Decision-first exercise

Microsoft unusual sign-in email: inspect the real destination

Decide how to handle a synthetic sign-in alert by separating a real alert pattern from a lookalike sender and domain.

Synthetic scenario · Content reviewed
Synthetic email

What you receive

Synthetic example
Channel
Email
Sender
Microsoft account team <security@microsoft-alerts.example>
Subject
Unusual sign-in activity

We detected a sign-in from Portland, Oregon using Edge on Windows.

If this was not you, review activity now. No reply is needed.

Review recent activity
Actual destination shown by the training view
https://account.microsoft.com.security-review.example/activity
Microsoft sends real security alerts. What should you do with this one?

Choose before revealing the explanation.

The answer and signal-by-signal reasoning appear after you decide.

Text version for assistive technology and automated testing (includes the answer)
Exercise: Microsoft unusual sign-in email: inspect the real destination
Scenario: Synthetic email
Channel: Email
Sender: Microsoft account team <security@microsoft-alerts.example>
Subject: Unusual sign-in activity
Message: We detected a sign-in from Portland, Oregon using Edge on Windows.
Message: If this was not you, review activity now. No reply is needed.
Displayed destination: Review recent activity
Actual destination: https://account.microsoft.com.security-review.example/activity
Question: Microsoft sends real security alerts. What should you do with this one?
Option: Open the email button because unusual-sign-in alerts can be real
Option: Delete it because every Microsoft sign-in alert is fake
Option: Avoid the button and open Microsoft account security independently
Answer: The alert pattern can be real; this sender and destination are not evidence of Microsoft ownership.
Both addresses end in example-controlled domains. The safe response is to open the known Microsoft account or work-account portal yourself and compare the full activity details.
Signals:
- Strong evidence: Sender domain is microsoft-alerts.example. The display name says Microsoft, but the address belongs to the owner of example. Microsoft currently documents a different sender for personal-account unusual-sign-in alerts.
- Strong evidence: Destination ends in security-review.example. account.microsoft.com appears only as left-side labels. The controlling registrable domain is security-review.example.
- Contextual signal: A named city, browser, and operating system. Those details can occur in genuine alerts and can also be fabricated. Location alone can be imprecise.
Safe actions:
- Open account.microsoft.com from a bookmark or typed address for a personal account.
- For a work or school account, use your known My Account portal or contact IT.
- Report the email with the mail client’s phishing control.
This synthetic exercise is not affiliated with or endorsed by Microsoft.
Reviewed: 2026-07-28

This synthetic exercise is not affiliated with or endorsed by Microsoft.

Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.