Managing personal Outlook.com account settings, security, and privacy
The symptoms match a compromised Outlook.com account: missing mail, suspicious behavior on new incoming messages, and possible hidden mailbox changes that remain even after a password reset and MFA.
Recommended cleanup path:
- Use Outlook on the web on a computer. Some malicious mailbox settings are easier to find there than in other clients.
- Recheck all mailbox rules and forwarding.
In Outlook.com, open Settings > Mail and review:
- Rules
- Forwarding
- IMAP Delete anything not created intentionally.
- Check blocked and junk settings. Go to Settings > Mail > Junk email and remove any legitimate addresses or domains from Blocked senders.
- Check for sweep or ignore behavior.
- Review Settings > Mail > Sweep for suspicious cleanup rules.
- In Deleted Items, select an affected conversation and check whether Ignore is enabled. If it is, stop ignoring the conversation so future mail is not deleted.
- Check account aliases and sign-in/contact info. In the Microsoft account settings, review sign-in preferences and security/contact information. Remove any alias or contact method that is not recognized.
- Sign out everywhere. Use the Microsoft account security page to sign out all active sessions. This helps remove any attacker session that survived the password change. One accepted Microsoft Q&A answer notes this can take up to 24 hours.
- Change the password again and keep two-step verification enabled. Use a strong, unique password that is not reused anywhere else.
- Review recent account activity. Check recent sign-in activity for anything not recognized.
- Try to recover missing mail. Check Deleted Items and the recovery option there, because attackers often delete mail after gaining access.
- If the problem still affects every new message after all checks above, use the hacked-account recovery flow. Microsoft provides a sign-in helper that guides recovery steps and can offer contact with an agent.
Why this is still happening after password reset and MFA:
- Attackers often leave behind inbox rules, forwarding settings, blocked senders, sweep rules, or ignore states.
- They can also add aliases or other account changes that continue affecting mail flow until removed.