Defanged malicious URLs in SOC security notification emails still classified as High Confidence Phishing by Defender for Office 365

Mohd Irzani Bin Wahid 0 Reputation points
2026-09-07T13:11:07.18+00:00

Hi, SOC security notifications may contain threat-intelligence indicators such as malicious domains, URLs and IP addresses.

Throughout my years of using Microsoft email services across different organisations, I have regularly handled similar security notifications. However, this is the first time I have encountered recurring quarantine of such messages in this manner.

As part of normal security practice, potentially malicious indicators are defanged before being included in the email, for example:

example[.]com hxxps://example[.]com

Despite being defanged, some SOC security notification emails are still being classified by Microsoft Defender for Office 365 as High Confidence Phishing and quarantined.

The internal Microsoft 365/email security team has simulated the situation and advised that, even when the email content has been defanged, Microsoft Defender for Office 365 Machine Learning (ML) may still classify the message as phishing because the potential risk associated with the malicious URL remains.

I would like to validate whether this is the expected behaviour of Microsoft Defender for Office 365 and understand the recommended approach from Microsoft for this type of security communication.

A similar concern has also been observed with legitimate threat-intelligence reference links. For example:

https://www.virustotal.com/gui/domain/example[.]com

In this case, the actual destination is virustotal.com, while the potentially malicious domain appears only as part of the URL path for threat-intelligence lookup purposes. However, such references may still contribute to the message being classified as phishing.

The security team has suggested the following workarounds:

  • Use Plain Text format without embedded hyperlinks.
  • Remove or mask malicious URLs from the email body and provide the advisory as a PDF attachment.
  • Use a password-protected PDF where the original hyperlink needs to be retained.

I would appreciate Microsoft’s clarification on the following:

  1. Is it expected behaviour for Defender for Office 365 ML to recognise and evaluate defanged indicators such as example[.]com and consequently classify the email as High Confidence Phishing?
  2. How does Defender evaluate legitimate threat-intelligence URLs where a potentially malicious domain appears only within the URL path, such as a VirusTotal domain-report link?
  3. Are Plain Text, PDF attachments, or password-protected PDF attachments the Microsoft-recommended approach for SOC/security advisories containing potentially malicious indicators?
  4. Is there a Microsoft-supported method to safely include defanged domains, URLs and threat-intelligence references in security notifications without causing recurring High Confidence Phishing classification?
  5. Is there any recommended configuration or best practice for trusted security notification emails containing threat indicators, without broadly bypassing anti-phishing protection?
  6. Have there been any recent changes to Defender for Office 365 ML, URL analysis or phishing-detection behaviour that may explain why this is occurring more frequently now, despite similar security notifications having been sent for many years?

These are often time-sensitive security notifications, and repeated quarantine may delay the delivery of important security information to customers.

I would appreciate Microsoft’s or other SME clarification on whether the observed ML behaviour is expected and any official recommendation or documented best practice for safely distributing defanged threat indicators and threat-intelligence references through Microsoft 365 email.

Thank you.

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.