Search for an Outlook alias and you get two different answers, because Outlook is two different things. One is Outlook.com, Microsoft's consumer mail service, where an alias is a second address bolted onto an account you already have. The other is Outlook the mail client, which reads whatever mailboxes you point it at. Advice written for one rarely fits the other.
A Microsoft account alias is a second label on a mailbox you already own. An alias from a separate forwarding service is an address at another provider that happens to deliver into that mailbox. In a From field the two look identical. When something goes wrong they behave nothing alike.
This guide covers both: what the built-in aliases do, where they stop, how to add an outside address to Outlook as a sending identity, and why replying almost never needs that setup. Microsoft renames menus often, so every interface path below is written as it stands at the time of writing.
What Outlook means by an alias
In Microsoft's own words, an alias is an additional email address associated with your Outlook.com account, and it uses the same inbox, contact list and account settings as your primary address. Every alias shares one password. You can sign in with any of them, and choose which one a message is sent from.
You add and remove them from the account page that manages how you sign in, not from mail settings. At the time of writing it is titled Manage how you sign in to Microsoft. You can create a new address on a Microsoft domain, or add one you already own elsewhere as a sign-in name. Microsoft caps how many an account may hold and how many new ones you can make in a period. Those figures have been revised more than once, so read them on the page rather than in any article, this one included.
One thing an Outlook alias is not is plus-addressing. Writing yourname+shop@ is a separate trick, a convention many mail systems support rather than anything standardised. RFC 5233 is often cited as the standard for it and is nothing of the kind. Its abstract opens by saying that on email systems which allow for subaddressing it is sometimes desirable to compare against sub-parts of addresses, and it then defines a Sieve filtering extension for doing so, leaving the separator character to each system.
What those do and do not hide
An Outlook alias hides your primary address from the person you are writing to. That is real and useful. A shop, a forum or a landlord sees the alias, not the address your bank uses.
It hides nothing else. The alias shares the inbox, the contacts, the settings and the password. It is a label on one account, not a wall between two, so compromising the account exposes every alias at once. And it puts no distance between you and the provider: if you wanted an alias because you would rather one company not hold the whole picture, a second address on that company's account does not move the needle.
There is a practical ceiling too. A handful of aliases cannot give every service its own address, which is the thing that makes a leak name the leaker and lets you switch one address off alone.
Where a separate alias service differs
Purpose-built forwarding services take a different shape. You generate an address per sender, they accept mail sent to it, and forward it to a mailbox you already read, Outlook included.
Three differences do most of the work. Volume, because you get an address per signup instead of a handful. Isolation, because switching one off touches nothing else. Ownership, because most of these services let you point a domain you own at them, so the address can be moved if the provider disappoints you.
Named options span a wide range of prices. Apple's Hide My Email is bundled with iCloud+ and forwards to the address on your Apple account. Firefox Relay, addy.io and SimpleLogin are among the dedicated forwarding services. Limits, retention and reply behaviour differ and change, so read the current documentation rather than a comparison table written a year ago.
The honest cost is an extra party in the path. A forwarder sees the envelope of every message it handles: who wrote to you, when, and at which address. Ask what is logged and for how long, and treat a vague answer as an answer. If the service closes and your addresses were on its domain, they die together, which is the argument for using a domain you own.
When the built-in option is the right answer
If you want two or three addresses, one for shopping, one for a side project, one for family, Microsoft's aliases do that at no cost and without a new account anywhere. Paying for a service on top would be renting a lorry to move a chair.
If all you want is to find out who leaked your address, and your provider supports plus-addressing, that is free and instant, with two caveats: plenty of signup forms reject the plus sign, and anyone reselling your address can strip the tag first, so the trick names the leaker without stopping the mail. Paying earns its keep when you want a lot of addresses, want any one of them dead within seconds, or want them on a domain that belongs to you.
Adding a private alias as a sending address in Outlook
First, the thing that wastes the most time: you cannot do this in Outlook.com on the web any more. Microsoft removed the ability to connect new third-party accounts and to sync existing connected accounts from within Outlook.com, and its support page for the change points people at Outlook mobile, Outlook for Windows or Mac, or plain forwarding instead. Any guide telling you to add a connected account in web settings is describing something that no longer exists.
In the desktop and mobile apps you add the alias as an account. Paths as at the time of writing:
- Classic Outlook for Windows: File, Add Account, type the alias address, choose Advanced options, tick Let me set up my account manually, pick IMAP, then fill in the servers by hand.
- New Outlook for Windows: Settings, Accounts, Email accounts, Add account. Note that new Outlook syncs third-party accounts through Microsoft's service rather than from your own machine.
- Outlook for Mac: Tools, Accounts, the plus button, Add Account.
- Outlook for iOS and Android: Settings, Add Mail Account, Add an Email Account.
The outgoing side is where the alias actually lives. Your provider publishes these values. Type them exactly rather than guessing:
- Outgoing SMTP server: the hostname your provider gives you, not smtp-mail.outlook.com. That one is for Outlook.com's own accounts.
- Port: 587 with STARTTLS is the usual submission port, and 465 with implicit TLS or SSL is the common alternative.
- Outgoing server requires authentication: tick it. An unauthenticated submission will be refused.
- Username: usually the full alias address, though some services use a separate account name. Use whatever the provider prints, character for character.
- Password: often a dedicated app or SMTP password generated in the provider's dashboard, not the password you use on its website.
- From address: it has to match the alias exactly. A mismatch here is the commonest cause of a rejected send.
The catch nobody mentions is the incoming side. Outlook is built around accounts that have a mailbox, so it asks for an incoming server even when all you want to do is send. Plenty of forwarding services have no mailbox to offer, because forwarding is the entire product. If yours provides IMAP, use it. If not, composing from that address inside Outlook may not be possible, and the provider's own compose window is the shorter road.
Then send a test message to an address you control and read the raw headers: the From line should show the alias.
Replying needs none of this
Most people who set up SMTP for an alias did not need to. If your forwarding service rewrites the reply address on each message it forwards, you press Reply in Outlook exactly as you would on any other mail, the reply travels back out through the service, and the person on the other end sees the alias. No account to add, no ports, no password.
SMTP is needed for one case: starting a new conversation with somebody who has never written to you, so there is no forwarded message to reply to. If you never do that from an alias, the previous section is optional.
There is one honest exception and it catches people out. Reply All. The rewritten address is the only one that routes back through the service. Every other recipient on the thread is an ordinary address, so your reply reaches them straight from your real account and shows your real address on the way. On a thread that matters, reply to the sender alone.
Reply rewriting is a service behaviour rather than a standard. Some forwarders pass mail through untouched, and replying to one of those exposes your real address every time, so test it once before you rely on it.
Troubleshooting
Authentication failures. A 535 response usually means the username is in the wrong form, you used the website password where an app password was required, or the authentication tick box is off. If two-step verification is on anywhere in the chain, expect to generate a dedicated password. Separately, Microsoft stopped accepting basic authentication for personal Outlook.com accounts over POP, IMAP and SMTP in September 2024, so a stored username and password no longer connects to Microsoft's own servers. That is about reaching Outlook.com rather than your alias provider, but it is why so many older guides now fail.
Ports. Use 587 with STARTTLS or 465 with implicit TLS. RFC 8314 recommends that clients and servers implement both, and notes there is no significant difference between their security properties when the implementations are correct. Port 25 is for relay between mail servers and is blocked on most consumer and cloud networks, so ignore any guide that suggests it for sending. A connection that hangs rather than being refused is usually a firewall dropping packets, so try the other port before blaming the credentials.
Rejected at send. A 550 or 553 mentioning the sender address means the server will not let this account send as that From address. That is an identity problem, not a server problem. Make the From field match the alias exactly, and check the alias is still active on the provider's side.
Mail landing in spam. If you send through your provider's own domain, alignment is their responsibility. From a domain you own, three records have to work together: SPF listing the host that sends on your behalf, DKIM signing with the key the provider issues, and DMARC, which only means anything once the first two align.
One case looks like a sending problem and is not. If mail forwarded to your Outlook inbox lands in spam, your SMTP settings are irrelevant, because forwarding is an inbound path. SPF breaks on forwarding unless the forwarder rewrites the envelope sender, so a forwarded message can fail checks the original passed. That is a question for the forwarding service, and a filter rule on your side is the usual short-term fix.