Is That Email a Scam? Microsoft’s Own List of Signs

An email says your account will close today, or a parcel is waiting, or your payment failed. It looks close enough to real that you are hovering over the link rather than deleting it.

Microsoft publishes the list of tells its own products look for. It is short, it is specific, and one of the items on it is the reason most people get caught.

I have not read a single message of anybody's to write this, so what follows is Microsoft's own wording plus the order I would work through it.

The sign that catches most people

Read this one first, because everything else follows from it.

Microsoft puts it first on its own phishing page. The first tell is an "Urgent call to action or threats", where a message claims you must click, call or open an attachment immediately.

Urgency is the whole trick. It exists to stop you doing the thirty second check that would end it.

⚠️ Real companies do not close accounts in an hour by email. A genuine problem waits until you type the address in yourself.

So the rule is simple: the more urgent it feels, the slower you go. That single habit defeats most of these.

The one about the address, with Microsoft's own example

The tell that is hardest to see and easiest to check.

Microsoft states the trap exactly: mismatched domains and "very subtle misspellings of the legitimate domain name. Like micros0ft.com where the second 'o' has been replaced by a 0."

Read the part immediately before the first single slash. That is the real domain, and everything after it can say anything at all.

⚠️ Microsoft's instruction for links is to look without touching: "hover your mouse over, but don't click the link" to see where it really goes.

On a phone, press and hold instead of tapping. The address appears and nothing opens.

The rest of the list, in Microsoft's words

Four more, and none of them needs any technical knowledge.

"First time, infrequent senders, or senders marked [External]" deserve a second look, in Microsoft's own wording.

"Spelling and bad grammar", because a real company's mail goes through people whose job it is to catch that.

⚠️ A generic greeting. Microsoft names "Dear sir or madam" as the giveaway that the sender does not know who you are.

And Outlook's own banner, which appears when, in Microsoft's words, "we could not verify the sender".

The attachment rule

Short, and it is absolute.

Microsoft's instruction is plain: "Don't open any links or attachments" in a message you are suspicious of.

An unexpected attachment is the highest risk thing in any inbox. More than a link, because a link at least shows you where it goes.

⚠️ An invoice you were not expecting is the classic. So is a delivery note, a scanned document and a shared file notification.

If you think it might be real, contact the sender another way. Not by replying, and not by any number in the message.

And if the worry is what is already on the machine rather than in the inbox, that is a different check. Scanning properly takes one pass.

What to do if you already clicked

The section people actually need, and speed matters.

Change the password for that account first, from a different device if you can, and change it anywhere you reused it. Clearing that site's cookies afterwards signs out anybody who got in.

Turn on two step verification on that account. Microsoft lists enabling multifactor authentication among its own steps after a click.

⚠️ Then tell your bank if money or card details were involved, and tell your IT department if it is a work machine.

And report it. Microsoft's route is Report, then Report phishing, inside Outlook.

The check that beats all of this

One habit, rather than a list to memorize.

Never act inside the message. Close it, open a browser, and type the company's address yourself.

If the problem is real, it will be waiting for you when you sign in. Every time.

⚠️ If there is nothing there, you have your answer and you have lost thirty seconds.

That habit makes every tell on this page optional. You do not have to spot a good fake if you never follow a link from a message.

The ones that are getting harder

Said honestly, because the old advice is aging fast.

Spelling mistakes are becoming rare. The grammar tell was reliable for twenty years and it is fading fast.

A message that quotes a real order of yours is not proof of anything. Data from breaches is bought and used.

⚠️ And a reply inside a real email thread is the hardest of all, because it arrives with genuine history above it.

Which is exactly why the habit beats the checklist. The tells will keep getting better. Typing the address yourself will not stop working.

Status: written from Microsoft's own phishing guidance on 28 August 2026. ⛔ No message, mailbox or account of anybody's was read, and no example here is taken from real mail.

How do I tell if an email is phishing?

Microsoft lists the signs: an urgent call to action or threats, a first time or infrequent sender, spelling and bad grammar, a generic greeting like Dear sir or madam, and a mismatched or subtly misspelled domain. Its example is micros0ft.com with a zero in place of the second o.

Should I click a link to check where it goes?

No. Microsoft's own instruction is to hover your mouse over the link without clicking, which shows the real address. On a phone, press and hold instead of tapping. Better still, close the message and type the company's address into your browser yourself.

What should I do if I clicked a phishing link?

Change that account's password immediately, from another device if you can, and anywhere you reused it. Turn on two step verification. Tell your bank if card details were involved and your IT department if it is a work machine. Then report the message.

Are spelling mistakes still a reliable sign?

Less every year. The grammar tell worked for two decades and it is fading, and messages now often quote real details taken from data breaches. That is why the habit of never acting inside a message beats any checklist of tells.

The Short Version

  • Urgency is the trick. The more urgent it feels, the slower you go.
  • Microsoft's example of a fake domain is micros0ft.com with a zero.
  • Read the part just before the first single slash. That is the real domain.
  • Hover to see a link, never click it. Press and hold on a phone.
  • Generic greetings like Dear sir or madam are a documented tell.
  • An unexpected attachment is the riskiest thing in any inbox.
  • If you clicked, change that password first and turn on two step verification.
  • The habit that beats every tell: close it and type the address yourself.

Where to Next

Close the message before you do anything else. Every decision is safer made outside it.

Type the company's address into your browser and sign in there. A real problem will be waiting for you.

If you have already clicked, change that password now and anywhere you reused it, then turn on two step verification.

Report the message rather than just deleting it. It costs one click and it helps the filtering for everyone.

And if you have seen one that was genuinely hard to call, describe it in the comments without any personal detail. The convincing ones are worth knowing about.

Leave a Comment