Federated identity management using Active Directory Federation Services
The domain itself (microsoftsupport.com) is one Microsoft genuinely uses for support case follow-up emails. It appears on Microsoft's own published list of support email domains: https://learn.microsoft.com/en-us/troubleshoot/azure/general/email-domains-support-agent. So the address alone doesn't settle it either way, and the earlier answer is right that exact spelling is the first thing to check. Since this involves your card details, here are the checks we'd add for your situation:
- Think back to how you reached "Microsoft's online help." This is the step most people skip. If you started by typing support.microsoft.com or account.microsoft.com into the browser yourself, a follow-up email is expected and very likely genuine. But if you found the help page through a search result, an ad, or a pop-up, it's possible the "support" you contacted wasn't Microsoft at all. Fake support sites are one of the most common scams, and their follow-up emails look convincing precisely because you're expecting one.
- Check the real sender address, not the display name. In Outlook, click the sender's name to expand the actual address (on mobile, tap it). It must end in exactly @microsoftsupport.com. Watch for extra letters, hyphens, swapped characters, or a different ending. Two indicators worth knowing: a "?" where the sender photo should be means Outlook couldn't verify the sender, and a "via" tag means the message really came from a different address than the one shown. Either one is a reason to be suspicious here.
- Judge the message by what it asks for. A genuine support follow-up references your case number. It will never ask you to reply with your card number, password, or verification codes, never ask you to install remote access software, and never ask for payment by gift card. Any one of those means scam, regardless of what the address says.
- Best of all: don't fix the payment issue through the email at all. Type account.microsoft.com into your browser yourself, sign in, and go to Payment options to add the new card (that's also the direct fix for the update problem you originally had). Done that way it no longer matters whether the email was real, you've bypassed it entirely.
If it does turn out to be phishing, use Report > Report phishing in Outlook. And if you already entered card details anywhere via that email, call your bank to block the card, change your Microsoft account password, and turn on two-step verification.
Full disclosure: we build a free email scam checker. If you'd like a quick second opinion on this specific message, you can forward it to ******@OutlookDog.com (a verdict comes back by reply in a few minutes, and forwarding keeps the real sender address and true link destinations, which pasting loses) or paste the text at https://outlookdog.com/scam-check.html. Free, no signup, nothing stored. Treat it as a second opinion, not a final verdict.