Home › Knowledgebase › KB-569

How to recognise and safely handle a suspicious 'Your password expires today' or fake IT password reset email

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious 'Your password expires today' or fake IT password reset email. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Phishing emails that impersonate IT support or Microsoft 365 are one of the most common ways attackers try to steal business credentials. These messages often claim your password expires today, your account has been compromised, or you must verify your login immediately. The goal is to rush you into clicking a link and entering your details on a fake webpage. This article explains how to recognise these emails, what to do if you receive one, and how to safely report it to 220 Internet Services.

What these phishing emails typically look like

While attackers constantly change their wording, most password reset phishing emails share a handful of tell-tale signs. Use the checklist below to quickly assess any suspicious message.

Common warning signs

Never enter your password after clicking a link in an email. If you are unsure whether a password reset is genuine, open your web browser and navigate to the service directly (for example, https://portal.office.com or https://myaccount.microsoft.com) and check your account status there.

Quick Fix Steps

If you have received a suspicious password reset email but have not clicked any links or entered any details, follow these steps straight away.

  1. Do not click any links or open any attachments in the email.
  2. Report the message to 220 Internet Services by opening a ticket through the support portal. Include a screenshot of the email and the sender's full address.
  3. Delete the email from your inbox and then empty your Deleted Items folder.
  4. If you use Microsoft 365, report the message using the built-in Report Phishing button in Outlook so Microsoft's filters can block it for other users.

If you have already clicked the link or entered your password

Acting quickly can limit the damage. Complete the steps below in order, even if you are unsure whether your details were captured.

Step 1: Change your password immediately

  1. Open a new browser window and navigate directly to the legitimate sign-in page. Do not use any link from the email.
  2. For Microsoft 365, go to https://myaccount.microsoft.com and select Change password.
  3. For your Windows computer login, follow the steps in our related guide: Password reset (Windows login).
  4. Choose a strong, unique password that you have not used elsewhere.

Step 2: Check and revoke suspicious sessions

  1. In Microsoft 365, go to https://myaccount.microsoft.com and select Sign out everywhere under Devices.
  2. Review Sign-in activity for any locations or times you do not recognise.
  3. If you see anything unusual, report it to 220 immediately through the support portal.

Step 3: Enable multi-factor authentication

  1. In https://myaccount.microsoft.com, select Security info.
  2. Add a second factor such as the Microsoft Authenticator app, a phone number, or a hardware security key.
  3. Save your changes and confirm the new method works before closing the browser.
Even if multi-factor authentication is already enabled, completing this step ensures your recovery options (such as your phone number) have not been altered by the attacker.

Step 4: Notify 220 Internet Services

  1. Open a ticket at app.220.com.au as soon as possible.
  2. Include the time you clicked the link, what information you entered, and any actions you have already taken.
  3. Our security team will review your account, force a password reset if required, and check for any unauthorised mailbox rules or forwarding.

How to inspect an email safely

If you want to double-check a message without clicking anything, use these techniques.

On a Windows computer in Outlook

  1. Open the email in your inbox. Do not click any links.
  2. Hover your mouse cursor over the sender's name to reveal the full email address.
  3. Hover over any link (without clicking) to display the actual destination URL at the bottom-left of the Outlook window.
  4. Right-click the email in the message list and choose ViewView Message Details to see the full message headers, including the originating server.

On a Mac in Outlook or Apple Mail

  1. Open the email and press Command + Option + H in Outlook for Mac to view the message headers.
  2. In Apple Mail, select the message and choose ViewMessageRaw Source.
  3. Look for the Return-Path and Received From fields to confirm the message originated from the claimed organisation.

On iPhone or iPad

  1. Open the Mail app and tap the sender's name at the top of the message to reveal the full address.
  2. Press and hold any link to preview the URL without opening it.

On Android

  1. Open Gmail and tap the three dots next to the reply button.
  2. Select Show original to view the full message headers.
  3. Press and hold any link to preview the URL.

Reporting the email to Microsoft 365

Reporting phishing helps protect your colleagues and other Australian organisations. The exact steps depend on which Outlook app you use.

Outlook on the web (Outlook 365)

  1. Select the suspicious message without opening it.
  2. In the top toolbar, click ReportPhishing.
  3. Follow the prompts to confirm. The message will be moved to your Junk folder and submitted to Microsoft.

New Outlook for Windows or Outlook for Mac

  1. Select the message.
  2. On the Home ribbon, click ReportPhishing.
  3. Confirm the prompt to submit the report.

Classic Outlook for Windows

  1. Select the message.
  2. On the Home ribbon, click Report MessagePhishing.

Outlook mobile (iOS and Android)

  1. Open the message.
  2. Tap the three dots in the top-right corner.
  3. Choose ReportReport Phishing.
If your organisation uses a third-party reporting add-in (such as KnowBe4, Proofpoint, or Defender for Office 365), the button may appear with your provider's branding. Use whichever option is available so the report reaches both Microsoft and your IT team.

Preventing future phishing emails

While no filter catches every phishing message, the following steps significantly reduce your risk.

220 Internet Services will never ask for your password by email, phone, or SMS. If anyone claiming to be from 220 requests your password, treat it as a scam and report it immediately.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket