Microsoft can send genuine unusual-sign-in alerts, so the subject alone is not proof either way. Open your Microsoft account or work-account portal independently and review recent activity before acting.
01
What you may be seeing
Microsoft documents real alerts for sign-ins from a new device or location. An alert can therefore be legitimate even when it was unexpected.
Phishing messages reuse the same concern and direct the recipient to a lookalike sign-in page. The decision should rest on the sender, actual destination, and independently viewed activity.
02
Signals to inspect—and why they matter
Strong evidence
The actual sign-in destination is outside Microsoft’s domains
A brand name in a subdomain or path does not control the site. For example, microsoft.example is controlled by the owner of example, not Microsoft.
Recent activity in the independently opened account contradicts the email
The account’s own activity view is a more direct source than the message. Review device, browser, application, result, and time—not location alone.
A personal-account alert uses an unexpected sender address
Microsoft currently documents account-security-noreply@accountprotection.microsoft.com for personal-account unusual-sign-in alerts. Work or school organizations may use different notification systems.
Contextual signals
An unfamiliar city or country
IP-based location can be imprecise, especially on mobile networks or VPNs. Compare the full activity details before concluding that the account was accessed.
Contextual signals can justify caution, but they do not authenticate or condemn a message by themselves.
03
Safe verification steps
Do not use the alert’s button or reply to the message.
For a personal account, type account.microsoft.com and open Security, then Recent activity.
For a work or school account, open your known My Account portal and review My Sign-ins, or contact your organization’s IT/security team through a known channel.
If the activity is yours, no phishing conclusion follows from the alert alone. If it is not yours, use the account portal’s security flow.
04
What to do next
Use Outlook’s built-in Report phishing control for a suspicious message; this is Microsoft’s reporting instruction.
If the account shows unauthorized successful activity, secure it through the official portal and follow your organization’s incident process.
If you entered a password on another site, change the affected and reused passwords from known-good devices and official sites.