@microsoftonline.com emails

Milan Djurasevich 0 Reputation points
2026-08-07T02:46:25.9+00:00

Hi,

I have ready that emails from @microsoftonline.com are likely to be phishing attacks.

Is this correct?

I received one today from msonlineservicesteam at microsoftonline.com and received three late last week.

Will it create a problem for me if I list messages from @microsoftonline.com on the email server's "kill" list (don't know the real term but where you block all emails from a given entity).

Outlook | Web | Outlook.com | Email
0 comments No comments

2 answers

Sort by: Most helpful
  1. Victor1-V 11,520 Reputation points Microsoft External Staff Moderator
    2026-08-07T10:47:47.8866667+00:00

    Hi Milan Djurasevich,

    I understand why several unexpected messages using the same domain would raise concern.

    Please note that this is a user-to-user forum, so contributors cannot inspect or verify the messages directly.

    The general safety guidance in the Q&A Assist answer is appropriate. Have you had a chance to try it? However, the domain shown in the From address alone does not prove that every message is phishing, because senders can disguise that address. Outlook may also flag an unverified sender without confirming that the message is malicious. Phishing and suspicious behavior in Outlook | Microsoft Support

    I would like to add that you can check the message header for the underlying sender details. In Outlook.com, open the message and select More actions > View > View message details. Review the From field and other sender information, but do not post the full header publicly because it may contain personal information. See View internet message headers in Outlook.

    I would also avoid blocking the entire domain unless you are certain that no legitimate messages are needed from it. Blocking a domain moves messages from every address under that domain to the Junk Email folder. Blocking the specific sender is the safer option initially.

    I hope this helps you verify the messages before deciding what to block. 


    If the answer is helpful, please click "Yes" to upvote it. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.    

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-08-07T02:46:39.9+00:00

    Yes. The provided guidance identifies @microsoftonline.com messages as phishing/scam in similar Outlook.com cases, and Microsoft guidance says mismatched or suspicious sender domains are a common phishing sign.

    Blocking that domain on the blocked senders/domains list is a reasonable step if those messages are unwanted. In Outlook on the web, go to Settings > Mail > Junk email and add the domain under Blocked senders and domains. Messages from blocked senders are sent to Junk email.

    Also use these checks before trusting similar messages:

    1. Verify the sender domain carefully. Slight misspellings or unexpected domains are a phishing red flag.
    2. If Outlook shows an unverified sender banner, treat the message cautiously.
    3. Do not open unexpected links or attachments.
    4. Report suspicious messages with Outlook’s Report button or Report > Phishing when available.

    If a message claims there is an account problem, sign in directly to Outlook.com or the relevant Microsoft account page instead of using links in the email.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.