How to Decode Microsoft SafeLinks URLs (And Check Them Safely)

Need to decode a SafeLinks URL right now? Free tool — paste and decode instantly, nothing sent to our servers

Use the Decoder Tool →

If you use Microsoft 365, you've probably seen links that look like this:

https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fyourvendor.com%2Finvoice&data=05%7C...

These are Microsoft SafeLinks URLs. They're designed to protect users from malicious websites — but they also make it impossible to see where a link actually goes. This guide explains what they are, how to decode them, and how MSPs and IT admins should handle them.

SafeLinks is part of Microsoft Defender for Office 365. When an email lands in Outlook on a Microsoft 365 tenant with Defender enabled, every hyperlink is rewritten by Microsoft before the message is delivered. When you click, Microsoft scans the destination in real time — blocking access if the site is malicious, allowing it if safe.

This is called "time-of-click protection." A URL that was clean at delivery could be flagged by the time you click it three days later.

Key Point SafeLinks is a legitimate Microsoft security feature — not phishing, not malware. It's Microsoft routing your clicks through its protection infrastructure so it can scan destinations at the moment you click.

SafeLinks URL Prefixes — What They Actually Mean

The prefix before .safelinks.protection.outlook.com indicates Microsoft's regional datacentre. It tells you nothing about whether the link destination is safe.

PrefixRegionNotes
nam10   nam12 North America Most common for US-based M365 tenants
eur01   eur03 Europe Common for UK and EU tenants
apc01 Asia-Pacific Includes ANZ region
ind01 India Indian datacentre region

How to Decode a Microsoft SafeLinks URL

Step-by-step using the decoder tool:

1
Right-click the link in Outlook

Choose "Copy Link Address" — not from the URL bar, which may be truncated.

2
Paste into the decoder tool

Use the Opollo SafeLinks Decoder — supports single URLs and batch decode for multiple links at once.

3
Review the decoded URL

The tool reveals the original destination and highlights the domain so you can verify it at a glance.

4
Run VirusTotal if suspicious

The decoder includes a direct VirusTotal button — scans against 70+ threat intelligence sources in one click.

Free Microsoft SafeLinks Decoder

Single URL · batch decode · CSV export · VirusTotal check

Decode Now →

Is Microsoft SafeLinks Safe?

Yes. SafeLinks is a legitimate Microsoft security feature. It is not phishing, not malware, and not a sign that anything is wrong with the email or the sender.

However, a website can become compromised after a SafeLinks scan. This is why reviewing decoded links carefully still matters, especially in IT and MSP environments handling sensitive client data.

Important Limitation SafeLinks reduces risk — it doesn't eliminate the need for user judgement. A site can pass a scan and become malicious hours later.

Does SafeLinks Track Clicks?

Yes — if the "Track user clicks" policy is enabled by the tenant administrator. When active, Microsoft Defender logs which user clicked which URL, at what time, and whether access was allowed or blocked. This data is visible in the Defender portal and exportable for incident response.

For MSPs supporting clients in regulated industries, this click data can be valuable evidence in breach investigations.

MSP & IT Team Workflow — Handling Suspicious Links

For managed service providers investigating potential phishing reports from clients, use this process before clicking anything.

1
Decode the URL first

Use the SafeLinks decoder tool to get the real destination. Don't click the SafeLinks URL directly during an investigation.

2
Check the domain carefully

Does the destination domain match the claimed sender? Watch for lookalike domains — paypa1.com, extra hyphens, fake subdomains.

3
Run a VirusTotal scan

Submit the decoded URL to VirusTotal — checks against 70+ threat intelligence sources. The decoder tool has a direct VirusTotal button on every result.

4
Use an isolated browser if still unsure

Tools like Browserling or a sandboxed VM let you visit a URL without exposing your device. The page loads on their infrastructure, not yours.

5
Document and escalate if confirmed malicious

Submit to Microsoft's Defender Submissions portal and block the domain in the tenant's Safe Links exclusion policy.

SafeLinks Policy Configuration for M365 Admins

SafeLinks policy is configured in the Microsoft Defender portal under Email & Collaboration → Policies & Rules → Threat Policies → Safe Links. Key settings to review for each client:

Track user clicks — Enables click logging for security audit trails. Recommended on for any client in a regulated industry.
Let users click through to original URL — Controls whether users can bypass a SafeLinks warning. Disable for high-security environments.
Do not rewrite the following URLs — Exclusion list for trusted internal tools. Keep minimal and review quarterly. This is the most common source of misconfiguration.
Apply real-time URL scanning — Scans URLs not previously known to be malicious at delivery time. Recommended on for all tenants.
MSP Tip Build a standardised SafeLinks policy template for client onboarding. The exclusion list is the most common source of misconfiguration — particularly when clients request their own domain be excluded without understanding the security implications.

Common SafeLinks Issues & Fixes

Marketing email links are getting mangled when copied and shared
When a SafeLinks-wrapped URL is copied from Outlook and pasted elsewhere, recipients see the wrapped version instead of the clean URL. Decode the link before reusing it — the batch decoder handles this at scale. Paste all links, export as CSV, use the clean URLs in your content.
SafeLinks is blocking a legitimate SaaS tool
Add the domain to the tenant's Safe Links exclusion list via the Defender portal. For MSPs managing multiple clients, build this into your onboarding checklist for every new SaaS tool.
Users are clicking "proceed anyway" on every warning
This is a security awareness training failure. Users who habitually bypass warnings undermine the protection entirely. Address in training and consider disabling the "click through" option in policy for high-risk groups like finance and HR.
The SafeLinks URL is truncated and won't decode
SafeLinks URLs are very long — some email clients truncate them when pasted. In Outlook, right-click the link and choose "Copy Link Address" rather than copying from the URL bar or hover text.

Final Thoughts on SafeLinks

Microsoft SafeLinks is a strong security layer inside Microsoft 365. It protects users from phishing attacks and malicious websites using real-time link analysis. Understanding how to decode and verify SafeLinks URLs gives you more control and visibility — and that balance between protection and awareness is what keeps organisations secure.

If your MSP or IT team needs help aligning marketing with cybersecurity positioning, that's exactly the kind of strategic work Opollo specialises in.

Need Help With MSP Marketing?

Opollo helps MSPs and IT providers build marketing programmes that generate consistent, qualified leads.

FAQs

Can SafeLinks protect me from malicious attachments in an email?

While SafeLinks is a powerful tool for scanning URLs, it is specifically designed to protect you from malicious web links. For attachments, Microsoft uses a complementary feature called Safe Attachments. This service opens email attachments in a virtual "sandbox" environment to check for malware or suspicious behavior before the file ever reaches your inbox. To ensure total security, you should ensure both SafeLinks and Safe Attachments are enabled within your Microsoft 365 Defender settings. 

Why do some links in my Outlook remain "clean" while others are rewritten?

Not every link is automatically rewritten by the SafeLinks protocol. There are several reasons why a URL might appear in its original form: 

Internal Domains: Your organization may have whitelisted internal domains or trusted partner sites to reduce latency. 

Organization Settings: IT administrators can define "Do not rewrite" lists for specific trusted URLs. 

Supported Protocols: SafeLinks primarily focuses on HTTP(S) and FTP protocols; other types of links may not be processed. 

Plain Text Emails: In some configurations, SafeLinks only wraps URLs in HTML-formatted emails, leaving plain text messages untouched. 

Does using a SafeLinks decoder bypass my organization’s security?

No, using a decoder tool does not bypass security. When you decode a URL, you are simply revealing the destination address so you can inspect it manually. However, the protection remains active; if you click the original rewritten link, Microsoft will still perform its real-time scan. Decoders are best used for: 

Verify the destination of a link before interacting with it. 

Clean up URLs for use in presentations or professional documentation. 

Checking for "open redirects" that scammers use to hide their true destination. 

Are there any performance downsides to having SafeLinks enabled?

For the vast majority of users, the impact on performance is negligible. However, because SafeLinks must route your request through Microsoft’s verification servers, you may occasionally experience a slight delay (latency) when a page is loading. Additionally, if Microsoft’s reputation service is experiencing an outage, links may take longer to resolve or fail to load entirely. Despite these rare occurrences, the security benefits of real-time protection far outweigh the millisecond delays in page loading. 

How do I report a malicious link that SafeLinks missed?

Security systems are not 100% foolproof, and occasionally a new "zero-day" phishing link might slip through. If you encounter a suspicious link that wasn't blocked, you should: 

Avoid clicking the link or entering any data. 

Use the "Report Message" or "Report Phishing" add-in directly in Outlook. 

Forward the email to your internal IT security team as an attachment. 

Optionally, submit the URL to Microsoft’s Security Intelligence portal to help improve the filter for other users. 

Table of Contents

See how Opollo can help – explore our MSP Marketing & Lead Generation Services

Comments are closed.