Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Getting spam in an Outlook.com inbox does not, by itself, mean your account has been hacked. Your address may have been exposed or added to a mailing list, a sender may be spoofing the From line, or a campaign may be rotating addresses. If other people say they received spam from you, check account activity, Sent Items, forwarding and rules before deciding what happened.
The first clue is where the messages appear: in Junk, in your Inbox, or in other people’s mailboxes as if you sent them. Those situations point to different causes and different fixes.
Are you receiving spam, or is your account sending it?
| What you see | What it may mean | First check |
|---|---|---|
| Unwanted messages are in Junk Email | Outlook has classified them as junk. This is not evidence that someone accessed your account. | Report convincing phishing attempts; check account security if there are other warning signs. |
| Unwanted messages keep reaching the Inbox | The sender may be changing addresses, the visible sender may be deceptive, or a rule or safe-sender setting may affect delivery. | Inspect the actual sender address, then review rules and safe senders. |
| Someone says they received spam from your address | The message could be spoofed, or your account could have been used to send it. | Check Sent Items and Microsoft account Recent activity, then review forwarding, rules and recovery details. |
The From line alone cannot distinguish a spoofed message from one sent after an account sign-in. Microsoft describes sender authentication and phishing indicators, but notes that a message failing authentication is not automatically malicious. Microsoft’s guidance on phishing and suspicious messages explains the indicators Outlook may show.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhy Outlook.com spam happens
Your address has spread beyond the people you gave it to
Email addresses can circulate through breaches, online forms, mailing-list sales, public pages and contact harvesting. Microsoft also describes “namespace mining”: checking which addresses exist to build lists for spam, phishing or malware. That can happen without a normal message ever reaching you. Microsoft’s sender-support guidance explains the practice.
#1 Best Overall
- COMPATIBILITY: For traditional analog landline phones and services from providers such as AT&T, Verizon, Frontier Communications, CenturyLink, and Brightspeed. Not compatible with internet-based or digital phone services (VoIP), including Vonage, Ooma, Xfinity Voice, and Quantum Fiber.
- IMPORTANT: The V5000 CPR Call Blocker requires Caller ID service and an analog telephone line. Without Caller ID, incoming numbers cannot be identified or blocked. No mains power required - just plug it into your phone line and use.
- Powerful Blocking, Made Simple: Preloaded with 5,000 verified scam and nuisance numbers, the V5000 starts protecting you right out of the box. And if a new or spoofed number gets through, the large “BLOCK NOW” button makes it easy to instantly block it - up to 1,500 additional numbers at your command.
- Realistic & Reliable Protection: While no device can stop 100% of spam (scammers constantly change numbers), the V5000 gives you the power to shut down repeat offenders quickly and effectively - offering more control than passive filters alone.
- Hassle-Free Design: NO POWER supply needed, NO APP, and NO SUBSCRIPTIONS. The V5000 is easy to install, with a clear screen and loud button click for extra confidence. Designed with seniors in mind, it’s ready to use and simple to maintain. For even stronger protection, you can pair it with your phone provider’s spam filtering service.
The sender is spoofing an address
Spoofing means falsifying sender information so a message looks as though it came from a familiar person or address, including your own. Think of the From line as a return address written on an envelope: it is a clue, not proof of who sent the message. A familiar display name can also conceal an unrelated actual address.
Outlook uses authentication signals and may flag an unverified sender. Those signals help assess a message but are not a perfect verdict: authentication failures warrant caution, yet can occur on legitimate messages too. Microsoft’s anti-spoofing overview describes how authentication and spoof intelligence are used.
A spam campaign keeps changing addresses
Blocking one address may not stop a campaign that rotates through new addresses or domains, or uses a deceptive display name. Microsoft specifically identifies changing or hidden sender addresses as reasons messages may continue despite a block. Compare the real addresses and domains across several messages rather than blocking only the displayed name. Microsoft’s troubleshooting guidance for mail from blocked senders recommends checking message details and headers.
You are receiving subscriptions or unwanted list mail
Some unwanted mail is ordinary marketing mail, whether you signed up or were added to a list. Outlook.com can identify some subscriptions from message headers and offers a manager at Settings > Mail > Subscriptions. Not every message appears there, including some messages already filtered as junk or blocked. Microsoft’s subscription-manager instructions describe the feature.
The account or mailbox settings may have been changed
An attacker with account access might send messages, alter recovery information, create inbox rules or add a forwarding destination. These signs merit a security response; spam volume on its own does not. A suspicious forwarding address or rule is especially important because it can affect mail without making the Inbox look obviously different.
How to check whether your account was compromised
Use these checks before treating a message that appears to come from you as proof of a hack. Go directly to Microsoft’s account pages rather than following links in an unexpected security email.
Rank #2
- [ IMPORTANT NOTE 1 ] This product is a call blocker only and does not have a telephone or answering machine function. No phone or answering machine is included in the package. Before purchasing, please make sure that your telephone line has Caller ID service and that it is an ANALOG line. the ENF860 requires Caller ID service from your telephone line provider to work and is for analog lines only ! No mains power required, just plug in the phone line to use
- [ IMPORTANT NOTE 2 ] In BLOCK mode, there will STILL BE some new variant numbers bypassing the database making the phone ring, you NEED to manually set up to block them OR switch to FAMILY mode to let only the numbers in FAMILY LIST through. Please refer to the manual for the CORRECT SETTINGS.
- Dual mode;In BLOCK mode you can block callers by Numbers and Names; In FAMILY mode all callers outside the FAMILY LIST are blocked;The two modes can be switched at any time as needed and NO data will be lost after switching modes.
- Preloaded with a large number of spam numbers that have been the subject of repeated complaints ; Users can also manually add 4000+ numbers to the NUMBER LIST to build their own database ; Add 256 NAMES to block calls by name.
- Blocks INTERNATIONAL, PRIVATE/WITHHELD, and Out of Area numbers by default; users can SET to block the entire area code or changing numbers starting with a fixed number, such as 00, 800, 855, 999, 7324, 33626, 134567, etc.
- Inspect Sent Items. Look for messages you did not write, including recent mail and messages to unfamiliar recipients.
- Review Recent activity. Visit Microsoft account Recent activity and look for unfamiliar successful sign-ins or account changes. Failed attempts alone do not establish that anyone entered the account; password attacks can produce failures without a successful login.
- Check rules and forwarding. In Outlook.com settings, inspect inbox rules and any forwarding destination you do not recognize. Remove unauthorized changes.
- Verify recovery details and connected access. Check that the recovery email and phone number are yours, and remove unfamiliar apps, devices or sessions where Microsoft offers that control.
- Secure the account if you find evidence of access. From a trusted device, change the Microsoft account password to a unique one and enable two-step verification. Microsoft’s Outlook.com account-protection guidance covers recent activity and security measures.
- Consider the device as well as the password. If malware or a stolen browser session is plausible, scan the device and secure it. Warn contacts not to trust suspicious recent messages claiming to be from you.
Receiving spam, seeing your own address in the From field, or getting failed sign-in alerts does not by itself prove compromise. Conversely, a clean Sent Items folder cannot rule it out completely: evidence might have been deleted, or mail may have been sent through another route.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Stop and report unwanted messages in Outlook.com
Report the message using the right category
In Outlook.com on the web, use the message’s Report controls. Choose Junk for unwanted bulk or commercial mail and Phishing when it tries to steal credentials, payment details or personal information. Reporting phishing does not itself block the sender, so block separately if you want matching future mail routed to Junk. Microsoft documents the reporting controls and distinction.
In Outlook mobile, select the message, tap the three-dot menu, choose Report Junk, then select Junk, Phishing or Block Sender, as appropriate. Microsoft’s mobile reporting instructions provide the steps.
Block a sender or domain selectively
For Outlook.com on the web, go to Settings > Mail > Junk email, add an address under Blocked senders or a domain under Blocked domains, then select Save. Blocking routes matching mail to Junk; it does not stop a campaign from changing its address. Block a domain only when the whole domain is clearly abusive. Do not block broad providers such as Gmail, Outlook.com or Microsoft.com because one sender abused an address there. Microsoft’s blocking instructions list the current web path.
Review safe senders and rules
Check Settings > Mail > Junk email > Safe senders and domains for entries you do not recognize; a safe-sender entry can affect classification. Also review rules that move, categorize, forward or otherwise handle messages. Microsoft explains safe senders and domains.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →If you create a rule, base it on a narrow, stable pattern, such as a distinctive subject phrase together with a known abusive domain. Avoid generic terms such as “invoice,” “delivery” or “account,” which can catch legitimate mail.
Rank #3
- How it Works: SPAM identified calls are instantly blocked automatically. Preferred Calls Ring through like normal with Caller ID displayed. Your phones connected to the TEL port Won't Ring on Blocked Calls. Create your own Invited or Allowed Family (White List) and block All other callers. Use the Dual Block Buttons to Block a NAME or NUMBER Displayed. Remote Block a Call when Dialing * 2 # through your telephone handset.
- The Patented ProSeries 3 Call Blocker from Digitone is an Easy Installation and is Simple to Use. No need to rush over and tap a red button when the ProSeries has already blocked a known unwanted SPAM, Out of Area, Private, Anonymous, 800 Service, ROBO?, Dashes, "Quotes" or V123+ call. Use Call History to select Any Caller to Block by (Double Tap) Name or Number. Block any NAME like: Unavailable, Unknown, SCAM RISK, City + State, Potential Scam, Wireless Caller. Block ANY call without answering, as they call in with either RED button.
- Feel confident that the ProSeries already Blocks Millions of Known Unwanted Numbers and Fake Names. No need to change your existing phones or service. Works with Any Analog Corded, Cordless Phone or Fax System on any telephone service. Large Back-Lighted Display. Got questions? Call the number on the front screen of the ProSeries 3.
- Works with all USA phone companies: AT&T, Cox, Spectrum, CenturyLink, Cable Modems, DSL, FIOS, or Digital Services from VoIP Telcos like [V] from Verizon, Ooma Telo, Ooma Basic, Vonage, Magic Jack etc. Also, works in Mexico, Canada, Brazil, European Union (ETSI), Australia, Singapore and others with North American standardized phone lines.
- Allow any blocked caller to ring through like normal with the Green Invite Button. Double Tap the Green Button to add VIP callers shown in Call History. Note: Caller ID Name and Number Service from your phone company is required for this model to work automatically.
Use unsubscribe only for mail you recognize
For a newsletter from a company you recognize and remember signing up with, Outlook’s subscription controls or that company’s expected unsubscribe link may be appropriate. Confirm that any link belongs to the expected organization. Do not click unsubscribe in obvious phishing, unfamiliar or panic-inducing mail: it may confirm the address is active or lead to a phishing or malware site. Microsoft’s identity-protection guide warns about interacting with suspicious unsubscribe links. For suspicious messages, report phishing and delete them instead.
When blocked messages still reach the Inbox
- Check the actual sender address. Open the message details rather than relying on the display name. If needed, inspect its headers.
- Compare several messages. Look for changing domains or random characters, repeated subject phrases, the same impersonated brand, phone number or link, and identical display names paired with different addresses.
- Review rules and safe senders. Remove any entry or rule you do not recognize that could affect delivery.
- Choose a narrow action. Report the messages, block a clearly abusive address or domain, or create a rule only when the matching clues are specific enough to avoid catching normal mail.
Do not create a rule that deletes every message containing a common business word. Outlook’s Junk folder is not permanent storage: Microsoft documentation gives different automatic-deletion periods on different Outlook surfaces, so check it periodically rather than relying on it to retain a message. Microsoft’s junk-mail filtering guidance and blocking guidance describe the feature in different product contexts.
What message headers can—and cannot—tell you
Headers provide technical routing and authentication details that the visible From line omits. Depending on the message and Outlook surface, useful fields include:
- From: the address presented as the sender; it is not sufficient proof of origin.
- Reply-To: where a reply will be directed, which may differ from From.
- Return-Path: the address used for delivery handling, not necessarily the person behind the campaign.
- Received: servers recorded as handling the message. These can help trace infrastructure, but do not reliably identify the criminal sender.
- Authentication results: SPF, DKIM and DMARC outcomes can indicate whether sending infrastructure was authorized for a domain. A failure is a warning, not conclusive proof of fraud.
Do not post full headers or screenshots publicly without removing personal details. Redact your address, IP addresses, message IDs, names, phone numbers, order or tracking details, and password-reset tokens or private URLs. Header analysis can help assess a message, but consumer-visible headers cannot always identify who is ultimately responsible.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Edge cases that can look like a hack
Your own address appears as the sender
That can be spoofing. Check Sent Items, Recent activity and mailbox settings before concluding the account was used. If someone else received the message, the recipient’s original headers may be more informative than a screenshot of the From line.
You receive fake Microsoft security notices
Do not use a phone number or sign-in link in an unexpected warning. Report it as phishing, then check your account by opening Microsoft’s account page directly. A Microsoft-looking address or logo alone does not establish that the message is genuine.
Rank #4
- This is the latest version Telephone Call Blocker with hidden or unavailable call numbers can be blocked. And there is no fees to use it; Please keep the manual for future use.
- Block up to 4000 individual phone numbers, including incoming and outgoing calls , prefixes and up to 10 digit area codes.
- One-touch to Block: Locate a number and then press Block to add it to the blacklist.Better set the call blocker in series ( one end of it connected to your phone and another end to the PSTN telephone line); Though it can also be set up parallel, but not compatible with some phone systems.
- Permanent storage of the numbers in the blacklist even power is off or telephone line is plugged out.
- Battery free: It is line powered, no need battery. And it works with almost all single line telephones. If you find some numbers are blocked but you never mean to, then press Block and check your blacklist, then delete those numbers which like area codes or prefix numbers.
The address ends in a Microsoft-associated domain
An address ending in a familiar Microsoft-associated domain does not prove Microsoft sent a particular message or that your account sent it. Assess the actual address, message context and authentication details rather than trusting the domain’s appearance.
Free tools Windows power users keep installed
One-click scans. No signup required.
Spam appears only in one app or on one device
“Outlook” can mean Outlook.com webmail, new or classic Outlook for Windows, Outlook mobile, or an app displaying a third-party mailbox. If a message appears only in one client, compare the same mailbox on Outlook.com and check that client’s filters, connected accounts and rules. Menu names and behavior vary by product; the Outlook.com paths above apply to Outlook.com on the web.
Why some spam gets through
Spam and phishing filters weigh multiple signals, and classification is not perfect. A stricter setting may reduce visible junk but can also hide legitimate messages; a more permissive setup can improve delivery of unfamiliar contacts while leaving more spam in the Inbox. Blocking every new sender is not practical if you expect mail from schools, service providers, medical offices or other contacts. Microsoft describes authentication and spoof-detection components in its anti-phishing protection documentation.
Outlook.com includes baseline spam and malware filtering. Microsoft 365 Personal and Family subscribers receive additional Outlook.com security features for Microsoft-hosted addresses ending in @outlook.com, @hotmail.com, @live.com or @msn.com; those features do not apply to third-party accounts merely synchronized into Outlook.com. More protection does not guarantee a spam-free mailbox. Microsoft describes the advanced features and eligibility.
Reduce future exposure without abandoning your account
- Use separate addresses for sensitive accounts, shopping and one-off registrations where practical.
- Consider a new alias to reduce future exposure, but do not expect it to erase mail sent to the old address. Manage the old address carefully and review Microsoft’s current alias and sign-in controls before changing them.
- Do not reuse your Microsoft password on other sites; a breach elsewhere can expose credentials even when the Outlook address itself was not hacked.
- Do not pay a service that promises to remove your address from every spam list. No universal removal is established, and granting mailbox access to an unknown service creates privacy risk.
Switching providers is a larger quality-of-life decision, not an immediate security fix. A new address can also attract spam if it is widely reused, and migration risks missed account-recovery messages.
When to contact Microsoft or use account recovery
Use Microsoft’s account recovery or support route if you confirm an unfamiliar successful sign-in, find changed recovery details or unauthorized forwarding and rules, see unauthorized sending, or cannot regain control of the account. Microsoft’s account-protection page links to Recent activity and security guidance. If you only have unsolicited mail and no other compromise indicators, start with reporting, selective blocking and mailbox-setting checks rather than assuming the account was taken over.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

