Decision-first exercise
Microsoft unusual sign-in email: inspect the real destination
Decide how to handle a synthetic sign-in alert by separating a real alert pattern from a lookalike sender and domain.
Synthetic scenario · Content reviewed
Synthetic email
What you receive
Decision 1 of 1
The reasoning appears after you lock this decision. Your choices remain only in this page and are not sent anywhere.
Text version for assistive technology and automated testing (includes the answers)
Exercise: Microsoft unusual sign-in email: inspect the real destination Scenario: Synthetic email Channel: Email Sender: Microsoft account team <security@microsoft-alerts.example> Subject: Unusual sign-in activity Message: We detected a sign-in from Portland, Oregon using Edge on Windows. Message: If this was not you, review activity now. No reply is needed. Displayed destination: Review recent activity Actual destination: https://account.microsoft.com.security-review.example/activity Question: Microsoft sends real security alerts. What should you do with this one? Decision 1: Microsoft sends real security alerts. What should you do with this one? Option: Open the email button because unusual-sign-in alerts can be real Option: Delete it because every Microsoft sign-in alert is fake Option: Avoid the button and open Microsoft account security independently Preferred option: Avoid the button and open Microsoft account security independently Rationale: Both addresses end in example-controlled domains. The safe response is to open the known Microsoft account or work-account portal yourself and compare the full activity details. Answer: The alert pattern can be real; this sender and destination are not evidence of Microsoft ownership. Both addresses end in example-controlled domains. The safe response is to open the known Microsoft account or work-account portal yourself and compare the full activity details. Signals: - Strong evidence: Sender domain is microsoft-alerts.example. The display name says Microsoft, but the address belongs to the owner of example. Microsoft currently documents a different sender for personal-account unusual-sign-in alerts. - Strong evidence: Destination ends in security-review.example. account.microsoft.com appears only as left-side labels. The controlling registrable domain is security-review.example. - Contextual signal: A named city, browser, and operating system. Those details can occur in genuine alerts and can also be fabricated. Location alone can be imprecise. Safe actions: - Open account.microsoft.com from a bookmark or typed address for a personal account. - For a work or school account, use your known My Account portal or contact IT. - Report the email with the mail client’s phishing control. This synthetic exercise is not affiliated with or endorsed by Microsoft. Reviewed: 2026-07-28
This synthetic exercise is not affiliated with or endorsed by Microsoft.
Evidence
Authoritative references
- Microsoft SupportWhat happens if there’s an unusual sign-in to your account
- Microsoft SupportView your work or school account sign-in activity from My Sign-ins
- Microsoft SupportProtect yourself from phishing
Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.