Decision-first exercise
Microsoft unusual sign-in email: inspect the real destination
Decide how to handle a synthetic sign-in alert by separating a real alert pattern from a lookalike sender and domain.
Synthetic scenario · Content reviewed
Synthetic email
What you receive
The answer and signal-by-signal reasoning appear after you decide.
Text version for assistive technology and automated testing (includes the answer)
Exercise: Microsoft unusual sign-in email: inspect the real destination Scenario: Synthetic email Channel: Email Sender: Microsoft account team <security@microsoft-alerts.example> Subject: Unusual sign-in activity Message: We detected a sign-in from Portland, Oregon using Edge on Windows. Message: If this was not you, review activity now. No reply is needed. Displayed destination: Review recent activity Actual destination: https://account.microsoft.com.security-review.example/activity Question: Microsoft sends real security alerts. What should you do with this one? Option: Open the email button because unusual-sign-in alerts can be real Option: Delete it because every Microsoft sign-in alert is fake Option: Avoid the button and open Microsoft account security independently Answer: The alert pattern can be real; this sender and destination are not evidence of Microsoft ownership. Both addresses end in example-controlled domains. The safe response is to open the known Microsoft account or work-account portal yourself and compare the full activity details. Signals: - Strong evidence: Sender domain is microsoft-alerts.example. The display name says Microsoft, but the address belongs to the owner of example. Microsoft currently documents a different sender for personal-account unusual-sign-in alerts. - Strong evidence: Destination ends in security-review.example. account.microsoft.com appears only as left-side labels. The controlling registrable domain is security-review.example. - Contextual signal: A named city, browser, and operating system. Those details can occur in genuine alerts and can also be fabricated. Location alone can be imprecise. Safe actions: - Open account.microsoft.com from a bookmark or typed address for a personal account. - For a work or school account, use your known My Account portal or contact IT. - Report the email with the mail client’s phishing control. This synthetic exercise is not affiliated with or endorsed by Microsoft. Reviewed: 2026-07-28
This synthetic exercise is not affiliated with or endorsed by Microsoft.
Evidence
Authoritative references
- Microsoft SupportWhat happens if there’s an unusual sign-in to your account
- Microsoft SupportView your work or school account sign-in activity from My Sign-ins
- Microsoft SupportProtect yourself from phishing
Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.