How to recognise and safely handle a suspicious 'Your password expires today' or fake IT password reset email
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious 'Your password expires today' or fake IT password reset email. Follow the steps below to fix the issue.
Common Causes
Phishing emails that impersonate IT support or Microsoft 365 are one of the most common ways attackers try to steal business credentials. These messages often claim your password expires today, your account has been compromised, or you must verify your login immediately. The goal is to rush you into clicking a link and entering your details on a fake webpage. This article explains how to recognise these emails, what to do if you receive one, and how to safely report it to 220 Internet Services.
What these phishing emails typically look like
While attackers constantly change their wording, most password reset phishing emails share a handful of tell-tale signs. Use the checklist below to quickly assess any suspicious message.
Common warning signs
- Urgency or fear: Phrases such as "Your password expires today", "Action required within 24 hours", or "Your account will be locked".
- Generic greeting: "Dear User", "Dear Customer", or no greeting at all, instead of your actual name.
- Mismatched sender address: The display name says "IT Support" or "Microsoft 365", but the actual email address is from a random domain such as
[email protected]or a personal Gmail account. - Suspicious links: Hovering over the link reveals a URL that does not match the legitimate domain. Genuine Microsoft 365 password resets will only ever come from
microsoft.com,office.com, or your organisation's verified domain. - Unexpected attachments: HTML or PDF files that prompt you to "enable content" or "sign in".
- Poor spelling or formatting: Unusual grammar, mixed fonts, or odd spacing.
- Unusual request: Being asked to reply with your password, or to send it via SMS.
https://portal.office.com or https://myaccount.microsoft.com) and check your account status there.
Quick Fix Steps
If you have received a suspicious password reset email but have not clicked any links or entered any details, follow these steps straight away.
- Do not click any links or open any attachments in the email.
- Report the message to 220 Internet Services by opening a ticket through the support portal. Include a screenshot of the email and the sender's full address.
- Delete the email from your inbox and then empty your Deleted Items folder.
- If you use Microsoft 365, report the message using the built-in Report Phishing button in Outlook so Microsoft's filters can block it for other users.
If you have already clicked the link or entered your password
Acting quickly can limit the damage. Complete the steps below in order, even if you are unsure whether your details were captured.
Step 1: Change your password immediately
- Open a new browser window and navigate directly to the legitimate sign-in page. Do not use any link from the email.
- For Microsoft 365, go to
https://myaccount.microsoft.comand select Change password. - For your Windows computer login, follow the steps in our related guide: Password reset (Windows login).
- Choose a strong, unique password that you have not used elsewhere.
Step 2: Check and revoke suspicious sessions
- In Microsoft 365, go to
https://myaccount.microsoft.comand select Sign out everywhere under Devices. - Review Sign-in activity for any locations or times you do not recognise.
- If you see anything unusual, report it to 220 immediately through the support portal.
Step 3: Enable multi-factor authentication
- In
https://myaccount.microsoft.com, select Security info. - Add a second factor such as the Microsoft Authenticator app, a phone number, or a hardware security key.
- Save your changes and confirm the new method works before closing the browser.
Step 4: Notify 220 Internet Services
- Open a ticket at app.220.com.au as soon as possible.
- Include the time you clicked the link, what information you entered, and any actions you have already taken.
- Our security team will review your account, force a password reset if required, and check for any unauthorised mailbox rules or forwarding.
How to inspect an email safely
If you want to double-check a message without clicking anything, use these techniques.
On a Windows computer in Outlook
- Open the email in your inbox. Do not click any links.
- Hover your mouse cursor over the sender's name to reveal the full email address.
- Hover over any link (without clicking) to display the actual destination URL at the bottom-left of the Outlook window.
- Right-click the email in the message list and choose View → View Message Details to see the full message headers, including the originating server.
On a Mac in Outlook or Apple Mail
- Open the email and press
Command+Option+Hin Outlook for Mac to view the message headers. - In Apple Mail, select the message and choose View → Message → Raw Source.
- Look for the
Return-PathandReceived Fromfields to confirm the message originated from the claimed organisation.
On iPhone or iPad
- Open the Mail app and tap the sender's name at the top of the message to reveal the full address.
- Press and hold any link to preview the URL without opening it.
On Android
- Open Gmail and tap the three dots next to the reply button.
- Select Show original to view the full message headers.
- Press and hold any link to preview the URL.
Reporting the email to Microsoft 365
Reporting phishing helps protect your colleagues and other Australian organisations. The exact steps depend on which Outlook app you use.
Outlook on the web (Outlook 365)
- Select the suspicious message without opening it.
- In the top toolbar, click Report → Phishing.
- Follow the prompts to confirm. The message will be moved to your Junk folder and submitted to Microsoft.
New Outlook for Windows or Outlook for Mac
- Select the message.
- On the Home ribbon, click Report → Phishing.
- Confirm the prompt to submit the report.
Classic Outlook for Windows
- Select the message.
- On the Home ribbon, click Report Message → Phishing.
Outlook mobile (iOS and Android)
- Open the message.
- Tap the three dots in the top-right corner.
- Choose Report → Report Phishing.
Preventing future phishing emails
While no filter catches every phishing message, the following steps significantly reduce your risk.
- Keep multi-factor authentication enabled on all work accounts.
- Use the Microsoft Authenticator app rather than SMS where possible.
- Report suspicious messages promptly so filters can be updated.
- Keep your operating system, browser, and Outlook up to date.
- If you are unsure about a message, contact 220 Internet Services through the support portal before clicking anything.
Still Having Issues?
💻 Open a Ticket