Quick verdicts for common addresses
SharePoint phishing email scams should remain untrusted until the sender, business reason, and complete link destination check out. A familiar Microsoft logo proves very little.
sharepoint.com: Microsoft lists*.sharepoint.comas a SharePoint and OneDrive service pattern. A genuine hostname cannot prove the account, file, or later redirect is safe.[email protected]: Microsoft does not document this exact address for SharePoint sharing notifications. Treat it as unverified, rather than automatically safe or fraudulent.SharePointOnline.com: Microsoft documents[email protected]as a sender for relevant notifications. You still need to check the context and link.my.sharepoint.com: Microsoft documents the usual OneDrive format as<tenant>-my.sharepoint.com, not the bare hostnamemy.sharepoint.com.MeSharePoint.com: Microsoft uses this domain for Defender phishing simulations. Report it normally so your IT team can confirm whether the exercise is authorised.ShareSession.com: The domain displays a sale page, not a Microsoft service. Do not trust it without independent confirmation.
The decision you need
Your goal is to classify the message as an expected share, a suspicious email requiring a report, or an incident requiring urgent account action.
The UK Government’s April 2026 Cyber Security Breaches Survey found that 88% of businesses identifying a breach or attack had experienced phishing. For medium-sized businesses, 60% reported phishing.
Delay opening the file until you are satisfied. A short wait is preferable to exposing passwords, business data, or a live multi-factor authentication (MFA) session.
What to have ready
You can complete the check without opening the link or attachment. Have these items ready:
- The original email, left unopened where possible
- A computer for hovering over links, or a phone that can preview them
- A known number or trusted directory entry for the apparent sender
- Access to your work account through a manually entered Microsoft 365 address
- Your organisation’s phishing-reporting route
- Access to message headers if an administrator needs to investigate the sender
Use an alternative contact method if you suspect your usual device or account has been compromised.
The 6-step verification check
These six checks help you separate a genuine business share from a convincing imitation. Complete them in order. If a check fails, do not open the file; move to step 6 and report the message.
1. Test the business context
Compare the sender, file name, timing, and requested action with work you already know about. A genuine share should have a clear reason: a solicitor sending agreed documents, a supplier returning revised drawings, or a customer sharing figures discussed earlier.
Urgency, authority, and pressure are warning signs. The National Cyber Security Centre (NCSC) advises stopping when a request feels suspicious. Do not sign in when the file is unexpected, vaguely described, or presented as an urgent confidential document without context.
2. Reveal the real sender
Hover over the sender’s name in Outlook and compare the display name with the complete email address. Check any underlined via label, which Outlook uses when the apparent sender differs from the actual address.
Administrators can review Return-Path and Authentication-Results, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC). These email-authentication checks show whether a domain authorised the message. They do not prove the request is harmless.
A notification can come from [email protected] or the sharing user’s mailbox. Either could still lead to danger if an account has been compromised.
3. Preview the link destination
Reveal the link without opening it. Hover over the button or text on a computer, long-press on Android, or use a light long-press on iOS.
Microsoft advises checking the displayed destination rather than trusting button text or branding. Stop if the destination is shortened, obscured, unreadable, or unrelated to the claimed service.
4. Read the exact hostname
Identify the hostname between https:// and the first /, then read it from right to left.
Microsoft uses patterns such as contoso.sharepoint.com and contoso-my.sharepoint.com. In contoso.sharepoint.com, the registered service domain is sharepoint.com. In sharepoint.com.attacker.com, the registered domain is attacker.com.
That distinction matters because attackers place reassuring words to the left of a domain they control. The Public Suffix List also helps administrators interpret multi-part endings such as .co.uk.
Reject ShareSession.com as a Microsoft destination. Report MeSharePoint.com for internal confirmation because it may be an authorised simulation.
5. Confirm the share independently
Contact the apparent sender using a known telephone number, an existing conversation, or a trusted directory entry. Confirm the file name, business purpose, recipient account, and approximate sharing time.
Do not reply to the questionable email or call a number supplied within it. The NCSC recommends using contact details obtained independently.
You can also enter OneDrive manually, sign in to the intended account, and open Shared > Shared with you. Microsoft explains that this view can be filtered by the sharer, date, or file type. A missing file is not final proof of fraud because the view does not show every sharing arrangement.
6. Report before removing
Select the message in Outlook and choose Report > Report phishing. Then follow your internal reporting process and state whether you clicked, downloaded anything, entered credentials, or approved an MFA prompt.
Depending on your Microsoft 365 configuration, Outlook reports can reach Microsoft, your organisation’s reporting mailbox, or both. You can also forward suspicious emails to the NCSC at [email protected].
Report the message rather than simply deleting it. Your security team may need the original email to find related messages, warn colleagues, or investigate the apparent sender.
Three stop-or-proceed gates
Open the file only when all three gates pass:
- Context gate: The sender and document make sense for current work.
- Domain gate: The complete hostname matches the expected Microsoft service or another independently confirmed destination.
- Confirmation gate: The sender confirms the share, or the file appears in the intended Microsoft 365 account.
Report the message if any gate fails, even when the email passes authentication or uses a genuine sharepoint.com address. Microsoft has documented attackers using compromised accounts and genuine SharePoint files to redirect recipients to credential-stealing pages.
If you already interacted
Your response should match what happened. Act quickly, but use a trusted device and manually entered service addresses.
You clicked but entered nothing
Close the page, report the email, and tell your IT team which link opened. Run a full antivirus scan if the suspicious link opened or anything downloaded or installed.
The NCSC says further action is unlikely when no information was entered and nothing was downloaded or installed. Continue monitoring account alerts.
You entered credentials or approved MFA
Change the password immediately everywhere it was reused. Ask your Microsoft 365 administrator to secure or disable the account, revoke active sessions, and remove unknown authentication methods or devices.
Microsoft’s compromised-account guidance also recommends checking suspicious sign-ins, hidden inbox rules, unauthorised forwarding, altered privileges, and attacker-added MFA methods.
You shared financial details
Contact your bank immediately using its official number. If money was lost, follow the NCSC reporting guidance and use Report Fraud in England, Wales, or Northern Ireland, or Police Scotland in Scotland.
Two remaining questions
A passcode or missing file cannot settle the decision alone. Both can occur during legitimate sharing.
Does a passcode prove legitimacy?
No. Legitimate external shares can request a Microsoft account sign-in or send a one-time passcode. An Anyone link may require neither.
Enter a passcode only after confirming the share independently and checking that the browser remains on the expected Microsoft hostname.
Why is the file missing?
Shared with you can omit stopped shares and some group, organisation-wide, anonymous, or external-sharing arrangements. Use the missing file as a reason to contact the sender, not as final proof of fraud.
Expert help for repeat emails
These checks belong inside a wider cybersecurity for SMEs plan, supported by a clear reporting route, account monitoring, and regular staff practice.
Blowfish Technology provides managed awareness training with phishing simulations, short follow-up modules, employee risk scores, and regular reporting. Managed identity monitoring adds human investigation and account containment when credentials or Microsoft 365 sessions may be exposed.
For help checking an uncertain SharePoint email, call 01695 351778 or email [email protected] before anyone opens the file.
The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.