If legit, such mails will contain a link to a microsoft site (eg: starting with "www.microsoft.com", "www.msn.com", "ideas.live.com", etc...). If not, the mails are bogus.
You can never make sure mails are legit by only looking at the email address in the from-field because you can put whatever you like in there.
Nor can you see if mails are legit by looking at the contents or even looking at the links in the text, again all this can be spoofed easly.
The only way to make somewhat sure the mails are legit is to look at the actually URL under the links. Quite often with such spoofed emails the textual link shows a legit site, but as soon as you click on the link you will be taken to a 3rd party (spam/porn/whatever) site.
eg: Go to
www.microsoft.com
(hoover over the link and look at the actual URL in your browser's status bar)
And in doubt, copy the underlying URL and only past the first part (the domain) to your browser.
In the above example, copy/paste only "http://very.dodgy.porn.site/", thus not the part after the domain. This is very important because many spam mails like that often have individualised links, so if clicked, the sender can know that he has send the email to an existing and active email-address (and you will recieve more spam).