How to Spot a Microsoft 365 Phishing Email Before You Click
Learn how to spot Microsoft 365 phishing emails, fake login pages, suspicious links, and MFA scams before they compromise your business account.


How to Spot a Microsoft 365 Phishing Email Before You Click
Tech Tip Friday from MooseDen IT
You open your email and see a message that looks like it came from Microsoft.
Your Microsoft 365 password expires today.
There's a big blue “Keep My Account Active” button.
The Microsoft logo is there. The email looks professional. It even knows your name and company.
So you click it.
That's exactly what the attacker was hoping you'd do.
Phishing attacks don't always look like obvious scams anymore. Today's phishing emails can be convincing enough to fool employees, business owners, and even experienced IT professionals.
The good news? You don't have to be a cybersecurity expert to spot many of them.
Here are a few things to look for before you click.
1. Don't trust the name. Check the actual sender.
One of the easiest tricks attackers use is impersonating someone you recognize.
An email might say:
Microsoft Account Team
But the actual email address could be something completely different.
For example:
From: Microsoft Account Team
Email: security-alert@randomdomain.example
The display name isn't proof that the email is legitimate.
When something seems suspicious, look at the actual sender address.
And don't stop there.
Attackers can use domains that look very similar to legitimate ones.
For example:
microsoft.com — legitimate Microsoft domain
micros0ft.com — notice the zero
microsoft-security.example — looks official at a glance
microsoft-login.example — Microsoft isn't necessarily involved at all
The trick is to slow down and look.
2. Be suspicious of unexpected urgency
Phishing emails love creating panic.
You'll often see messages like:
“Your account will be disabled today.”
“Your password expires in 30 minutes.”
“Payment failed — update your information immediately.”
“Your mailbox is full.”
“Unusual sign-in detected.”
“You must verify your account.”
“Your administrator has requested action.”
The goal is simple:
Get you to act before you think.
If an email makes you feel like you have to click something immediately, stop.
Take a breath.
Open a new browser window and go directly to the service you're being asked about instead of clicking the email link.
3. Hover over the link before clicking it
This is one of the best habits you can teach your employees.
Suppose an email says:
“Click here to verify your Microsoft 365 account.”
Before clicking, hover your mouse over the button or link.
Your computer should show you where the link actually goes.
If the email claims to be from Microsoft but the link points somewhere completely unrelated, that's a huge warning sign.
And remember:
A link looking like Microsoft doesn't make it Microsoft.
A phishing website can be designed to look almost identical to the real Microsoft sign-in page.
Microsoft specifically recommends verifying URLs and being cautious with links in unsolicited or unexpected messages.
4. Watch out for fake Microsoft 365 login pages
This is where phishing can become particularly dangerous.
You click a link and see a familiar Microsoft 365 login screen.
It has:
The Microsoft logo
Your company name
A familiar-looking sign-in page
Your email address
The same colors and fonts you're used to seeing
It looks legitimate.
But it's actually a fake website designed to steal your username and password.
That's why the safest habit is to avoid signing into Microsoft 365 through unexpected email links.
If you need to access Microsoft 365, open your browser and go to your normal Microsoft 365 portal yourself.
Don't let the email choose where you sign in.
5. “But I have MFA, so I'm protected... right?”
MFA is extremely important.
If you don't have MFA protecting your Microsoft 365 accounts, that's something you should fix.
But here's the important part:
MFA isn't a reason to ignore phishing.
Attackers have developed techniques designed specifically to get around traditional MFA protections.
For example, an attacker may steal your password and then attempt to trick you into approving an unexpected sign-in request.
If you suddenly receive an MFA prompt that you didn't initiate:
Don't approve it.
Instead:
Deny the request.
Report the suspicious activity to your IT administrator.
Change your password if appropriate.
Let your IT administrator investigate the account.
Microsoft also recommends stronger, phishing-resistant authentication methods for privileged accounts because administrators are frequent targets.
MFA is still one of the most important security controls you can have.
Just remember:
MFA is another layer of protection — not permission to click anything
If you haven't enabled MFA for your Microsoft 365 accounts yet, check out our guide: Microsoft 365 MFA for Small Business..
6. Be careful with attachments
Phishing doesn't always involve a link.
You may receive an email with an attachment such as:
An invoice
A purchase order
A shipping notice
A voicemail
A fax
A Microsoft Word document
An Excel spreadsheet
A PDF
The message may say something like:
“Please review the attached invoice immediately.”
If you weren't expecting the document, don't open it just because it looks like a normal business document.
When in doubt, verify it another way.
If a vendor supposedly sent you an invoice, call the vendor using a phone number you already have — not a phone number contained in the suspicious email.
7. Don't assume good grammar means it's safe
For years, people were taught that phishing emails were easy to spot because they contained terrible spelling and grammar.
That's no longer a reliable rule.
Modern phishing emails can be professionally written.
Attackers can also use information about your company, employees, vendors, and customers to make messages much more believable.
So don't ask:
“Does this email look professional?”
Ask:
“Was I actually expecting this?”
That's a much better question.
8. Watch for unusual requests from people you know
Phishing isn't always pretending to be Microsoft.
Sometimes the attacker pretends to be your boss, coworker, customer, or vendor.
For example:
“Hey, I'm in a meeting. Can you purchase these gift cards and send me the codes?”
Or:
“Please change the bank account for our next payment.”
Or:
“I need you to send me the employee W-2s.”
These requests should immediately raise a red flag.
If something involves money, passwords, sensitive information, or changing payment details, verify the request using another method.
Call the person.
Talk to them in person.
Send them a new message using a known contact method.
Never rely solely on the suspicious message to verify itself.
9. What if you already clicked?
First:
Don't panic.
Making a mistake doesn't mean the business is automatically compromised.
But you should act quickly.
If you clicked a suspicious link:
If you entered your password
Contact your IT administrator immediately.
Your password may need to be changed, and your account may need to be investigated.
If you approved an MFA request you didn't initiate
Tell your IT administrator immediately.
This should be treated as a potential account compromise.
If you downloaded or opened an attachment
Tell your IT administrator what happened and leave the computer alone until they can determine whether anything malicious occurred.
If you entered financial information
Contact your bank or financial institution immediately.
The faster you report a potential incident, the more options you may have.
Microsoft's guidance similarly recommends contacting your IT administrator and changing affected passwords if you believe you've fallen victim to phishing.
10. Report the phishing email
Don't just delete a phishing email and move on.
If you're using Microsoft Outlook, Microsoft provides a built-in Report button that allows users to report messages as phishing. Microsoft recommends the built-in reporting experience rather than the older Report Message or Report Phishing add-ins.
Reporting suspicious messages helps your organization identify attacks and can help Microsoft improve its filtering systems.
Your company should also have a simple process for employees to report suspicious messages to whoever handles IT.
And that process should be easy.
If employees are afraid they'll get in trouble for reporting a suspicious email, some will simply ignore it.
The 10-Second Phishing Test
Before clicking a link, opening an attachment, or responding to an unexpected request, ask yourself:
1. Was I expecting this?
2. Do I recognize the actual sender?
3. Where does the link really go?
4. Is this message trying to make me panic or hurry?
5. Is it asking for money, passwords, MFA approval, or sensitive information?
If something doesn't feel right, don't click.
Verify it another way.
The Bottom Line
Technology can stop a lot of phishing attacks before they ever reach your inbox.
Microsoft 365 includes built-in email protection, and additional security tools can provide protections such as Safe Links, Safe Attachments, anti-phishing policies, and impersonation protection.
But technology isn't perfect.
The person sitting in front of the computer is still an important part of your security strategy.
The best defense is a combination of:
Strong passwords
Multi-factor authentication
Phishing-resistant authentication where appropriate
Secure Microsoft 365 configuration
Email filtering and protection
Regular updates and patching
Employee security awareness
A simple process for reporting suspicious activity
And most importantly:
When something feels urgent, unusual, or too good to be true — slow down.
A few extra seconds could save your business from a very expensive problem.
Need Help Securing Microsoft 365?
Microsoft 365 is powerful, but the default configuration isn't necessarily the right security configuration for every small business.
MooseDen IT helps small businesses improve their Microsoft 365 security, including MFA, account security, email protection, device management, and other Microsoft 365 security controls.
Don't wait until someone clicks the wrong link.
Need help? Contact MooseDen IT for Microsoft 365 and small-business IT support.
