How to Block Suspicious Emails in Outlook
If your Outlook inbox is filling up with phishing attempts, spam, and unwanted senders, learning how to block suspicious emails in Outlook can quickly reduce risk.
This guide covers the most effective Outlook features, plus a few email-security practices that help keep malicious messages out of view.
Outlook gives you several ways to stop suspicious mail, but the right method depends on whether you want to block a single sender, a domain, or future messages that match a pattern.
Why suspicious emails are a security problem
Suspicious emails are more than a nuisance.
They may contain credential-stealing links, malware attachments, invoice fraud, gift-card scams, or impersonation attempts targeting Microsoft 365 users and personal Outlook accounts.
- Phishing: Messages that try to steal passwords, one-time codes, or financial details.
- Spam: Bulk unwanted mail, often from low-quality marketing lists or shady senders.
- Spoofing: Emails that appear to come from a trusted brand but are forged.
- Malware delivery: Attachments or links designed to install harmful software.
Blocking suspicious senders helps, but it works best when combined with Outlook junk controls, message reporting, and account-level security settings.
How to block a sender in Outlook
If one address is sending repeated unwanted messages, blocking that sender is the fastest option.
Outlook can move future messages from that address into Junk Email automatically.
In Outlook on the web
- Open the suspicious email.
- Select the three-dot menu near the message.
- Choose Block or Block sender.
- Confirm the action if prompted.
In Outlook for Windows
- Right-click the suspicious message.
- Select Junk.
- Choose Block Sender.
In Outlook for Mac
- Open or select the message.
- Use the message toolbar or right-click menu.
- Choose Block Sender or move the message to Junk.
Blocked sender lists are useful for repeat offenders, but they are not enough when scammers keep changing addresses.
In that case, block the domain or create more advanced rules.
How to block suspicious emails in Outlook using the Junk Email settings
Outlook’s Junk Email settings provide stronger control over message filtering.
These settings can help when a sender uses multiple addresses or when you receive recurring spam from similar sources.
Add addresses to the Blocked Senders list
The Blocked Senders list tells Outlook to treat future mail from specific addresses as junk.
This works well for individual spam senders that keep reappearing.
- Open Outlook settings or Junk Email options.
- Find Blocked senders and domains.
- Add the email address or domain you want to block.
Block an entire domain
Blocking a domain can stop messages from every address under that domain, such as @example.com.
This is useful when spam comes from many variations of the same source.
Use caution with domain blocking if a company uses multiple legitimate departments from the same domain.
Blocking a domain can also stop legitimate mail, including receipts, support replies, or security notices.
Mark messages as Junk
When a suspicious email slips through, mark it as Junk so Outlook learns from your action.
This does not block a sender permanently by itself, but it improves filtering over time.
- Select the message.
- Choose Junk or Report phishing if available.
- Move the message out of your inbox.
How to create rules to automatically move or delete suspicious emails
If you receive repeated messages with the same subject line, keywords, or sender pattern, Outlook rules can automate the cleanup.
Rules are especially useful for newsletters that ignore unsubscribe requests or for scam messages that use a predictable subject pattern.
Common rule examples
- Move messages containing specific phrases, such as “urgent payment” or “account locked,” to Junk.
- Delete emails from a particular address after delivery.
- Route messages with suspicious attachments to a separate folder.
- Flag emails from outside your organization in Microsoft 365 environments.
Rules are helpful, but they should be used carefully.
Overly broad rules can hide legitimate email, so test them before relying on them fully.
How to report phishing in Outlook
Blocking helps with future messages, but reporting helps Microsoft improve filtering for everyone.
If an email looks like phishing, report it instead of only deleting it.
Using the Report Message or Report Phishing add-in
Many Outlook versions support Microsoft’s reporting tools.
These tools let you send suspicious mail to Microsoft for analysis while removing it from your inbox.
- Open the suspicious email.
- Select Report Message or Report Phishing.
- Choose the appropriate category.
If your organization uses Microsoft Defender for Office 365, reporting suspicious messages may also trigger security investigations and domain-level protection updates.
Best practices for identifying suspicious emails before blocking them
Before you block or delete a message, check for signs of fraud.
This makes it easier to distinguish true threats from harmless marketing emails.
- Sender display name does not match the actual address.
- Misspellings, urgent pressure, or threats of account closure.
- Unexpected attachments, especially .zip, .iso, .html, or macro-enabled files.
- Links that do not match the visible text.
- Requests for passwords, verification codes, gift cards, or wire transfers.
Hover over links before clicking, and verify any urgent request through a separate trusted channel.
If the message claims to be from Microsoft, PayPal, UPS, DocuSign, or your bank, log in directly through the official website instead of using the email links.
How to reduce suspicious emails at the account level
Blocking email in Outlook is effective, but account-level protection adds another layer.
This is especially important for Microsoft 365 and Outlook.com users.
- Turn on two-factor authentication: Protects your account if a password is exposed.
- Review connected apps: Remove unfamiliar third-party app access.
- Check forwarding rules: Attackers sometimes create auto-forwarding to monitor mail.
- Update passwords regularly: Use unique, strong passwords managed by a password manager.
- Enable junk email protection: Keep Outlook’s filtering features active.
These steps do not replace blocking, but they reduce the chance that a suspicious email can lead to account compromise.
What to do if a suspicious email keeps coming back
Some spam campaigns rotate sender addresses, making simple blocking less effective.
When that happens, combine several controls.
- Block the current sender and domain.
- Report the message as phishing or junk.
- Create a rule for recurring subject lines or keywords.
- Check whether your email address has been exposed in a data breach.
- Review whether your address is public on websites, forums, or social profiles.
If you use a work account, your Microsoft 365 administrator may also be able to tighten anti-phishing policies, safe link scanning, and spam filtering at the tenant level.
Outlook versions and settings you may need to know
The exact menus for blocking suspicious email vary by Outlook version.
The core idea is the same, but the labels may differ slightly between Outlook on the web, classic Outlook for Windows, new Outlook, Outlook for Mac, and Outlook mobile.
- Outlook on the web: Usually offers quick block and report options in the message menu.
- Classic Outlook for Windows: Often uses the Junk menu and message rules.
- New Outlook: Typically mirrors the web interface and relies on cloud-based filtering.
- Outlook for Mac: Provides block, junk, and rules controls, though placement may differ.
Regardless of the version, the most reliable approach is to block known senders, report phishing, and use rules for repeat patterns.
When blocking is not enough
Blocking suspicious emails in Outlook can lower your exposure, but it cannot stop every malicious campaign.
Sophisticated phishing attacks may use compromised legitimate accounts, lookalike domains, or highly personalized messages.
If you receive a message that appears to target your organization, finance team, or executive staff, escalate it to IT or security immediately.
For personal accounts, change your password if you clicked anything suspicious, and monitor for unauthorized logins.
In practice, the safest workflow is simple: block the sender, report the message, tighten filtering, and verify anything urgent through trusted channels.