DefenderTroubleshooting

Safe Links and Safe Attachments: troubleshooting blocked links, missing rewrites and delays

How Safe Links rewriting and time-of-click checks work, what the Safe Attachments actions do, how to find out why a click was blocked, and how to allow a legitimate URL without weakening protection.

A user reports that a link in an email opened a red "this website has been classified as malicious" page; another complains that every link in a newsletter turned into a long safelinks.protection.outlook.com address; a third saw an attachment as a placeholder for ten minutes. All three are Defender for Office 365 doing its job, but each needs a different answer. In this post I'll explain how Safe Links and Safe Attachments actually work, how to find out why a click was blocked, and how to allow what's legitimate the right way.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Key takeawaysFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (5 steps: Find out what blocked the click; Allow a legitimate URL properly; Use the "Do not rewrite" list for what it's for; Links aren't being rewritten; Attachments are slow or users see placeholders). 4. Verify the fix. 5. Key takeaways. Toolbox: contoso.com, contoso.com/*, *.contoso.com, *.contoso.com/*, safelinks.protection.outlook.com.1Symptoms2Why it happens3How to fix it4Verify the fix5Key takeaways1Find out whatblocked the click2Allow a legitimateURL properly3Use the "Do notrewrite" list for w…4Links aren't beingrewritten5Attachments areslow or users see…TOOLBOXcontoso.comcontoso.com/**.contoso.com*.contoso.com/*safelinks.protection.outlook.comHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Key takeawaysFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (5 steps: Find out what blocked the click; Allow a legitimate URL properly; Use the "Do not rewrite" list for what it's for; Links aren't being rewritten; Attachments are slow or users see placeholders). 4. Verify the fix. 5. Key takeaways. Toolbox: contoso.com, contoso.com/*, *.contoso.com, *.contoso.com/*, safelinks.protection.outlook.com.1Symptoms2Why it happens3How to fix it1Find out what blocked the click2Allow a legitimate URL properly3Use the "Do not rewrite" list for what it's for4Links aren't being rewritten5Attachments are slow or users see placeholders4Verify the fix5Key takeawaysTOOLBOXcontoso.comcontoso.com/**.contoso.com*.contoso.com/*safelinks.protection.outlook.com
At a glance: how this guide is organised · 5 fix steps · 5 key tools

Symptoms#

  • Clicking a link shows a Safe Links warning page: malicious website, phishing attempt, suspicious message, scan in progress, or an error page.
  • Links in email are rewritten to https://<region>.safelinks.protection.outlook.com/... and users or external tools complain.
  • Links are not rewritten for some messages, and you're not sure protection applies.
  • Attachments arrive as placeholders before the real file appears, or messages with attachments are delayed.
  • Users can't click through a block, or, worse, they can.

Why it happens: how the two features work#

Safe Links scans URLs in inbound email during mail flow and, by default, rewrites them so that every click is checked again at the moment it happens (time-of-click). The rewritten URL carries the original as a parameter, and hovering shows the original address. Links are rewritten per recipient and survive forwards and replies, but not automatic forwarding unless the final recipient is also protected. Only HTTP, HTTPS and FTP links are handled; URLs in RTF (TNEF) and S/MIME-signed messages aren't, and links to SharePoint and OneDrive are deliberately no longer wrapped although they're still checked. In Teams and in Word, Excel, PowerPoint, Visio, OneNote for the web and the Office mobile apps, URLs aren't rewritten at all: the client calls Safe Links at click time, which needs modern authentication and a signed-in work account.

Protection comes from the Built-in protection preset policy for every licensed user who isn't covered by Standard, Strict or a custom Safe Links policy; policies apply by priority and processing stops at the first match. The settings that generate most tickets are Do not rewrite URLs, do checks via SafeLinks API only (no wrapping; clicks are checked only in supported Outlook clients), Wait for URL scanning to complete before delivering the message (safer, but adds latency), Apply Safe Links to email messages sent within the organization, Track user clicks (without it, the click reports are empty) and Let users click through to the original URL, which Microsoft recommends leaving off.

Safe Attachments#

Safe Attachments detonates attachments in a sandbox after the regular anti-malware scan. Scanning usually completes within 15 minutes, and a new policy takes about 30 minutes to become effective. The policy action decides what users experience:

ActionWhat happensNotes
OffNo detonation; anti-malware still scansOnly for recipients who get mail from trusted senders; ZAP won't quarantine without a signal
BlockMessage held until scanning finishes; detected messages quarantinedDefault and the Standard/Strict recommendation; safe mail can be delayed
Dynamic DeliveryBody delivered immediately with attachment placeholders; file released when clean, message quarantined if maliciousExchange Online mailboxes only; PDFs and Office files preview while scanning
MonitorDeliver and track detectionsStill described in the docs, but Microsoft announced its retirement in the Message Center and the conversion of Monitor policies to Block; don't build on it

Older guides also mention a Replace action; it no longer appears in the policy. Dynamic Delivery can't replace attachments in some cases, such as messages moved by Inbox rules, public folders, S/MIME messages or on-premises recipients. Users can't release their own messages that Safe Attachments quarantined as malware or phishing; they can only request release.

How to fix it#

1. Find out what blocked the click#

Open Reports › Email & collaboration › Email & collaboration reports › URL protection report. The URL click protection action view shows Allowed, Blocked, Blocked by tenant admin, Blocked and clicked through, Clicked through during scan and Pending scan, with a table of click time, user, URL, action and app for the last 30 days. "By tenant admin" points at your own configuration rather than Microsoft's verdict. For message context use Email & collaboration › Explorer (Plan 2) or Real-time detections (Plan 1); in Plan 2 you can also hunt:

KQL
UrlClickEvents
| where Timestamp > ago(7d)
| where AccountUpn =~ "user@contoso.com"
| project Timestamp, Url, ActionType, Workload, IsClickedThrough, NetworkMessageId
| order by Timestamp desc

2. Allow a legitimate URL properly#

If the site is genuinely clean, don't just add it to a policy list. Go to Actions & submissions › Submissions, the URLs tab, submit the URL as I've confirmed it's clean and select Allow this URL. This creates an allow entry in the Tenant Allow/Block List that also overrides malware and high-confidence phishing verdicts; entries created directly on the Policies & rules › Threat policies › Tenant Allow/Block Lists › URLs tab can only override spam, bulk and regular-confidence phishing. Allow entries expire 45 days after they were last used by default (or on a fixed date up to 30 days out) and become active within about five minutes. From Exchange Online PowerShell:

PowerShell
Connect-ExchangeOnline
New-TenantAllowBlockListItems -ListType Url -Allow -Entries "portal.contoso.com/*" -Notes "Vendor portal, verified"
Get-TenantAllowBlockListItems -ListType Url -Allow

Mind the syntax: contoso.com matches only that host, contoso.com/* adds its paths, and a leading wildcard such as *.contoso.com is only supported for allow entries through the advanced delivery policy. Non-Microsoft phishing simulations belong in the advanced delivery policy, not in allow entries.

3. Use the "Do not rewrite" list for what it's for#

Each Safe Links policy has a Do not rewrite the following URLs list. Entries there aren't scanned or wrapped during mail flow, but they can still be blocked at click time; Teams and the Office web apps ignore the list; and only the first matching policy's list applies to a user. Use it for internal URLs you don't want wrapped (up to three wildcards per entry, for example *.contoso.com/*), not to override a malicious verdict; that is the allow entry's job. Conversely, a Tenant Allow/Block List allow entry doesn't stop a URL being wrapped.

  • The applicable policy has Do not rewrite URLs, do checks via SafeLinks API only selected. Protection remains in supported Outlook clients, but other mail apps lose time-of-click checks.
  • The link points to SharePoint or OneDrive, sits in an RTF or S/MIME message, or the message is internal and the intra-organisation setting is off.
  • The URL is in the policy's Do not rewrite list, or the message arrived before the policy took effect.
  • Another service wraps links before Microsoft 365 sees them, which prevents Safe Links processing.
  • Teams protection changes take up to 24 hours to apply.

5. Attachments are slow or users see placeholders#

Placeholders mean Dynamic Delivery: the body arrived on time and the file follows when the sandbox finishes. Message delays mean Block or Wait for URL scanning to complete. Check the Mail latency report on the same reports page, which separates inline detonation from asynchronous (Dynamic Delivery) detonation, before changing anything. If timeliness matters more than a few minutes of hold, Dynamic Delivery is the compromise; don't switch to Off.

Verify the fix#

  • Re-click the link: an allowed URL opens without the warning page, and the URL protection report records the click as allowed.
  • The entry appears on the URLs tab of the Tenant Allow/Block List with the expected expiry and, later, a Last used date.
  • For rewriting questions, view the message source: a protected link shows the safelinks.protection.outlook.com prefix.
  • For attachment delays, the Mail latency report and the recipient's experience match the policy action you chose.

Key takeaways#

  • Allow through submissions, not through policy lists; it's the only route that overrides malware and high-confidence phishing, and it expires on its own.
  • Keep click tracking on and click-through off, and turn on organisation branding so users can tell a real warning page from a fake one.
  • Prefer the Standard or Strict preset over hand-built policies; Built-in protection already covers everyone else.
  • Review the Tenant Allow/Block List regularly; Last used date tells you which entries are still needed.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)