Microsoft spam filter flags URL to legit business web site as malware for no discernible reason

Vidar Grøtte 1 Reputation point
2021-09-02T14:16:25.263+00:00

Since mid July, Microsoft's spam-filter has been blocking all e-mails containing the URL to our company web site, but ONLY when the URL includes the 'www' part. References to the main domain work perfectly fine. This happens regardless of who the sender is, and the reason is given as 'anti-malware protection'.

We do know that the SSL certificate for our web site was incorrectly configured for the www variant of the URL for a while, but this was fixed on August 16th. We have since reviewed configuration and submitted the affected URL as a false positive through Microsoft 365 admin center several times, but the system still insists the URL should have been blocked. Again, the naked domain leading to the exact same content is accepted without a hitch.

Office 365 support, our web hosting company, and several IT consultants have been unable to identify a reason. Other systems we have tried, scan our web site as low risk and perfectly OK.

Can someone with insight in Microsofts spam filter find the concrete reason why the URL is blocked, so we can remedy whatever fault remains on our web site?
Could the URL still be affected by some sort of override/quarantine due to earlier certificate issues, and if so, how long it will last?

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,349 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Yassine AYOUBI 1 Reputation point
    2022-07-30T12:46:38.02+00:00

    Hello,

    Did you resolve this issue ? We have the same problem and there's three tickets opened at Microsoft O365 support.

    They didn't find and don't understand why our URL is balcklisted and quarantined.

    Thanks in advance for you reply.

    Have a great day.

    0 comments No comments

  2. Yassine AYOUBI 1 Reputation point
    2022-07-30T12:46:55.76+00:00

    Hello,

    Did you resolve this issue ? We have the same problem and there's three tickets opened at Microsoft O365 support.

    They didn't find and don't understand why our URL is balcklisted and quarantined.

    Thanks in advance for you reply.

    Have a great day.

    0 comments No comments

  3. Vidar Grøtte 1 Reputation point
    2022-08-01T08:56:37.967+00:00

    Ultimately, web server configuration and/or site content was the issue, but it took some time to figure things out since Microsoft support cannot see the exact reason for the flagging.
    We tried many different things, and the problem seemingly resolved on its own some time after our actions. This means we were unable to pinpoint one specific cause, but here's a description and some pointers that I hope can be helpful.

    • We started by looking at our email setup, and actually fixed some potential issues with rDNS and activated DKIM. No immediate result.
    • One important element turned out to be a misconfiguration on the web server, causing the wrong SSL certificate to be served when we included www in the URL. After our web hosting company remedied this, e-mails started to be classified as malware rather than phishing, but were still blocked.
    • The following days we also cleared out some outdated references and links from our web site and changed occurences of http to https or relative URLs to avoid mixed content.
    • Around 3 weeks after the certificate issue was remedied, e-mails with 'www' links suddenly started going through again, and we could only assume that some time was required for the O365 spam filter to refresh cached information or see improved reputation.

    These may be helpful resources to check your domain:
    MX Toolbox
    Sucuri site checker
    DNS blacklist lookup