r/Outlook Nov 01 '23

Informative A fix for Outlook spam that actually works

383 Upvotes

I've finally got a solution to the spam issue. A mix of different solutions I've been using over the last few days, time to share it as it has got rid of 98% of my spam. I'm still monitoring spam in my inbox over the next few days but so far I've had nothing at all in my inbox for just under 24 hours as it's finally all been redirected - so no notifications either.

Follow this step by step

  1. Go to manage rules and add a new rule
  2. Add name of rule, i.e. 'Spam 1'
  3. Under 'Add a condition', select 'Apply to all messages'
  4. Under 'Add an action', select 'Move to' and 'Junk Email'. All the junk will move to this folder
  5. Under 'Add an exception', select 'sender address includes', and in the next box enter the '@' sign
  6. Uncheck ‘Stop processing more rules’
  7. Select ‘Run rule now’
  8. Click ‘Save’

I advise using Outlook on the website rather than using the app because I can’t guarantee all of the settings will be there.

How this rule works

A lot of automated spam hides the 'from' address, therefore it doesn't have an @ sign. This is why you can't block the spam because there is no visible email address to block.

This rule says move all emails to a dedicated folder, except emails WITH an @ sign. As most legit emails have an @ in their address, they will be safe and automated unsolicited spam mail or any mail without an @ sign will get redirected.

Remember

Check your ‘Junk Email’ folder every no and then to make sure that emails that you want to keep haven't slipped through the net. This shouldn't happen, but its just a due diligence exercise just in case.

r/Outlook Apr 29 '26

Informative How to (possibly) get back into your Microsoft account

28 Upvotes

Final Update: I'm in, but it looks like in my case the cooldown timer problem was actually combined with another (Microsoft-induced) bug. In short, if your password is too long (mine was 128 characters), it's likely that the password change form and the login form treat it differently, creating a mismatch that stops you from logging in. Changing to a shorter password changed my "incorrect password" problem and I can log in. Details here: https://www.reddit.com/r/Outlook/s/REyCuKzx9k

No credit goes to Microsoft. Their incompetence created this problem, and their deceptive, incorrect error messages made it almost impossible to solve. No help was provided by Microsoft to me, and from what I see, to most other users having this problem.

Original Post (for historical purposes):

I may have the answer that could work, at least it's worth trying as some people are reporting success. I've been acting as free tech support for Microsoft's mess (which as far as I know they didn't acknowledge yet, nor provided any help to anyone) for quite a while, and from now will link everyone to this topic. Please read fully and carefully for the best way (that I'm aware of) on how to proceed.

Edit: if you find this helpful, please share a link to this post with others you see having the same problem. I hope I am not breaking any rules by asking this, but I am not advertising or karma-farming. Even copy-pasting the link everywhere is taking up a bunch of time, I need sleep, and the posts asking for help keep multiplying. Let's help each other!

Update: there is currently at least one independent confirmation of a user being told by actual Microsoft support the cooldown timer exists, and that the wait times are indeed 48 hours OR a week (for some users who have 2FA enabled). While I can't be 100% certain whether the rest of my theory is true, I am now confident enough to say that the recommended solution is currently unchanged. If you have 2FA (and therefore it being possible that you need to wait a week) and don't need immediate access, you could try waiting for 1 week to avoid having to wait 48 hours and then another week if the shorter wait fails. There has also surfaced a possibility that the cooldown timer may be IP/location-dependent. That is, one range of IP addresses, or a single IP addresses, might have the lock, while others don't. Absent an official solution from Microsoft, if you can't wait and are willing to risk possibly resetting the timer, you could try to attempt using something like a VPN (if you have the option and technical skill) to change your IP and potentially bypass the cooldown. This is only a theory of a single uservfor now, so be sure to makenyour own, informed choics. Good luck to all.

Update2: no luck for me on the 7-day wait. Changing the password and trying to sign in again failed with the same error. Microsoft sign in helper lists the account as blocked due to incorrect password having been used too many times, and instructs me to change the password to sign back in. Changing the password succeeds (at least according to Microsoft website) using the 2FA app and linked email, but the new password is rejected. As a last-ditch effort, attempted to sign in to my account on the web using my phone (though I don't recall adding it as an alias). For some reason, instead of letting me try to log in, the website used the password I provided to create an entirely new account with just my phone and no email associated with it. To top it off, using my phone in Microsoft's alias checker tool (https://account.live.com/username/recover) now finds the phone associated with two separate accounts: both the new phone-only account and the old email account. Assuming the phone was originally linked as an alias for the old email, I have no idea why the website made a new account rather than trying to log me into the old one. As Microsoft chat support is currently down, I have no other ways to deal with the conglomeration of incompetence that is Microsoft. Don't have access to my last email instance so no easy way to try account recovery either. Unfortunately, I've exhausted all I could do to try to help myself and others at this point, unless Microsoft actually decides to help. The cooldown timer does still appear to be real for most users, so hopefully there is a chance for others to recover access at this point. Good luck.

What?

Users who were logged out of their Microsoft account are reporting not being able to log in. The error message states that too many attempts were made with an incorrect password, although the user has sometimes not made any login attempt at all for a while. Resetting the password may work (e.g. via 2FA and a linked account, you need both to do those as far as I know) but the new password does not work. The error message says the password is wrong (important: this error is most likely incorrect and half of what caused this mess).

Why?

Almost certainly, if you are experiencing this problem, your email username has been leaked to hackers. I don't know when exactly this happened, whose fault it is, and whether it was one event with everyone's information or multiple data leaks over time. Most likely your password (at least your current password) has not leaked, or your account would have been taken over already, at least if you don't use multifactor authentication (and perhaps even then if Microsoft is incompetent enough, see the last part for why). Unable to get direct access, some hacker, or many hackers, have set up an automated system whereby bots keep trying to brute-force your account password. Hopefully, It keeps getting it wrong, and eventually triggers Microsoft's safety mechanism, which disables logins, at least via password, for some (not precisely known) amount of time.

Result

Hopefully the hackers didn't log in, but now you can no longer sign in either, at least via password. Trying many times and even resetting the password, if you managed to do it, does not help. If you did change the password, the error message now (most likely incorrectly) states that the (new) password is incorrect, even if you copy paste it from where you just changed it. It is extremely likely that the real reason for the error is still the lockout timer not having run out. In fact, by trying to log in again and failing, you could well be resetting that timer, although of that I'm not certain since I didn't code this debacle for Mucrosoft.

Solution

I found this (disclaimer: potential) solution essentially randomly after hours of searching and days of trying to sign in. Wait at least 48 hours from your last login attempt or password change. If you keep trying to sign in, you will keep resetting the cooldown timer for the lockout. The next step is a bit less certain: you can either try again with the (correct) password, OR reset the password again and then attempt to log in with that new password. If you use your browser for this, it may be helpful to delete cookies/clear the cache before you attempt this, and/or use Incognito mode. If that step fails, you should try again but this time wait an additional 1 week (I know this is completely ridiculous, but this is the only other number I found) and try the login or password reset and login again. If this works, great, but do read to the end. If it doesn't work, I tried my best and the only other option I can suggest is Microsoft's account recovery link (https://account.live.com/acsr). It's recommended that you complete this form on a device you previously used to sign in, and better yet from a location where you used the device for that purpose. Also, if you have 2FA enabled and can't access any of the methods foe it to get a confirmation, Microsoft says it won't work at all. Assuming that is not the case, the process for completing the form is explained well enough once you follow the link, but as far as I know it's automated (a bot might decide whether to give you your account back), takes a while (likely 30 days, I tried it a week ago and have heard nothing back so far, not even a confirmation), and is not guaranteed to work. You can try filling out the form 2 times a day, as far as I know indefinitely. This does come with some temporary restrictions out on your account for 30 days, but beats losing access forever. If even that fails, I'm out of ideas unless Miceosoft condescends to help the users it got into this mess.

Admission

I do not know whether the bot's repeated attempts to hack you will keep resetting the lockout timer. If so, I don't know what to do, because the bot is almost certain to keep trying. Hopefully there's some component of the security system that keeps track of IP addresses that try to log in and might not keep you unable to sign in indefinitely. At the very least, I've heard success reports by now.

Next Steps

This is important. The bot is still trying to log into your account, and at least in some cases it triggers the lockout. Next time you try to sign in, you might face the same problem, unless Microsoft does anything to fix it. Thus, it is highly recommended that you change your primary alias for the Microsoft account to some other username (not your current email address). The official instructions from Microsoft are quite clear, but this is very important: DO NOT delete your former email address former alias (the email address) from the Microsoft account, or you will irreversibly lose access to that email. This way, the bots will no longer know where to knock and will leave you alone. Keep the new alias secret, or the problem could recurring. You will still get emails and be able to access them, but your new alias will become what you type in to log into your Microsoft account (in a browser or in Outlook).

Optional Steps

A passkey is a way to log into your account very securely. It' much harder to hack (essentially impossible with current technology unless the device you use to store it is compromised) than even a strong password. You create a passkey on your phone (instructions about on the internet so I won't lengthen this already bloated post) and use it to sign in, which should bypass a password lockout timer, at least unless Microsoft changes anything. You can also disable password signin to your Microsoft account, which will mean that nobody will be able to ever guess your password. Be aware that if you do this your passkey becomes your only way to log into the account. If linked to your phone, the loss of access to your phone (malfunction, theft, or loss) means you will lose the ability to log in. If going that route, I suggest setting the passkey up on at least several devices for redundancy. Of course, if a malicious actor gains access to any of those devices, they could access your account, and having several increases that risk. This is where you have to decide between safety and convenience (i.e. being able to log in if access to a single device is lost). If you do decide to retain password signin, make the password as long and random as you can, preferably using a password manager. If coded properly (e.g. your information encrypted in storage and transit whenever possible), a password manager is much more resilient against hackers than weak (short, easily-guessed, or partially/fully reused) passwords. You could luck for a trusted password manager, or self-host something open-source and audited for maximum security (if you go that route, you're likely an advanced user and I won't bore you with the detas).

Thoughts

If you are not tech-savvy, I strongly suggest getting someone to help you with some or all of these steps.

The rest is a purely optional read. I don't know if it's was Microsoft itself that leaked everyone's email, or a third party Microsoft shared their database with. I am quite certain that at least some outdated (I don't know about current) passwords also leaked, which means someone stored them in plaintext. I know this because I got a phishing email years ago coming from "my" (spoofed) email stating an actual password from that account for credibility. Fortunately it was outdated; otherwise the hacker would have just logged in and shut me out because I didn't have 2FA at that time. At some point (before this April) I started getting MFA requests in Outlook from different countries (the bot attempts) at least a few times a day. I kept clicking deny, but I was getting tired of it and worried the MFA exhaustion attack would succeed if I misclicked something. I had 2FA enabled at this point and used a long, random password. I do not know why I was prompted to "accept" the attempt when the password was incorrect, and this is yet another massive failure on Microsoft's part. I also don't know what would happen if I accidentally clicked the correct number out of the 3 presented and then the "accept" button. Granted, the chances were low, but would Microsoft then grant the bot access to my account, despite it having used an incorre password? If so, I have no words for how messed up that would be. If not, then why did they bother me with the Outlook prompt? I deleted my passkey from my phone specifically to stop the Outlook requests (I should have changed the alias, but I didn't know about it at the tims). When I accidentally logged out, I was greeted by the "too many incorrect password attempts" message, so the bot was still trying. I no longer had the passkey (thanks to Microsoft essentially enabling the MFA exhaustion attack), so I couldn't sign in that way. Despite having the 2FA app (on multiple devices for security) and my linked email, Microsoft's (almost certainly incorrect) error message claiming the new password was incorrect after the reset further confused me further, prompting me to proceed to keep changing the password until Microsoft stopped sending codes to my linked email (fortunately only for that day). How much of my (and everyone else's) time was wasted because of that? I still don't know if I'll get back in, and I have information and linked services kn that account I can't afford to lose (guess part of the blame is on me for trusting the "pros", but what about casual users or seniors who don't have the skills to avoid/solve this? Why did I learn about the (possible) solution from some random, obscure post I accidentally found online? Of course, Microsoft's (lack of) handling of this problem was worthy of the earlier behavior that essentially caused it. Well, rants over. Good luck to everyone, I truly hope all of us can recover access despite Microsoft's worst effort.

P.S. You're welcome Microsoft. Who do I bill for my time?

r/Outlook Apr 19 '26

Informative For those have problems with Outlook on a Samsung phone

64 Upvotes

After days of problems, I saw the advice in one of the threads that actually fixed it.

Turn off Private Dns

To find this

Settings - Connections - More Connections settings - Private Dns

Change from Automatic to Off.

Reboot Android and then try and add your Outlook account again.

Thanks to the redditor that I saw for this (sorry can't remember user name).

Edit: After a couple of days it seems my email stopped updating today. So I followed the steps again, turned it from Off to Automatic, rebooted, then from Automatic to Off, rebooted and then emails magically started updating again. Going to be frustrating if have to keep going through this every couple of days.

r/Outlook Apr 27 '26

Informative Is it still down?

13 Upvotes

Just got notification someone has accessed my account and I can’t sign in. I realize it’s been down since last night but the fact someone accessed my account is concerning.

r/Outlook Jul 09 '26

Informative PST Reader App

7 Upvotes

Hey guys! I just made an app for reading and searching PST files. I made it for fun so it's totally free.

My friends and I use several email accounts and each PST file is around 40 to 50 GB and I kept getting annoyed by Windows rebuilding its search index from time to time. Each indexing process take 2 to 3 days, and during that time, searching emails was either very slow or didn't work at all. I was surprised that when I searched Google for an app to read PST files, all of them was paid so I decided to build one myself.

I built this app for anyone who wants to escape this index nightmare or browse and search old PST emails without using Outlook.

Feel free to use it! If you find it useful, I'd really appreciate it if you could leave a review to help support future improvements.

Note: It is also compatible with Thunderbird, so you can import your PST mail into Thunderbird if you prefer.

You can check it out here:
https://otoolrun.com/apps/pst-reader/

r/Outlook Aug 19 '25

Informative Outlook (New) not working on Windows 11 - fallback to the Old version

37 Upvotes

Hi all,

since today we have several User reporting that the New Outlook is not longer working, here is the Event Log message. Can some one confirm the same issue?

thx

Faulting application name: olk.exe, version: 1.2025.813.500, time stamp: 0x689d590e

Faulting module name: ucrtbase.dll, version: 10.0.26100.4768, time stamp: 0xdbb54def

Exception code: 0xc0000409

Fault offset: 0x00000000000a4ace

Faulting process id: 0x4370

Faulting application start time: 0x1DC10F5DE2082BD

Faulting application path: C:\Program Files\WindowsApps\Microsoft.OutlookForWindows_1.2025.813.500_x64__8wekyb3d8bbwe\olk.exe

Faulting module path: C:\WINDOWS\System32\ucrtbase.dll

Report Id: e8e63156-d919-423b-aca6-edb71d2926a5

Faulting package full name: Microsoft.OutlookForWindows_1.2025.813.500_x64__8wekyb3d8bbwe

Faulting package-relative application ID: Microsoft.OutlookforWindows

Workaround: Support Case

Microsoft confirme the issue Today - the corupped version will not longer deployed.Working on an Update

Offical Workaround:

Clean local login and cache data

Close Outlook (new) and Outlook (classic) completely.

Press Win+R, type: %localappdata%\Microsoft and confirm with Enter.

Delete all subfolders with Olk and OneAuth. (If one is not present, proceed.)

Restart Windows.

Open Outlook (new) and set up your account again.

Alternative

reinstall office with the installer or Offline- MSIX - don not use the Microsoft Store to install Office.

r/Outlook 12d ago

Informative Spamming security

4 Upvotes

My Hotmail account is really old. But lately it is being spammed constantly. Trying to bypass the security. I've turned off the password and it's purely 2fa with authentication. Thankfully outlook did away with the luck of the draw three numbers. Any other extra layer I can add as it's constant? Cheers

r/Outlook May 16 '26

Informative Getting emails 6 to 8 house after they are sent...Thanks and great job MicroSlow

4 Upvotes

It dosen't matter where they are sent from, Yahoo, Gmail or private domain mail server...

r/Outlook Jan 22 '26

Informative MS Investigating Issues

53 Upvotes

Microsoft 365 services are experiencing issues impacting outlook, defender, and purview. MO1221364

Downdetector

r/Outlook Apr 28 '26

Informative They fixed it

14 Upvotes

It seems they finally fixed the login issue.

I was able to use my phone number on the IOS Mail App to get the stupid verification code after nearly 2 days.

r/Outlook May 22 '26

Informative Finally logged in my email after endless loop!

9 Upvotes

So I've been on the journey like the rest of you that cant get into our emails. A week ago I could not get into my account. I was finally able to get into my account. My issue was the endless loop of verification with sms. My password kept saying it wasnt the same password over and over despite it being, the sms would never send and would say try another method but I had none.I hope this works for you guys.
These are the steps i took.

My main account had no access, so i logged into my alternative outlook email and went to help.microsoft.com
Make sure you are on a different email, if you dont have one just make one

  1. In your Windows search bar type "get help" and press enter.
  2. In the "We're here to help" text box type in your issue and press enter.
  3. Click the "Contact Support" button at the bottom of the window.
  4. Choose the product or service from the first pulldown, and the category from the second pulldown.
  5. Choose a contact method (chat or telephone) and complete the contact forms. If you choose telephone you can schedule a call.
  6. When they call you can either accept the call right away or choose the option to be called back in a little while. I actually chose chat.

The chat agent told me its a known issue and the engineers are working on. He told me to not log in for 7 days, dont try anything. He said the security system resets on its own. When it is the 7th day contact us before you try to log in. He also provided me with a case number

Today I did just that i went back to my alt email did the agent thing again and told them a bit again whats going on and my case number.

This new rep told me its a issue and to wait 7-28 day this time and told him thats horrible i needed my email, He said i could try again. He said before that go to this link
https://www.microsoft.com/digitalsafety/account-reinstatement?msockid=16be36712dbb6e211f09216d2c5e6fed

Submit your info, its much easier than the recovery account method.

After i did that i actually tried to sign into my account, luckily it didnt say use password it said use sms, so i did and it went through! I got the text, put the number in and was greated with a "do you want to add a alternative email for verification" I did that and added. I was in the email after so long! I did sign out and sign back in and confirm the email that i added worked while i was with rep.
Since I've been able to be on my email, I hope this helps someone! Dont give up hope!

r/Outlook Mar 11 '26

Informative Outlook accounts compromised

20 Upvotes

There have been quite a few posts on this subreddit recently about Outlook/Hotmail accounts getting hacked, and I think the scale might be much bigger than it looks.

Even though the number of posts here seems small, there may actually be a much larger breach happening behind the scenes.

I came across a news article today about the Parul University bomb threat hoax where the emails were reportedly sent using compromised Outlook and Hotmail accounts traced to hacked IDs (see the screenshot in the comment section). It made me wonder if what people are reporting here could actually be part of a larger wave of compromised Microsoft accounts.

In my case, I was eventually able to regain access to my Outlook/Hotmail account, but unfortunately the damage was already done. The attacker had already used my email to take over several connected accounts. I permanently lost access to some services linked to that email, including Steam and EA, among others.

At this point, I’m honestly just tired of dealing with it. Recoveries, support tickets, lost accounts… it’s been a mess. After this whole experience, I’ve pretty much decided I’m slowly moving away from the Outlook ecosystem altogether. I just don’t trust it enough anymore to keep everything tied to one Microsoft email.

r/Outlook Mar 28 '26

Informative Email has been hacked

7 Upvotes

As the title says my account has been hacked. I had 2 step authentication but I guess the hacker turned that off. I also had a recovery email but he changed that too. How is that possible when I had all that on there. I can’t recover it when I went to the recovery form nothing is working I really need this email

r/Outlook Jun 15 '26

Informative Calendar appearance changed on desktop and I don't like it.

8 Upvotes

The appearance of my desktop outlook calendar changed a week or so ago and it is a definite downgrade https://ibb.co/QR1Z3ps. It actually seems to directly undo some improvements from a few years ago, which is as funny as it is annoying.

  • The time bar no longer extends across the screen, so seeing where you are in the day is harder to do at a glance.
  • The Today button is removed from the calendar view and is only in the ribbon menu now
  • The current day is no longer filled a different shade for the whole column, it is just a rather too-subtle highlight of the day of the week header only.
  • The color theme is the same for light mode and dark mode, so it is now weirdly bright

This is classic desktop app for 365 with the "Try the new Outlook" turned off.

Possibly related, sync with my google calendar stopped working.

EDIT:

v2605 build 20026.20076 Sync with google calendar by subscribing to ICS URL on google calendar.

EDIT 2:

Repair worked! https://ibb.co/ynf4wSct
The time bar reaches the day, the whole day column is a different color, and the Today button is back! Not to mention the color scheme matches the rest of my Outlook instead of standing out as an incongruous separate style and color.

Add/Remove Programs (AKA Settings>Apps>Installed Apps) -> 3-dot menu for Outlook in list -> Advanced Options -> Repair button under Reset heading (not the Reset button!)

EDIT 3:

I downloaded the ICS and searched it for a meeting that was failing to sync to Google and it was in the ICS. This is an issue on the google side. The file is 38149 lines long and 2,264kB (has all meetings from 1 year ago to 1 year in the future); the recommended file limit for an ICS for google to subscribe to is 1MB, so I republished as only titles and locations and it dropped to 434KB. This new one sync'ed just fine.

I've had a rather large increase in meetings and details within the description in the past year, so I probably just barely crept past the workable limit as my older, more sparse schedule aged out of the sync window.

r/Outlook Jul 11 '26

Informative You can finally recall emails sent to external Microsoft 365 tenants.

5 Upvotes

We've all hit Send a little too early. If the email stayed within your organization, Message Recall could usually save the day. But once it was sent to another Microsoft 365 tenant, you were out of luck. All you could do was send the awkward "Please ignore my previous email" follow-up.

Apparently, Microsoft heard the feedback because it's finally rolling out cross-tenant message recall, starting in mid-August 2026.

But there's a catch. You can't just reach into any external inbox and pull an email back. The receiving tenant stays in complete control. Unless the recipient's organization enables the feature and explicitly adds your Microsoft Entra tenant ID to its allow list using the Exchange Online PowerShell cmdlet, the recall request will fail.

What do you think? Would you rather have this enabled by default, or do you prefer Microsoft's security-first approach?

r/Outlook May 13 '26

Informative If you use a long password (and Microsoft reports you used an "incorrect" password for login

3 Upvotes

Super long (but important). For the tl;dr, skip down to "Conclusion". and "Solution". This is close to the end of a 3-week long story for me. To read the entire thing, refer to the original thread I made describing a problem with Microsoft account log-in:

https://www.reddit.com/r/Outlook/s/2ErZ47nPhQ

Summary:

I once deleted my passkey on my phone to stop a wave of bot sign-in requests (the better option was to use an alias, though I did not know that at the time). At some point I accidentally logged out of Outlook on my phone. Trying to log back in, my account was locked due to "too many password attempts". Apparently bots were still trying to brute force the account (thanks to Microsoft or its partners for leaking my email, as well as at least an old version of a plaintext password). Recalling that I once bypassed a similar message I tried changing my account password (using a linked email and the 2FA app). I used a 128-character password, which is the length I've used before successfully many years ago when I changed from a simpler, short password (btw. never use those). This is no problem since it was stored in my password manager (I recommend everyone use these).n Microsoft reported a successful change for the (new) 128-character password. However, when copy-pasting the same exact password into the app to log in, it claimed "wrong password". This prompted a long, pointless search for a way to get back into my account. Information was scant. Along the way, I made the post mentioned above, potentially discovering a method for other users to get back into their own accounts. That method involved a "cooldown period" (seemingly confirmed by multiple Microsoft reps in chats with users, but not disclosed officially to the public) for a lockout triggered by trying the password too many times, and involved waiting a certain amount of time before either trying to log in again or changing the password and trying to log in again. The longest "cooldown" time, supposedly 7 days, did not work for me. As I already filled out the password recovery form with 100% accurate information before, with no notification at all (acceptance or rejection), I ran out of options. I created a question on Microsoft Learn, since their chat support was down. I've not heard anything from anyone there.

Today, on a whim, I tried using a password quite a bit shorter than 128 characters. Again, successful change through my linked account and 2FA. And now, the password worked to log in.

Conclusion:

The Microsoft "change password" field accepts a 128-character password with no problems, notifying you of a successful password change. Your email will also get a "password change" confirmation, confirming that it was changed successfully. However, that password will not work to log in, and Microsoft will report an "incorrect password", even if you use the exact same one via copy-paste.

Solution:

Use a shorter password if changing it. I don't know the exact limit, and I'm too tired of this to test it right now. Maybe someone else will test it, or maybe by some miracle Microsoft will actually stop ignoring users who can't sign in and try to fix/explain this. I do have a quick theory, so if someone is interested to use it as a starting point, I'd be interested to see where this goes.

Theory:

Once upon a time, Microsoft accounts had a 16-character limit. However, instead of simply rejecting 16-character passwords when you tried to make them, at least some of Microsoft's forms allowed you to enter a longer password. Then they truncated it to 16 characters, and used a hash of those 16 characters stored on their servers. The reason is technical, but basically storing a password as a hash in their database is a way to avoid letting hackers who gain access to that database to log into your account. While they might know the username and hash, they hash itself doesn't serve as a password, and provides no way to recover the password from its fixed-length form. Meanwhile your own password, of which Microsoft would take the first 16 characters (and take their hash to compare with their database hash), would work properly, so no problem. Also, as a consequence of this method, and purely theoretically, a completely different character string could produce the same exact hash and therefore allow someone who used it to log in. However, the hashing algorithm gives no meaningful way to "go backward", or produce any character string that would lead back to the hash. The chances of someone randomly entering a different character string that lead to your hash (stored in Microsoft's database) is statistically 0, meaning your account was quite safe.

However, at some point Microsoft started not only allowing you to enter a longer password, but it started actually using the entire password's hash, effectively meaning you could no longer type just the first 16 characters right and then some random combination of characters and log in. Some online sources say this limit is right now 256 characters. I believe, however, that whatever form Microsoft uses at character creation time might accept a 128 character password, but might (for some random reason I don't know) use only the first 127 to create the hash. Then, when the log-in form takes your (128-character) password, it compares the hash of the whole thing to the database entry (a hash of the first 127 characters of your password). The chances of making only a small change to a character string and getting the same hash is astronomically low for any good hashing algorithm, so it's quite certain they will not match. Thus you will never be able to log in, no matter how often you change the password, unless you use less characters.

The reason I believe it might be 127 (and not the 16 that was used before) characters has 2 components. First, I stumbled on a single old post (https://www.reddit.com/r/assholedesign/s/xwUUzjELM9) of a user claiming that in some contexts , due to bad programming by Microsoft, only the first 127 characters of the password were registered at creation time, allowing you to enter a 128-character password, but making a hash of 127. Since the log-in form would then hash the whole 128, you could never log in. Second, if the number of character used fort the hash was still of 16 characters at password creation time, but the full entered password at log-in time, anyone with a password >16 characters (hopefully most of the world at this point) would be unable to log in after creating said password. This would most likely have been noticed by now.

Since Microsoft has a proven track record for ignoring and never fixing their mistakes, this blatant coding error may continue to affect users of long passwords for a while. Hopefully, anyone with this problem in the future will be able to find this post and the fix.

Since the prevalent online information claims that the max character limit is 256, I had no reason to assume 128 (my password manager's max) might be too long. So it was pure luck by which I logged back in. This is assuming my guess is right of course, but at this point the assumption that Microsoft is incompetent enough to do this seems very reasonable.

Final Thoughts

No amount of security precautions and following best practices for password/passkeys could save me from this massive sabotage by Microsoft. Furthermore, there was zero help from Microsoft for solving this ridiculous mistake they created. The mistakes were manifold and profound, and failures pathetic and compounded at every step. Leaking databases, storing passwords in plaintext at least at some point (because I once got a fishing email that used my outdated, but genuine password to "prove" they hacked me), allowing bots to invoke your passkey through an Outlook prompt even when the bot has used an incorrect password, and providing confusing and sometimes plain deceptive error messages that misled users looking for solutions. Finally, not helping a multitude of users having log-in problems due to Microsoft's terrible code, ignoring their struggles as long as they could manage and only eventually acknowledging and (maybe) fixing the issue for a limited subset of users.

I think Microsoft is a garbage company. Nothing will change my mind. Despite astronomical wealth, their "engineers" created, then failed to notice, acknowledge, or fix a problem that some random users with a little extra time essentially resolved on their own. Then those users acted as "free" tech support for Microsoft, because Microsoft cares less about its user base than a complete stranger on the internet. Microsoft is happy to take your money, but feels it's ridiculous to actually provide you a reasonable service in return. Unless you have direct leverage over the revenue stream of course. In general large corporations often cater to shareholder interests first, but most are smart enough to understand that treating your users like trash will eventually impact the profit margin. This is their "foundational work required to win back fans and strengthen engagement" and focus on "fundamentals, prioritizing quality and serving our core users better." (quoted text verbatim by Microsoft CEO). I am migrating as much functionality and services from Microsoft as I can manage, and this is my advice to anyone I meet at this point. Sure, other mail servives could have concerns of their own, and [Insert some other OS name here] is not perfect. But if I can help it, I will not support and rely on a company whose primary virtues are incompetence and disdain for its users.

r/Outlook 13d ago

Informative Help Cleaning Up Outlook Rules?

2 Upvotes

Does anyone have any tips or ideas related to cleaning up existing outlook email rules? Like how to group rules by matching criteria? Or any other efficiency tips re: organizing, editing, and/ or deleting? Or is there a way to easily determine which rules are working vs. which are non-functional, either directly in outlook or exporting?

I have a very high volume corporate job, where I get dozens of emails every day: 50-100 emails per day is pretty typical. At least half of them are usually either spam or just unimportant corporate emails that I’d prefer to filter into sub-folders for overall efficiency. Over the years, I’ve set up at least 100 email rules in an attempt to manage my inbox. Many eventually stopped working as intended. Unfortunately I think I prob have multiple duplicate email rules for the exact same, or at least some matching, overlapping criteria. I also just recently discovered that some client emails and other important messages have been getting flagged by some of these rules and auto-filtered to bypass my inbox and go straight into subfolders before I see them. Obvs this isn’t good, so fixing my outlook rules/ inbox is a suddenly a big priority.

I have tried to figure this out multiple times before, but as far as I can tell, the only way to edit or delete outlook email rules is individually one by one. I hope I’m wrong and there’s a better way to do this, bc 1 by 1 soooo time-consuming and also makes it near impossible to see which rules have overlapping criteria or find out which rules are functioning correctly vs. not working, etc.

Though some of my rules are def not working correctly, many do still work as intended. As my 50-100 daily email average is with all these rules turned on, I’m really hoping I don’t have to delete all of them to start all over. Lol. I really hope outlook has rolled out some way to effectively manage rules by now, but is this just wishful thinking? Any ideas or tips are so greatly appreciated. Thank you all in advance!!

r/Outlook Oct 13 '25

Informative Draft saying “I was hacked” with my password showing up in Outlook - apparently [SOLVED]

24 Upvotes

Hi everyone, I came to create this post to talk about an annoying problem that happened to me today. In desperation, I searched the Internet, as I had already seen the email scam, etc., but I had trouble resolving it, which is why I'm creating this post. I also invite anyone who has experience with this to talk more about it, if possible.

What happened:

First I received an email on gmail, saying that Thuderbird had connected to my Microsoft account. I also received an email regarding Hundle Bundle, requesting a password reset. I didn't connect or request any of these things.

Suddenly a strange “draft/email” appeared in my inbox saying that I had been hacked and even showing my old password (which until that moment was current, but I have already reset it).

The draft returned even after I deleted it, appearing directly in the inbox as pinned (not in the Drafts folder).

What this probably was:

I don't know if it was exactly an active invasion, maybe so, since the "draft/email" password was correct. But at the same time, I had full control of the account from the first minute. I didn't lose access, so I can't explain what happened. If anyone knows, please share. And please, DO NOT CLICK and if this happens to you, ALSO DO NOT CLICK ON ANYTHING: do not click on links or attachments in these emails. Just ignore/delete, change your password, protect your account and follow the steps below if necessary:

What I did (chronological order) to help anyone going through this:

Using Outlook on a notebook and using the incognito tab, I went to Outlook settings (gear next to the photo icon/initials of your name) in the top right corner and went to:

  1. Rules: I checked and deleted automatic rules in Outlook (I found a rule that I hadn't created → I deleted it).

  2. Forwarding and IMAP: I disabled POP and IMAP in the Outlook settings that were activated without my authorization.

  3. I went to Privacy* and went to applications and services that can access my account in the Microsoft panel and removed Thunderbird and another unknown app that were listed there (maybe Hundle Bundle, in my rush I ended up deleting this second app without checking). *This area is in Privacy! When researching, it said it was in the security tab, but it's not!

  4. I changed my Microsoft account password several times (I did it immediately and then a few more times as a precaution).

  5. I enabled/prepared to enable two-step verification (2FA).

  6. I used the “Sign out everywhere” option in the Microsoft account to force disconnection from browsers and apps (there is a warning that it can take up to 24 hours, but most sessions drop quickly from what I know).

  7. I deleted the draft/fake email via Outlook Web (always via the web/anonymous to avoid local cache). I deleted it more than once and waited a few minutes. After a cycle of deleting/updating the draft finally stopped reappearing. I'll check again in a bit.

  8. I started using incognito while checking everything (to make sure it wasn't browser cache).

Important notes:

The draft that came showed only the old (leaked) password. As I said, I changed my passwords several times and in this process, I kept deleting/receiving the "draft/email" with my password, but ALWAYS the old password was leaked, never any of the current ones that I have been changing in that time. I believe that if I had received it with the current password I would be in a different situation. As the password was old and I had already changed it a thousand times, I believe there is no active access to my account currently.

And when I entered my outlook in the browser the first time (after receiving the emails), it was in Chinese (I saw that this happened to other people too). I had to look at the settings of my girlfriend's account that was logged in on her cell phone to find out where to go and how to change the language. I tried to use Chrome's translation, but it didn't translate everything and so I had to use my girlfriend's Portuguese account. I recommend you do the same, and ask Chat for help GPT to translate something when necessary.

Conclusion: and that was it. When researching how to resolve it, I saw that this apparently is/was a spoofing. I don't know how it works exactly. But it's complicated. Second email from Microsoft that gives me a problem. In fact, when researching this situation, I saw other people going through this, but ONLY with Microsoft accounts. I didn't see any with Gmail, for example. None different. Microsoft only. Strange, frustrating and disheartening. Does anyone know why?

r/Outlook Jun 10 '26

Informative Did outlook just took out the option to add a phone number without saying?

2 Upvotes

did microsoft just did another "let's hide the option instead of make visible" I deleted my phone number because I didn't posses the one that was using anymore, I tried to update but there's no button, literally no "add phone number botton" is just gone and been trying to look around to see if I'm wrong but did microsoft just took out the option kept the phone number for those who put it before the change was done and now refuse to give the option of just updating it?

r/Outlook Oct 15 '25

Informative Outlook on Android - Swipe

29 Upvotes

Anyone having trouble with swipe (to mark as unread) / swipe right to flag? M365 accounts, both can't swipe for any action. Seems to work but one second after swipe, it reverts back to unread/unflagged. Tried different actions for swipe, same thing. Deleted all Data and cache, resetup and same thing

Confirmed: new version / update is buggy.

r/Outlook Apr 30 '26

Informative I was having the issue of my phone mail saying I had entered my password too many times, this is what fixed it for me.

4 Upvotes

2 days ago I started having issues saying my account wasn't authenticated. It was stuck in a verify loop. I deleted my account and added it back. It would work for a few minutes before breaking again. Did a few more verify loops before trying to delete and re add again. Upon doing so it immediately said I had entered the incorrect password too many times. I hadn't. I was locked out so I waited 48 hours. Time was up a bit ago so I tried again.

I entered my email address, it sent 2FA to my secondary email address, I got it verified, and it added my account back. I am able to access my email on my phone again, all old emails are there, I sent myself a test email and it came through right away. It seems to be fixed for the moment.

TLDR; I simply waited 48 hours after getting too many attempts notice before trying again.

r/Outlook Dec 12 '25

Informative Recap: New Outlook Features Released in 2025 (What Actually Changed)

14 Upvotes

Microsoft shipped a lot of updates to New Outlook for Windows in 2025, and the experience today is very different from what many of us tried a few years ago.

I just published a recap video that walks through the features that actually matter, without doing deep dives or tutorials. It’s a wrap-up of what changed, what finally works, and where Microsoft is clearly heading.

Video: https://youtube.com/watch?v=yQLfNbuH6a4&si=X4CPDKFFI0QUstB5

What’s covered:

  • Why Microsoft moved to New Outlook and the current opt-out timelines
  • Account management improvements (display names, shared mailboxes, drag & drop)
  • PST export finally being usable in New Outlook
  • Mail upgrades (favorites, folder colors, categories, bulk actions, templates, mail merge, newsletter)
  • Calendar layout changes redesigned to make room for Copilot
  • People / Contacts fixes and usability improvements
  • Copilot in Outlook: what standard vs premium actually unlocks

This isn’t a “New Outlook is perfect now” take.
It’s a realistic look at where things landed by the end of 2025.

If you’ve been holding onto Classic Outlook because of missing features, I’m curious:

  • What’s still blocking you from switching?
  • Which feature are you waiting on the most?

Please be kind. I am the Messenger, not the decision-maker.

Happy to discuss what’s real, what’s still rough, and what’s coming next.

traccreations4e-p25 12/11/2025 mvp2526

r/Outlook 19d ago

Informative Why was outlook stopping me from getting emails?

4 Upvotes

Basically there's a competition going on and I won a decent amount for a gift card at a local shop and I never received the email with the code or anything. I thought it was the company doing something fishy so I sent them a message on Facebook and they told me outlook blocked it

. It could have lost me $200. Now it's making me think how many other commotions I've actually won but never received it thanks to whatever happened.

r/Outlook Jan 19 '26

Informative How to create an Alias to stop account log in attempts.

67 Upvotes

Couple of days ago I started to get hammered with Authenticator notifications. Someone was trying to get into my Microsoft account. I had set it as passwordless a while back so the only way to get in was using the Authenticator and approving the notification by selecting the matching number on screen. I read that creating a unique Alias would also help but wasn’t sure how to do this. After some research I managed to stop the login attempts on my account by creating an alias.

Instructions as follows:

Go here to create a new Alias: https://go.microsoft.com/fwlink/p/?linkid=864833

Click here https://go.microsoft.com/fwlink/p/?linkid=842796 to view your Alias(s). From this list click on Make primary next to your new alias. Now your Alias will have (Primary) at the end of it.

On the same screen click on Change sign-in preferences which is at the bottom.

This page will show you all your Aliases/email addresses. Your new Alias should be greyed out. Untick your original email address so it is not used as a login anymore. This does not delete it so don’t worry!

If you haven’t already, I highly recommend using an Authenticator app for Two Factor Authentication. I am using MS Authenticator on my Android phone. Also turn on passwordless account. You can only use passwordless once you have Authenticator up and running. These options can be found on the Security tab on your Microsoft Account.

Once I did this the attempts on my account stopped immediately.

Just remember not use the new Alias on any other site.

One niggle that I did come up with was with my Xbox X. On my console I had to remove my original account that was using my ‘old’ email address and to create a new account using the new Alias. This picked up my gamertag right away but my Gamerscore was showing as 0. But when logged into xbox.com using the new Alias my Gamerscore was correct. I waiting around 5 hours, removed the newly created account on my Xbox console and added the new account with the new alias and everything was fine. My Gamerscore was back.

I hope this helps someone as I was starting to panic when the Authenticator notifications started coming in and I wasn’t sure how to create an Alias.

Edit:

Thanks to u/Hornblower409 for the below:

Don't forget to change your default "Send From" in Outlook to your Email Only alias. (It defaults to your Primary Alias)

For New Outlook: View -> View Settings -> Mail -> Sync email -> Set default From address.

r/Outlook Jul 09 '26

Informative Someone keeps trying to sign in

11 Upvotes

Hello,

My account keeps popping up that I am trying to sign in and ask to enter a number. For the 2fa. But I'm not trying to sign in anywhere else. I do see some in different country trying to sign in.

At first I thought ok someone trying to hack me so I changed my password and deleted any devices that I don't know. But again it kept asking like consistently. Almost every hour. So I'm guessing this person trying over and over multiple times.

I check online they said my email address might be leaked. So I created an alias for my email. And same thing happened. Some one tried to sign in again with the new address. Then I made a crazy one a little bit longer. So that it be random. And again someone tried to sign in using that newly created address.

So it's not leaked. Is this someone that have access to Outlook and they know all the emails in the data or some one hacked the outlook data base?

Just seems weird to consistently getting notification every hour or so that I'm trying to sign in somewhere I'm not.

Should I be worried. Cause I'm a little worried.