How to Monitor Outlook for Suspicious Activity
Microsoft Outlook is a common target for phishing, account takeover, and unauthorized mailbox access because it often contains sensitive business and personal data.
Knowing how to monitor Outlook for suspicious activity helps you catch early warning signs before a small anomaly becomes a major security incident.
This guide explains the exact signals to watch, where to check them in Outlook and Microsoft 365, and how to respond if you spot something unusual.
What counts as suspicious Outlook activity?
Suspicious activity includes any mailbox behavior that does not match a user’s normal habits or your organization’s security policies.
In Microsoft 365 environments, this often points to credential theft, session hijacking, malicious inbox rules, or unauthorized sign-ins from a new device or location.
- Login attempts from unfamiliar countries, IP ranges, or devices
- Unexpected password reset messages or MFA prompts
- Emails marked as read, deleted, or moved without user action
- Forwarding rules that send messages to external addresses
- Changes to Outlook profile settings, signatures, or delegated access
- Spam, phishing, or malware messages sent from the account
Watch the right sign-in signals first
The fastest way to monitor Outlook for suspicious activity is to check sign-in behavior in the Microsoft account or Microsoft 365 security portal.
For consumer accounts, the Microsoft account activity page shows recent sign-ins, location data, device details, and whether a login was successful or blocked.
For work or school accounts, Microsoft Entra ID sign-in logs provide much deeper context, including Conditional Access results, authentication methods, risk indicators, and client apps used.
Repeated failed logins followed by a successful one are a strong indicator of password guessing or credential stuffing.
What to look for in sign-in logs
- Unexpected geographic locations or impossible travel patterns
- Legacy authentication attempts using IMAP, POP, or SMTP AUTH
- Sign-ins from unfamiliar browsers, devices, or operating systems
- Multiple failed password attempts in a short time
- Successful logins after a suspicious MFA prompt
Review mailbox rules and forwarding settings
Attackers often create hidden inbox rules to reduce visibility after compromise.
A mailbox rule may automatically delete security alerts, move bank emails to a folder, or forward messages to an external address controlled by the attacker.
These changes can be subtle, which makes them a high-value place to inspect regularly.
In Outlook on the web, check Rules, Forwarding, and Automatic Replies.
In Microsoft 365, administrators can review mailbox rules through Exchange admin tools and PowerShell.
Any rule that forwards to an unknown domain, deletes messages containing “security,” or moves mail out of the inbox deserves immediate attention.
Mailbox rule red flags
- Rules the user does not recognize
- Auto-forwarding to non-corporate addresses
- Rules that delete or archive mail before the user sees it
- Unexpected out-of-office messages
- Signatures changed to include suspicious links or phone numbers
Check for unusual message behavior
Message-level anomalies can reveal compromise even when sign-in logs look normal.
If an account is being used by an attacker, sent items may contain messages the user never wrote, and deleted items may show cleanup activity.
You may also notice replies to old conversations that contain payment instructions or links to fake login pages.
Pay attention to messages sent to many recipients, especially if the sending style is inconsistent with the account owner.
In Microsoft Defender for Office 365, message trace and threat investigation tools can help identify whether the account sent spam, phishing, or malicious attachments.
Examples of suspicious email activity
- New outbound email threads with vague subject lines like “Invoice” or “Urgent”
- Replies sent outside normal business hours
- Messages in Sent Items that the user does not remember composing
- Contacts receiving strange requests for gift cards, wires, or password resets
- Phishing emails arriving from the user’s own mailbox
Monitor delegated access and shared mailbox changes
Attackers sometimes grant delegate access or abuse shared mailboxes to expand access without immediately triggering suspicion.
If Outlook is connected to a shared mailbox, verify who has full access, send-as rights, and send-on-behalf permissions.
Any new delegate that was not approved should be treated as a security incident.
In enterprise environments, review audit logs for permission changes and mailbox access events.
Changes to calendar sharing, mailbox ownership, or Exchange permissions can indicate that an attacker is trying to maintain persistence after initial compromise.
Use Microsoft security tools to automate detection
Manual checks are important, but automation makes suspicious activity easier to detect at scale.
Microsoft Defender, Microsoft Entra ID Protection, and Exchange Online auditing can generate alerts for risky sign-ins, impossible travel, mass mailbox rule creation, and suspicious email forwarding.
If your organization uses Microsoft 365, configure alerts for account compromise indicators and send them to your security team or SIEM platform.
Integration with Microsoft Sentinel or another SIEM helps correlate Outlook activity with endpoint telemetry, phishing reports, and identity risk signals.
Useful Microsoft tools for monitoring Outlook
- Microsoft Entra sign-in logs
- Microsoft Entra ID Protection risk detections
- Exchange Online mailbox auditing
- Microsoft Defender for Office 365
- Microsoft Purview audit logs
- Microsoft Sentinel for correlation and alerting
Set up practical monitoring controls
Good monitoring depends on consistent controls, not just one-time checks.
Use multi-factor authentication, block legacy authentication, require Conditional Access for risky sign-ins, and limit external auto-forwarding.
These settings reduce the chances that suspicious Outlook activity will go unnoticed or succeed in the first place.
For individuals, enabling security alerts, reviewing recent activity weekly, and using a strong unique password can significantly improve protection.
For businesses, mailbox auditing, phishing-resistant MFA, and conditional access policies should be standard practice.
- Turn on MFA for every Outlook or Microsoft 365 account
- Disable POP, IMAP, and SMTP AUTH unless explicitly required
- Restrict automatic forwarding to trusted domains
- Review mailbox rules and delegates on a recurring schedule
- Require alerts for risky sign-ins and suspicious inbox changes
What should you do after detecting suspicious activity?
If you find suspicious Outlook activity, act quickly to limit damage.
Start by changing the password, revoking active sessions, and reviewing recent sign-ins.
Then remove unknown mailbox rules, check forwarding settings, and inspect sent items for unauthorized messages.
If the account belongs to an organization, notify IT or security immediately so they can investigate token theft, lateral movement, and any emails sent to internal or external recipients.
In some cases, the safest response is to reset credentials, reissue MFA, and conduct a full mailbox and device review.
Immediate response checklist
- Reset the account password
- Sign out of all active sessions
- Remove suspicious inbox rules and forwarding
- Review sent mail, deleted items, and calendar changes
- Scan the device for malware
- Report phishing messages and preserve evidence
How often should you monitor Outlook?
The right frequency depends on risk level, account importance, and organizational policy.
High-value accounts such as finance, executives, IT admins, and customer support inboxes should be reviewed daily or continuously through automated alerts.
For personal accounts, weekly activity checks are usually enough if MFA is enabled and the account is used normally.
If you recently clicked a suspicious link, entered credentials into a fake login page, or received a login alert you do not recognize, check Outlook activity immediately rather than waiting for your regular review cycle.
Build a habit of checking the most important indicators
The most effective way to monitor Outlook for suspicious activity is to focus on identity, mailbox rules, message behavior, and automated alerts.
Those signals reveal the majority of account compromise cases early, especially when combined with MFA and proper logging.
By reviewing sign-ins, forwarding rules, delegates, and sent mail patterns on a regular basis, you can spot abnormal Outlook behavior before attackers use the account for fraud, phishing, or data theft.