Share via

Emails overwritten by scam email/[Draft] scam email keeps coming back

Andrew L 25 Reputation points
2026-02-21T20:18:09.1666667+00:00

My emails keep getting overwritten by a scam email whenever they get to my inbox. I also keep getting a [Draft] email with the scam email in my inbox even after deleting it. There's no rules, no connected apps, forwarding is turned off, I've tried all the methods to fix it that are online and nothing is working. It happens on the email app and web browsers, in Incognito mode and regular mode.

When I try to reach out to support it just keeps telling me to sign-in and when I sign-in it tells me I need to sign-in. I can't seem to get connected to any support services. It's very frustrating.

Outlook | Windows | Classic Outlook for Windows | For home
{count} votes

5 answers

Sort by: Most helpful
  1. John Jefferson Doyon 62,215 Reputation points Independent Advisor
    2026-02-21T20:50:45.9733333+00:00

    Hi, I'm John! I will help you with this.

    If you haven't tried anything yet please start by running a full antivirus scan on your computer using Windows Security and any third-party antivirus software you have.


    To be safe, I recommend the following steps:

    Check your account rules and forwarding settings, hackers create rules that automatically forward or delete emails. You can do this in Outlook settings under Mail > Rules and Forwarding. https://support.microsoft.com/office/manage-email-messages-by-using-rules-in-outlook-c24f5dea-9465-4df4-ad17-a50704d66c59

    Just to be safe, I’d recommend to sign out everywhere. Visit: https://account.live.com/proofs/manage/additional Scroll down to Sign me out and select "Sign me out".

    And changing your password again and enabling two-step verification if you haven’t already. This will add an extra layer of security to prevent future unauthorized access.

    If you notice anything unusual in your account settings or purchase history, you might also want to check the Microsoft account security page https://account.microsoft.com/security to review recent activity.

    "How to help keep your Microsoft account secure" https://support.microsoft.com/account-billing/how-to-help-keep-your-microsoft-account-secure-628538c2-7006-33bb-5ef4-c917657362b9


    I really hope this information is helpful! Let me know if you have any further questions or concerns.

    Regards,

    John J.D.

    1 person found this answer helpful.

  2. Luke 10 Reputation points
    2026-02-27T06:41:41.3966667+00:00

    I've just fixed this for a customer I had. Ended up being a hidden rule as many have suspected.

    The fix for me was to add the compromised account to a full featured version of Outlook. I used Outlook (classic).

    NOT the version of Outlook which is pre-installed.

    Then run the following command in Run (WIN +R)

    outlook /cleanrules

    EDIT: First step should be to remove consent for Thunderbird and Microsoft Graph at the following link: https://microsoft.com/consent

    Also, remove any email forwarding which shouldn't be there, reset passwords, add 2FA, remove any email forwarding which shouldn't be there.


  3. Hornblower409 5,895 Reputation points
    2026-02-23T01:05:09.7866667+00:00

    2026-02-28 - Removed by author. Out of date.

    0 comments No comments

  4. L. Timmons 0 Reputation points
    2026-02-22T23:08:35.2+00:00

    I am having this same issue and keep getting sent on an endless loop back to Microsoft support that cannot help me. And ehen i go to the direct link for outlook support I get looped back to my hacked and hijacked email inbox. PLEASE HELP ME.


  5. Q&A Assist
    2026-02-21T20:19:20.1133333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    It seems that your email account may be compromised, especially since you're experiencing issues with scam emails and drafts reappearing. Here are some steps you can take to resolve this:

    1. Inspect Inbox Rules: Even if you believe there are no rules in place, revisit the settings in Outlook. Navigate to Settings → Mail → Rules and check for any hidden or suspicious rules that might be causing the issue.
    2. Check Forwarding Settings: Ensure that there are no unknown forwarding addresses set up. Attackers may create forwarding rules to send copies of your emails to another account.
    3. Sign Out Everywhere: Access your Microsoft Account Security settings and use the option to sign out of all sessions. This will help terminate any active sessions that could be compromised.
    4. Manage App Permissions: Review the applications that have access to your account. Revoke permissions for any apps that you do not recognize or trust.
    5. Utilize PowerShell Commands: If you have admin access to Microsoft 365, you can run PowerShell commands to identify and remove hidden inbox rules. For example, using Get-InboxRule -Mailbox youraddress@example.com can help uncover any rules not visible in the standard settings.
    6. Reset Your Password: After completing the above steps, reset your password again and ensure that multi-factor authentication (MFA) is enabled for additional security.
    7. Monitor Activity: Keep an eye on your sign-in logs for any suspicious activity. This can help you determine if someone else is accessing your account.

    If these steps do not resolve the issue, consider reaching out to Microsoft Support for further assistance.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.