Hacker News new | ask | show | jobs
by tallanvor 423 days ago
It seems likely your site had something detected as malware, or is still being detected as malware.

When I test sending a mail to my M365 account with your URL mentioned I find that it gets quarantined (same as if I try to send an email from my M365 account with that URL).

In your M365 test tenant, you should be able to go https://security.microsoft.com/quarantine and see that the emails are getting quarantined, with this information provided as to why:

Detection technologies: URL detonation reputation, Mixed analysis detection

Given that it says "URL detonation reputation" rather than just "URL detonation", that suggests it's using historical information rather than having performed a new test.

This is Microsoft Safe Links functionality - at the very least since you should be able to find the quarantined emails, the headers will contain a correlation ID support can use, although they might not have much power over safe links.

1 comments

Thank you, you've gotten further than I have.

On my "quarantine" I can't find anything (it's empty) therefore I can't also check what's going on. But "URL detonation reputation" is consistent with the behavior we're observing.

Edit: Nevermind, I see that you've already done this.

It might be worth it to pony up for an M365 license or two, send yourself an email, and then open a support ticket inquiring why the email was blocked. I would even avoid mentioning that you are the sender. Just pretend you're a regular customer who receives email from your domain and you're wondering why it was blocked and if there's anything that can be done to stop it from happening.