Need to decode a SafeLinks URL right now? Free tool — paste and decode instantly, nothing sent to our servers
Use the Decoder Tool →If you use Microsoft 365, you've probably seen links that look like this:
These are Microsoft SafeLinks URLs. They're designed to protect users from malicious websites — but they also make it impossible to see where a link actually goes. This guide explains what they are, how to decode them, and how MSPs and IT admins should handle them.
What Is Microsoft SafeLinks?
SafeLinks is part of Microsoft Defender for Office 365. When an email lands in Outlook on a Microsoft 365 tenant with Defender enabled, every hyperlink is rewritten by Microsoft before the message is delivered. When you click, Microsoft scans the destination in real time — blocking access if the site is malicious, allowing it if safe.
This is called "time-of-click protection." A URL that was clean at delivery could be flagged by the time you click it three days later.
SafeLinks URL Prefixes — What They Actually Mean
The prefix before .safelinks.protection.outlook.com indicates Microsoft's regional datacentre. It tells you nothing about whether the link destination is safe.
| Prefix | Region | Notes |
|---|---|---|
| nam10 nam12 | North America | Most common for US-based M365 tenants |
| eur01 eur03 | Europe | Common for UK and EU tenants |
| apc01 | Asia-Pacific | Includes ANZ region |
| ind01 | India | Indian datacentre region |
How to Decode a Microsoft SafeLinks URL
Step-by-step using the decoder tool:
Choose "Copy Link Address" — not from the URL bar, which may be truncated.
Use the Opollo SafeLinks Decoder — supports single URLs and batch decode for multiple links at once.
The tool reveals the original destination and highlights the domain so you can verify it at a glance.
The decoder includes a direct VirusTotal button — scans against 70+ threat intelligence sources in one click.
Free Microsoft SafeLinks Decoder
Single URL · batch decode · CSV export · VirusTotal check
Is Microsoft SafeLinks Safe?
Yes. SafeLinks is a legitimate Microsoft security feature. It is not phishing, not malware, and not a sign that anything is wrong with the email or the sender.
However, a website can become compromised after a SafeLinks scan. This is why reviewing decoded links carefully still matters, especially in IT and MSP environments handling sensitive client data.
Does SafeLinks Track Clicks?
Yes — if the "Track user clicks" policy is enabled by the tenant administrator. When active, Microsoft Defender logs which user clicked which URL, at what time, and whether access was allowed or blocked. This data is visible in the Defender portal and exportable for incident response.
For MSPs supporting clients in regulated industries, this click data can be valuable evidence in breach investigations.
MSP & IT Team Workflow — Handling Suspicious Links
For managed service providers investigating potential phishing reports from clients, use this process before clicking anything.
Use the SafeLinks decoder tool to get the real destination. Don't click the SafeLinks URL directly during an investigation.
Does the destination domain match the claimed sender? Watch for lookalike domains — paypa1.com, extra hyphens, fake subdomains.
Submit the decoded URL to VirusTotal — checks against 70+ threat intelligence sources. The decoder tool has a direct VirusTotal button on every result.
Tools like Browserling or a sandboxed VM let you visit a URL without exposing your device. The page loads on their infrastructure, not yours.
Submit to Microsoft's Defender Submissions portal and block the domain in the tenant's Safe Links exclusion policy.
SafeLinks Policy Configuration for M365 Admins
SafeLinks policy is configured in the Microsoft Defender portal under Email & Collaboration → Policies & Rules → Threat Policies → Safe Links. Key settings to review for each client:
Common SafeLinks Issues & Fixes
Final Thoughts on SafeLinks
Microsoft SafeLinks is a strong security layer inside Microsoft 365. It protects users from phishing attacks and malicious websites using real-time link analysis. Understanding how to decode and verify SafeLinks URLs gives you more control and visibility — and that balance between protection and awareness is what keeps organisations secure.
If your MSP or IT team needs help aligning marketing with cybersecurity positioning, that's exactly the kind of strategic work Opollo specialises in.
Need Help With MSP Marketing?
Opollo helps MSPs and IT providers build marketing programmes that generate consistent, qualified leads.
FAQs
Can SafeLinks protect me from malicious attachments in an email?
While SafeLinks is a powerful tool for scanning URLs, it is specifically designed to protect you from malicious web links. For attachments, Microsoft uses a complementary feature called Safe Attachments. This service opens email attachments in a virtual "sandbox" environment to check for malware or suspicious behavior before the file ever reaches your inbox. To ensure total security, you should ensure both SafeLinks and Safe Attachments are enabled within your Microsoft 365 Defender settings.
Why do some links in my Outlook remain "clean" while others are rewritten?
Not every link is automatically rewritten by the SafeLinks protocol. There are several reasons why a URL might appear in its original form:
Internal Domains: Your organization may have whitelisted internal domains or trusted partner sites to reduce latency.
Organization Settings: IT administrators can define "Do not rewrite" lists for specific trusted URLs.
Supported Protocols: SafeLinks primarily focuses on HTTP(S) and FTP protocols; other types of links may not be processed.
Plain Text Emails: In some configurations, SafeLinks only wraps URLs in HTML-formatted emails, leaving plain text messages untouched.
Does using a SafeLinks decoder bypass my organization’s security?
No, using a decoder tool does not bypass security. When you decode a URL, you are simply revealing the destination address so you can inspect it manually. However, the protection remains active; if you click the original rewritten link, Microsoft will still perform its real-time scan. Decoders are best used for:
Verify the destination of a link before interacting with it.
Clean up URLs for use in presentations or professional documentation.
Checking for "open redirects" that scammers use to hide their true destination.
Are there any performance downsides to having SafeLinks enabled?
For the vast majority of users, the impact on performance is negligible. However, because SafeLinks must route your request through Microsoft’s verification servers, you may occasionally experience a slight delay (latency) when a page is loading. Additionally, if Microsoft’s reputation service is experiencing an outage, links may take longer to resolve or fail to load entirely. Despite these rare occurrences, the security benefits of real-time protection far outweigh the millisecond delays in page loading.
How do I report a malicious link that SafeLinks missed?
Security systems are not 100% foolproof, and occasionally a new "zero-day" phishing link might slip through. If you encounter a suspicious link that wasn't blocked, you should:
Avoid clicking the link or entering any data.
Use the "Report Message" or "Report Phishing" add-in directly in Outlook.
Forward the email to your internal IT security team as an attachment.
Optionally, submit the URL to Microsoft’s Security Intelligence portal to help improve the filter for other users.