Sending, receiving, and organizing email in Outlook.com
Take these steps to fully clean up the account and stop the malicious rule/bot behavior:
- Scan the PC/phone for malware before changing anything else
- Make sure antivirus is up to date and run a full scan.
- On Windows 10/11 or 8.1, use Windows Defender:
- Select Start.
- Search for Windows Defender and open it.
- Turn on protection and run a full scan.
- Ensure automatic updates and regular scans are enabled.
- Change the Microsoft account password again
- After the malware scan completes, sign in and change the password using the official flow: change your password.
- Use a strong, unique password that is not reused anywhere else.
- If sign-in fails at any point, use the official reset your password process.
- Enable stronger sign-in protection (MFA)
- Set up Microsoft Authenticator or another second factor so attackers cannot reuse credentials even if they have them.
- In a similar case from the community, persistent malicious rules stopped after multi-factor authentication was enabled.
- Sign out everywhere and revoke access
- In the Microsoft account security settings, use Sign out everywhere to invalidate all active sessions.
- Remove any unknown or untrusted apps from Manage app permissions so they can’t keep re-adding rules.
- Clean up Outlook.com mailbox configuration
Perform these checks in Outlook on the web (Outlook.com):
- Rules
- Go to Settings → Mail → Rules.
- Delete all rules that look suspicious or that reference bots, forwarding, or moving all mail away from Inbox.
- If a rule keeps reappearing, it usually indicates an active session or app still has access—hence the importance of steps 3–4.
- Forwarding
- Go to Mail → Forwarding.
- Remove any forwarding addresses that are not recognized.
- Automatic replies
- Go to Mail → Automatic replies.
- Turn off any auto-replies that were not configured intentionally.
- Connected accounts
- Review connected accounts and remove any that are not recognized.
- Rules
- Check account activity and security info
- Visit the recent activity page at https://account.live.com/activity to see where and when the account has been accessed.
- If unfamiliar locations/devices appear, mark them as “This wasn’t me” where available.
- Add or verify alternate email and phone as security info so recovery is easier if this happens again.
- Visit the recent activity page at https://account.live.com/activity to see where and when the account has been accessed.
- Verify sign-in page and avoid phishing
- When signing in, ensure the address bar shows login.live.com. If it does not, close the page and navigate manually to Outlook.com.
- If suspicious emails or links led to this issue, review guidance on recognizing phishing and junk email.
- If the account is blocked or issues persist
- If Outlook.com temporarily blocks the account due to unusual activity, use the Sign-in Helper to unblock.
- If unblocking fails or the malicious rule continues to reappear even after all steps above, follow the guidance in When you can't sign in to your Microsoft account (linked from the unblock article) to escalate and contact support.
After completing these steps, monitor the mailbox for a while to confirm that:
- No new suspicious rules appear.
- New mail arrives normally without being replaced by bot content.
- Recent activity shows only expected sign-ins.
References:
- How to recover a hacked or compromised Microsoft account
- Help protect your Outlook.com email account
- Unblock my Outlook.com account
- I have seen great advice for deleting the idtienphuoc1 Rule but none for stopping it from re-adding itself - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Stopped receiving emails on my account. - Microsoft Q&A