Per my research, Safe Links scans incoming email for known malicious hyperlinks. Scanned URLs are rewritten using the Microsoft standard URL prefix: https://nam01.safelinks.protection.outlook.com. After the link is rewritten, it's analyzed for potentially malicious content.
Please go directly to the Safe Links page at Microsoft 365 Defender portal to check if you have any Safe Links policies will rewrite the scanned url:
Note: To create, modify, and delete Safe Links policies, you need to be a member of the Organization Management or Security Administrator role groups in the Microsoft 365 Defender portal and a member of the Organization Management role group in Exchange Online
However, even if the url is rewritten, we can still access the target source through the rewritten link:
More information for your reference:
If an Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.