How to Tell If Your Outlook or Hotmail Has Been Compromised

    Identify the signs of a hacked Outlook or Hotmail account and learn how to check for unauthorized activity.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 8 min read

    Maybe Microsoft sent you an ‘unusual sign-in’ warning, you’ve spotted messages you didn’t send, or you just have a nagging feeling someone’s been in your account — or perhaps you’ve already recovered it and want to be certain nothing was left behind. Either way, take a breath: you’re doing exactly the right thing. This run-through covers both jobs — it confirms whether your Outlook or Hotmail was actually accessed, and surfaces the quiet footholds an intruder leaves to slip back in later: rogue forwarding and inbox rules, extra aliases, connected apps, app passwords and tampered recovery settings — so you can shut them all down.
    Affiliate disclosure: if you create or upgrade a paid Proton plan through links on this page, CyberSecurityGuides may earn a commission at no extra cost to you. We only recommend tools we use and trust.

    How to check for unauthorised access

    1

    Check your signed-in devices

    First, sign in to your Microsoft account on a device you trust — go to account.microsoft.com and log in. Then open the Devices tab. This lists every device your account is signed in on — so if an attacker logged in from their own computer, it can appear here as one you don’t recognise. Look for any Windows PC or laptop you don’t own, especially one added recently or in an unfamiliar place. Open its details (via Info & support or See details), confirm it isn’t yours, and choose Remove this device to unlink it from your account.

    Telling yours apart

    Your own device is usually marked This device — leave that one. Treat any unfamiliar machine, particularly a Windows PC added today or signed in from a place you’ve never been, as the one to remove.
    Microsoft

    Sign in

    yourname@outlook.com

    Password

    Forgot password?

    Sign in

    account.microsoft.com Devices tab listing signed-in devices, with an unfamiliar Windows PC flagged and removed

    What this list doesn't show

    This tab only covers Microsoft devices — Windows PCs, Xbox consoles and the like that are linked to your account. It does not show every place your account is signed in: someone reading your mail through Outlook on the web in a browser won’t appear here at all. So a normal-looking Devices list isn’t proof you’re alone — your sign-in activity (the next step) is what catches browser sessions, and a full Sign out everywhere ends them.
    2

    Review your sign-in activity

    Now open the Security tab and, under Account Security, choose View my sign-in activity. This lists every recent sign-in with the date, approximate location, device and whether it succeeded. Don’t be alarmed by a long list of unsuccessful sign-ins from all over the world — these are almost always automated brute-force bots working through common passwords against millions of accounts at once, not someone targeting you personally. What actually matters is whether any attempt succeeded: open any successful sign-in that wasn’t you and choose This wasn’t me, and Microsoft will walk you through changing your password and securing the account.

    Reading the activity list

    A sign-in from a city near you can still be legitimate — location is estimated from the IP address and is often imprecise. The clearest red flags are devices you don’t own, sign-ins at times you were asleep or offline, or a successful sign-in somewhere you’ve never been. And if you use a VPN or relay service, your own legitimate sign-ins can show up at unfamiliar or distant locations.

    Bear in mind, too, that this list usually only covers the last 30 days. Anything an attacker did before that won’t appear here — so a clean list is not a guarantee nothing happened. That’s exactly why the rest of these checks still matter.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Devices

    SURFACE-LAPTOP

    Surface Laptop 5

    DESKTOP-K7E5AAP

    Z790 Gaming PC

    Devices checked. Next, head to Security to review your sign-in activity.

    account.microsoft.com Security page, View my sign-in activity, then Recent activity showing an unrecognised successful sign-in from another country

    Securing the basics isn't the whole job

    Choosing This wasn’t me is the right first move — Microsoft helps you change your password and sign the intruder’s sessions out, which is enough to lock them out right now. But that only covers the basics. Someone who’s had access may have left quieter ways back in — forwarding rules, hidden inbox rules, extra aliases, connected apps or added recovery methods — that a password change alone won’t touch. Work through the rest of this guide to find and close them, so the account stays yours.
    3

    Check your security info

    Return to the Security page, open Manage how I sign in and read every entry under Ways to prove who you are. An attacker who got in may have quietly added their own way back.

    These are the email addresses, phone numbers, authenticator apps and passkeys that can reset your password or pass two-step verification — so a single unfamiliar one is a backdoor that lets them straight back in later. Remove anything you don’t recognise, leaving only the methods you set up yourself.

    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Security

    How you sign in, the devices you're signed into, and your account's online security.

    Account Security

    Sign in and recovery settings.

    Manage how I sign in
    View my sign-in activity

    File backup and security

    Ways to prove who you are list with an attacker-added recovery email flagged and removed

    Can't remove it? Add a safe method first

    Microsoft won’t let you delete your last remaining ways to sign in — so if you only have a couple of basic methods set up, it may refuse to remove the attacker’s until you’ve added another. If that happens, add an alternative email address you control first, then come back and remove the rogue one. Don’t have a separate, secure address to use? A Proton Mail account is a great choice — it’s end-to-end encrypted and Swiss-based, giving you a clean recovery address the attacker has never had access to.

    Set up a secure Proton Mail address

    End-to-end encrypted and based in Switzerland — a clean inbox the attacker has never touched, ideal as a safe recovery address you fully control.

    Get Proton Mail
    4

    Remove suspicious app passwords

    Still on the Manage how I sign in page, scroll down to App passwords. An app password lets an email client or app sign in directly to your mailbox — and, crucially, it keeps working even after you change your account password or tighten the account’s security. That makes it the perfect backdoor: an attacker can hook a mail app up to your inbox with one and quietly keep reading everything, no matter what else you lock down. Microsoft only shows a Remove existing app passwords link when at least one exists — so if you see it and never set one up yourself, treat it as a red flag. They aren’t listed individually, so choose Remove existing app passwords to wipe them all, then recreate any you genuinely use.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices

    Additional security

    App passwords

    Some apps and devices (such as Xbox 360, Windows Phone, or mail apps on your other devices) don't support security codes for two-step verification. In these cases, you need to create an app password to sign in. Learn more about app passwords

    Create a new app password

    Remove existing app passwords

    Manage how I sign in page, App passwords section, removing all existing app passwords

    Why remove them all

    Because the Remove existing app passwords link only appears when an app password is present — and you can’t see which ones exist or when they were created — there’s no way to single out a rogue one. If you use a desktop or phone mail program like Apple Mail or Outlook desktop, you may well have set one up yourself, so it isn’t always sinister — but since you can’t tell them apart, it’s safer to remove them all and set up fresh ones. Any legitimate app will simply prompt you to sign in again.
    5

    Replace your account recovery code

    Still on the same page, scroll to the bottom to the Recovery code section and choose Generate a new code. A recovery code is a 25-character code that can get someone back into your whole account, so a fresh one instantly invalidates the old code — any copy an attacker may have saved stops working. Save the new code somewhere safe (Microsoft won’t show it again).
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices

    Additional security

    Passwordless account

    OFF

    Turn on

    Two-step verification

    OFF

    Turn on

    Sign out everywhere

    Sign out everywhere

    Recovery code

    You can use this code to access your account if you lose access to your sign-in info. Print this out and keep it in a safe place or take a picture of it.

    Generate a new code

    Microsoft account Security page scrolled to Additional security, replacing the recovery code so a new one is generated and the old one is invalidated

    Why replace it even if nothing looks wrong

    Generating a recovery code does show up in your recent activity — but remember that log only goes back 30 days. If an attacker generated one before that window you won’t see it, and Microsoft never displays your current code, so there’s no way to tell whether it’s still the one you set. The safe move is to replace it regardless: a fresh code cancels any old one an attacker might be holding, even one you can’t see.
    6

    Check your account aliases

    This one is unique to Microsoft accounts and easy to miss. An alias (or account username) is an extra email address that signs in to — and sends from — the same account, so an attacker can add one as a hidden spare key, then keep using your mailbox even after you’ve changed your password.

    Switch to the Your info tab, find the Account info section and choose Edit account info. That opens Manage how you sign in to your account, which lists every username on the account under Account username. Remove any you didn’t create; leave only your own.

    About the primary alias

    You can’t remove the primary alias. If an unfamiliar address has been set as primary, switch your real one back to primary first, then remove the rogue one.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Your info

    Account info

    Edit account info
    Email addressyourname@outlook.com
    Phone numberNone
    Sign-in preferencesLink your phone to your PCClose account

    account.live.com names Manage page showing account aliases, with an unrecognised alias being removed

    7

    Review your connected apps

    Still in your account settings, open the Privacy tab and choose App access. This lists every third-party app that can reach your account’s data. Click Details on anything you don’t recognise to see exactly what it can do — if it can read your email or contacts, or keep access when you’re not using it, and you didn’t set it up, choose Stop sharing. A connected app keeps its own access even after you change your password, so this is a common way attackers stay in.

    Check the permissions, not the name

    Don’t judge by the name alone — a harmless-looking app can hold full mailbox access. Open it and read exactly what it can do before you decide.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Privacy

    Manage your privacy settings and review the data apps can access for your Microsoft account.

    Empower your productivity

    Location

    Directions and info from my location data

    No data

    Browsing and search

    Suggestions from my browsing history

    No data

    Apps and services

    Improve products using my activity data

    Activities: 7

    App access

    Choose which apps and services can access my info

    Apps: 1

    People suggestions

    Expand suggestions from my contacts

    account.microsoft.com consent page, opening a suspicious app with full mailbox access and removing its permissions

    8

    Check your forwarding

    Now open your inbox at outlook.live.com, click the Settings gear (top-right) and choose Mail → Forwarding and IMAP. A favourite trick is to switch on forwarding to an address the attacker controls, so a copy of every email you receive quietly lands in their inbox — even after you change your password. If forwarding is on to an address you don’t recognise, clear that address, turn Enable forwarding off, and click Save to apply the change.

    Use a computer

    These settings aren’t in the mobile app. Open Outlook in your phone’s browser and request the desktop site if you’re away from a computer.
    Outlook
    Search
    Y
    New mail DeleteArchiveReportMove toReply allRead / Unread

    Favourites

    Inbox16
    Drafts
    Archive

    yourname@outlook.com

    Inbox16
    Junk Email
    Drafts
    Sent Items
    Deleted
    Archive
    FocusedOther

    Microsoft account team

    11:44

    Your single-use code

    Hi yourname@outlook.com, we received your request…

    May

    Coles at Flybuys

    12/05

    It's time to redeem your credits

    Everyday Rewards

    12/05

    Remember, Everyday Travel

    Expedia.com.au

    12/05

    Save 15%+ on winter escapes

    David Jones

    12/05

    25% Off Winter Fashion

    Harris Scarfe

    12/05

    Winter Sale is On Now!

    Your single-use code

    MT

    Microsoft account team

    account-security-noreply@accountprotection.microsoft.com

    Hi yourname@outlook.com,

    We received your request for a single-use code to use with your Microsoft account.

    Your single-use code is: 234615

    Outlook Settings, Mail, Forwarding pane showing forwarding switched on to an unknown address, then turned off and saved

    9

    Check your inbox rules

    Still in Settings → Mail, open Rules. Rules run automatically on incoming mail, and a hidden one can delete or move your security alerts so the warnings never reach you — or forward sensitive messages elsewhere. Delete any rule you didn’t create, especially anything that targets messages about codes, passwords or security.

    Spotting a hidden rule

    Rogue rules are often given a blank or single-character name (like “.”) to make them easy to overlook, so read the conditions, not just the name. And watch for any rule that forwards or redirects your mail to another address — that’s a second, separate way to siphon your email, independent of the Forwarding setting you turned off in the last step. A clean forwarding screen doesn’t rule it out, so a rule like this needs deleting too.
    Outlook
    Search
    Y

    Settings

    Search
    Account
    General
    Email
    Calendar
    People
    Layout
    Compose
    Smart suggestions
    Attachments
    Rules
    Conditional formatting
    Sweep
    Junk email
    Customise actions
    Message handling
    Forwarding and IMAP
    Subscriptions

    Forwarding and IMAP

    Forwarding

    You can forward your email to another account.

    Forwarding is off. Next, open Rules from the list on the left.

    Outlook Settings, Mail, Rules pane revealing a hidden rule that deletes security messages, then deleting it

    10

    Sign out everywhere and reset Windows Hello

    Finally, head back to your Microsoft account at account.microsoft.com and force every session out. Open Security, choose Manage how I sign in, and scroll down to Sign out everywhere. Selecting it signs you out of every browser, app and device your account is used on — so anyone still logged in, the attacker included, is kicked out within 24 hours; you’ll simply sign back in on your own devices. Just below it, also choose Reset Windows Hello on all of my Windows devices — that clears any face, fingerprint or PIN sign-in an attacker might have set up on a device of their own to reach your account, while still letting you unlock your own devices.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Welcome, Your name

    yourname@outlook.com

    Security

    Update your password and sign-in options

    Devices

    See where you're signed in

    Back at account.microsoft.com, the Security page Sign out everywhere section, confirming to sign out of all browsers, apps and devices within 24 hours

    A clean finish

    If you haven’t already changed your account password, do that too — otherwise a signed-out attacker could simply log straight back in with the old one. The full password-and-two-step lockdown is covered in the secure your account guide linked below. Signing out everywhere can take up to 24 hours to take full effect and can’t sign you out of Xbox, but it’s the cleanest way to end any session you didn’t catch in the earlier checks.

    Frequently asked questions

    Can someone read my emails without me knowing?
    Yes. A hidden forwarding rule, an inbox rule, a connected app or an app password can all let someone read your mail silently — and some of them keep working even after you change your password. That is why checking your forwarding, rules, connected apps, aliases and app passwords matters even when nothing looks obviously wrong.
    I got a Microsoft security alert, but it was me. Should I worry?
    No. Alerts for your own new phone, browser or location are completely normal. Only act if the device, place or time is something you genuinely don't recognise.
    Does changing my password sign everyone else out?
    Not always on its own. On the Security page, use Sign out everywhere to end every other session within 24 hours, then turn on two-step verification so a stolen password alone isn't enough next time.
    What if I'm locked out of my account completely?
    Start the account recovery process as soon as you can — the longer you wait, the more an attacker can change. Our step-by-step Outlook / Hotmail recovery guide walks you through getting back in, even if your password and security info have already been changed.

    What to do next

    If you found something

    You've signed the intruder out and cleared the footholds they left behind — now make sure they can't get back in. Lock the account down with two-step verification and tighten your security info.
    Secure your Outlook / Hotmail account

    If everything looks clean

    That's a relief — and it's the perfect moment to get ahead of the next attempt. A free, big-tech inbox like Outlook will always be a high-value target. With an end-to-end encrypted inbox like Proton Mail, your messages are encrypted so that only you can ever read them — not even Proton can see inside. It's the single biggest upgrade you can make to your email security.
    Why switch to Proton Mail

    Worried about another account?

    The warning signs are universal — here's the full checklist that works for any email account.
    Signs any email is hacked

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Email Security