Add contact to the Recent Addresses list only after user actually replied to it (or wrote first).
In Outlook for Windows user needs to reply to an email (or write first) for an address to be added to the Recent Addresses list. On Macs user doesn't need to do anything and the addresses are added automatically. This gives a possibility for malicious users to inject one or multiple similar email addresses of known contacts by just sending email to victim. More than that, Outlook orders the list based on the recipient which sent the most emails, so if malicious user sends more emails than the original sender, he would overrule and become the first suggestion of the Auto-Complete list. This can be a sneaky way to exfiltrate company sensitive information or takeover the mail conversations. So, maybe it's better to add the email address to list only after user actually replied to it, or at least give the user an option to control this behavior.