A message in the Windows notification corner can look like a system or antivirus alert while actually coming from a website you once allowed to send notifications. Closing the browser may not stop these alerts. Treat a demand to call a number, renew a subscription or install a tool as untrusted until you identify the sender. The fix is usually a site permission, not a popup blocker.
Before you start
Do not click the warning, call its number or install its proposed cleaner. Note the displayed website and screenshot it if you need evidence. If the alert appears inside a browser tab instead of the desktop notification area, it may be a page element or popup and needs a different check.Do it step by step
- Open Edge yourself using the trusted desktop or Start menu shortcut. From Settings, go to Privacy, search, and services, Site permissions, then All sites. Do not navigate through the alert's button.
- Find the website shown in the notification. Examine its full domain carefully; a name resembling Microsoft or a security vendor is not proof of ownership. Open that site's permissions and set Notifications to Block.
- If you still have the genuine page open, the site-information icon beside the address bar can also reveal Permissions for this site and its Notifications choice. Use it only after confirming the address; the settings list is safer when the warning itself is suspicious.
- Review other unfamiliar sites allowed to notify you. Remove allowances you cannot explain, but keep sites whose alerts you intentionally use. Avoid an indiscriminate reset if it would erase permissions needed for accessibility or work.
- Wait for another scheduled alert or close and reopen Edge to check that the sender no longer appears. If a notification remains in Windows Notification Center, dismiss the old item; an existing item is not proof that new ones are still arriving.
- If you clicked the alert and downloaded a file, do not open it. Delete the unneeded download and run the trusted security scan already on your device; change credentials only if you entered them into a suspicious page.