Glossary
Safe Links
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
A Defender for Office 365 feature that rewrites URLs and validates them at click time.
Safe Links is the Microsoft Defender for Office 365 feature that rewrites URLs in incoming email and Teams messages to point at a Microsoft proxy. When a user clicks, the proxy looks up the destination against current threat intelligence — including URLs that have gone malicious since the message was delivered — and either allows, warns, or blocks the click. Defends against time-of-click attacks where a phishing link looks clean at delivery but is weaponised before users click. Applies to URLs in Outlook (all platforms), Office desktop and web apps, Teams messages, and Microsoft 365 mobile apps. Requires Defender for Office 365 Plan 1 or higher.
Worked example
An employee receives an email with a link to what looks like a shared invoice document. At the moment of delivery, the destination was a legitimate-looking but newly registered site with no bad reputation yet; by the time the employee actually clicks it two days later, attackers have swapped the page for a credential-harvesting form. Because the link was rewritten by Safe Links, the click routes through Microsoft's proxy first, which re-checks the destination against current threat intelligence at click time — not delivery time — flags the site as now malicious, and blocks the page from loading, showing a warning instead.
Common pitfalls
Assuming a link is safe because it "looked fine when the email arrived" is exactly the gap Safe Links exists to close — the whole point of time-of-click protection is that email security scanning at delivery can't see threats that don't exist yet. Users hovering over a Safe-Links-rewritten URL and being confused or suspicious because it doesn't show the original destination is a common support question — the long safelinks.protection.outlook.com wrapper is expected behaviour, not a sign of a phishing attempt itself. And forgetting that Safe Links has configurable exceptions and doesn't apply to every possible surface by default (some third-party or unusual client configurations can bypass it) means it should be treated as one strong layer of defence, not an absolute guarantee no malicious link can ever reach a user.