow the prompts to secure the account.
    1. Check and fix Outlook.com mailbox settings Attackers often keep sending spam by changing mailbox rules/settings rather than staying signed in.
    • Check connected accounts, forwarding, and automatic replies settings and remove anything not set up personally.
    • In Outlook.com, also review any inbox rules, forwarding rules, or send-as/alias settings and delete anything suspicious.
    1. Add and update security info
    • Add or update alternate email addresses and mobile phone numbers as security info so account recovery is easier in the future.
    1. Monitor and notify contacts
    • Continue monitoring Recent activity and mailbox behavior.
    • Inform contacts that the account was compromised and that they should ignore suspicious messages previously sent from it.

    Regarding “logging every open session” and the 24‑hour delay: sign-out from all devices and security changes can take some time to fully propagate. During that period, ensuring devices are clean, the password is changed after scans, and all forwarding/connected-account rules are removed is critical to actually stopping outgoing spam.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.