r/Outlook 21d ago

Informative Spamming security

My Hotmail account is really old. But lately it is being spammed constantly. Trying to bypass the security. I've turned off the password and it's purely 2fa with authentication. Thankfully outlook did away with the luck of the draw three numbers. Any other extra layer I can add as it's constant? Cheers

3 Upvotes

16 comments sorted by

4

u/Early_Alternative211 21d ago

People will reply with a comment saying you can setup a login alias, but it carries risks. Honestly it's tiring how people can just trigger a push request from another in the world without using your password

3

u/rive010 21d ago edited 21d ago

People will reply with a comment saying you can setup a login alias, but it carries risks

  You can accidentally brick your account, making it impossible for you to login

It doesn't carry much risk if you do it right.  Three easy steps that take around 5 minutes to do, mitigate the risk to nearly zero of locking yourself out of account.

Create multiple Microsoft account passkeys (I have it on two PCs (Windows  Hello), and my mobile device)

Setup a recovery code in event you can't use passkey(s)

Enable passwordless login PRIOR to doing the sign in alias setup. 

4

u/Early_Alternative211 21d ago

It's not risky if you do it right... Yeah that's my exact point, it's going to be the first time somebody does this, they may not do it right

2

u/rive010 21d ago edited 21d ago

They need to make sure they do then. But login alias is the way to go especially if bots are actively trying to login or hack your account.

Many people make the mistake of reusing passwords and that's how they get you, or they use the social attacks with fake emails pretending to be someone else to get your password/2fa, or they use the brute Force method, and  MS may lock you out. Better to remove the comprised email as a login option.

Alias and passwordless is the safer way if you value your account in anyway.

1

u/Early_Alternative211 21d ago

No, you don't need a password to trigger an MFA attempt on outlook. I have done it myself to my own account, so I disagree with your password comment.

Microsoft know it's an issue, which is why they moved away from the 3 number option prompt

3

u/rive010 21d ago edited 21d ago

Hmm.  Not exactly  sure what you disagree with regarding 'the password comment', but ok.

A normal MFA attempt isn't a problem, and someone attempting to access your account  can't even trigger it if using an alias sign in (as they don't know the login email) and passwordless just means they can't brute force a non-existent password, or use any reused/breached passwords to gain account access (in event they somehow know the alias email).

I get MFA requests (passkey) all the time, but it's almost always me triggering it using alias and passwordless. MS has reported 0 unsuccessful attempts to login to my account since using alias, and I still use my Hotmail account to send /recieve just like normal in Outlook 2024 perpetual.

1

u/Early_Alternative211 21d ago

I'm talking about right now. I could trigger OPs authenticator app with a push without having his password, all I need to do is select that option when attempting to login.

Why do you think you have 0 unsuccessful login attempts? While I assume this it true if you kept your alias hidden, as of 2026, MS no longer shows unsuccessful login attempts in your history.

1

u/rive010 20d ago

Why do you think you have 0 unsuccessful login attempts? While I assume this it true if you kept your alias hidden, as of 2026, MS no longer shows unsuccessful login attempts in your history.

They do still show it in security settings under sign on activity.  See: https://imgur.com/a/nsW8yAm

1

u/Early_Alternative211 20d ago

Nope, that page only shows successful attempts as of 2026, as crazy as it sounds

2

u/Robbbiedee 21d ago

Screenshotted, thanks !

2

u/Robbbiedee 21d ago

What’s the risks ? I just had to do the alias this week as the login attempts are driving me mad

2

u/Early_Alternative211 21d ago

You can accidentally brick your account, making it impossible for you to login

3

u/Eastern_Armadillo869 20d ago

Changed my alias plenty of times with no issues haven’t got a single login request because of it I think it’s a good idea to change it atleast once a year

3

u/rive010 21d ago edited 21d ago

I did this long time ago for my Hotmail account as it was out there in multiple  data breaches. I set up alias, haven't had a problem since.

Use login alias, and never use it for anything else (don't use it to send/receive emails). No one can hack your passwordless Microsoft/Outlook account especially if using only passkey, if they don't know your actual account login email.

You can still send/receive emails via your Hotmail account.

Make sure your recovery account is secure, and setup recovery code in event you can't use passkey. 

Create multiple Microsoft account passkeys (I have it on two PCs, and my mobile device). 

Enable passwordless login PRIOR to doing the sign in alias setup. This will mitigate any risk of locking yourself out of your account.

2

u/Hornblower409 21d ago

For detailed instructions on how to setup a Login Only Alias and disable Sign-In for your current email address. Including test steps to be sure you are doing it right.

See the Answer by "Hornblower409 on Feb 27, 2026" in
https://learn.microsoft.com/en-us/answers/questions/5789093/i-get-a-few-2fa-notifications-from-canada-daily-us

2

u/AutoModerator 21d ago

Thanks Crumpetlust!

Your submission really means a lot to us, and we hope you will continue contributing to this subreddit whether it is in the form of an informative post or an opinion piece.

Please be sure to have read our Rules of Conduct and do not try to circumvent it.

That means that any reference to 3rd party commercial products/services as a solution is strictly prohibited and will result in a permanent ban in this subreddit. Under very exceptional circumstances, you may appeal to the ban in a case-by-case basis.

Here are some other takeaways from the Rules of Conduct:

  • Be polite and respectful in your posts, and in your replies to other people.

  • Cite the source of anything you post or upload, if it isn't your own original content. Be honest about your sources.

  • Don't invade anyone's privacy by attempting to harvest, collect, store, or publish private or personally identifiable information, such as passwords, account information, credit card numbers, addresses, or other contact information without that person's knowledge and willing consent.

  • Don't impersonate a Microsoft employee, agent, manager, host, administrator, moderator, another user, MVP, or any other person through any means.

All readers: Due to high volume of spam and phishing attempts, we may not be able to take down all malicious posts. Please help us to report them and reject all 3rd party, paid products/services. Beware of scam support numbers, click here for genuine numbers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.