A suspicious Outlook message can look like a shared document, a purchase invoice or a subscription renewal. It may come from an address resembling a known sender or even a compromised contact. The safer question is whether the requested action is real, checked through a separate route. Treat an unexpected request for a sign-in code as urgent, even if the sender display name looks familiar.
Use the native report and verify separately
- Leave links and attachments unopened. If the message claims an account problem, open the service through your saved app or known URL. If it appears to be a colleague's request, contact that person through an existing number or chat.
- Select the suspicious message in Outlook or Outlook.com and choose Report → Report phishing from the ribbon or menu. The exact placement varies by Outlook version and organization settings.
- If this is a work mailbox, also use the security-reporting route your organization provides. Preserve the message when the security team asks for it; do not simply forward it to a distribution list.
- If you provided a password, code or payment information, begin the relevant account or bank response immediately. Reported mail is not a retroactive fix for access already granted.