Resource icon

Outlook shows a suspicious-link warning: verify the request safely

Outlook.com can warn when a link in an email appears related to phishing or malware. The warning is a pause to check the underlying request. A copied brand, known contact name or familiar email thread does not make the destination safe.

Before you start​

Keep the email open for reference but do not enter credentials into the warned page. Identify what the message wants you to do: sign in, download, pay or confirm account details.

Do it step by step​

  1. Stop at the warning rather than choosing to continue. Note the visible destination domain and the alleged sender without entering data.
  2. Open the organization's website or app from a saved bookmark or manually typed known address. Look for the same notice within your account.
  3. For a work request, contact the person through an existing channel, such as a known phone number or a new message to their recorded address.
  4. If the request cannot be verified, use Outlook's phishing report control or your organization's reporting process. Preserve the message if a security team needs it.
  5. If you already followed the link and entered a password, change it on the real site, check sessions and recovery settings, and alert your security team or provider.

Check the result​

A genuine task should be visible or confirmable through the independent route. You do not need the warned email link to complete a legitimate account check.

If something goes wrong​

Protection differs between Outlook.com plans and managed Microsoft 365 accounts. The absence of a warning does not authenticate a link; continue checking context and domain.

Know the limit​

Microsoft describes extra link screening for eligible Microsoft 365 subscribers and advises against clicking through a suspicious-link warning. Microsoft's Outlook.com security guidance
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack