Share via

mail content automatically modified server side after delivery

Juergen Schulz 0 Reputation points
2026-02-26T18:16:15.0033333+00:00

whenever someone send me email its subject is comromised and same subject always.

done all the security procedures but nothing helps.

outlook hacked !!!

Outlook | Outlook for mobile | Outlook for Android | For home
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-02-26T18:16:34.3833333+00:00

    The behavior described is consistent with a compromised mailbox where a malicious rule or integration is modifying messages after delivery. To stop it, the account and mailbox must be fully secured, not just the device.

    Follow these steps in order:

    1. Secure devices first
    • On every device used with Outlook (PC, Mac, Android, iOS), run a full, up-to-date antivirus/antimalware scan.
    • Make sure the operating system and apps are fully updated, as recommended in the Outlook.com protection guidance.
    1. Sign out all sessions and reset credentials
    • Go to the Microsoft account security page and use the option to sign out of all sessions ("Sign out everywhere" or equivalent) so any attacker sessions are killed.
    • Change the account password to a strong, unique one that is not used anywhere else.
    • Enable multi-factor authentication (MFA) on the Microsoft account. Experience from similar cases shows that once MFA is enforced, malicious rules and activity usually stop.
    1. Check for malicious rules and forwarding Using Outlook on the web (not just the mobile app):
    • Go to Settings → Mail → Rules and delete any rule that:
      • Renames subjects
      • Moves messages to unexpected folders (Junk, RSS, Notes, etc.)
      • Forwards or redirects mail to unknown addresses.
    • Go to Settings → Mail → Forwarding and remove any forwarding address that is not explicitly configured.

    If using a Microsoft 365/Exchange account and an admin is available:

    • In Exchange Online PowerShell, run Get-InboxRule -Mailbox user@domain (or the more detailed example from the compromised-account guidance) to list all rules, including hidden ones, and remove any suspicious rules.
    1. Check for other compromise indicators Based on the compromised-account guidance, review for:
    • Suspicious items in Sent Items or Deleted Items (e.g., scam or extortion emails).
    • Unexpected changes to signatures.
    • Recently added external forwarding in tenant outbound spam policies (for Microsoft 365 admins).
    1. Review sign-in and account activity
    • For Outlook.com/Microsoft accounts, review recent activity at https://account.live.com/activity to see where and when the account has been accessed and confirm there are no unknown sign-ins.
    • For Microsoft 365 work/school accounts, an admin should review Microsoft Entra sign-in logs and Defender audit logs as described in the compromised-account article.
    1. Continue monitoring
    • After cleanup, monitor the mailbox for a period to confirm that:
      • No new suspicious rules appear.
      • Subjects are no longer being changed.
      • No new suspicious sign-ins are logged.

    If the problem persists after all of the above, contact Microsoft Support with details that the mailbox appears compromised and that rules or server-side processing are altering message subjects after delivery.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.