Safe Links Protection

Mail systems

Students Teachers Employees

Safe Links protection helps protect users from phishing attacks and malicious websites by checking links not only when an email is delivered, but also every time a user clicks on them. This helps detect threats that may appear after a message has been sent and provides a safer experience when using Microsoft 365.

Overview and Behavior of Safe Links Protection

Safe Links is a feature of Microsoft Defender for Office 365 that protects users from phishing attacks and malicious websites. Links contained in email messages are rewritten when the message is delivered and are re-evaluated each time they are opened. If a link leads to a malicious or fraudulent website, access is blocked and the user is warned.

This protection can detect threats that emerge after a message has been delivered. Attackers may change the content of a target website after sending an email, which is why Safe Links verifies the safety of a link at the moment the user clicks it. As a result, it provides a higher level of protection than traditional link scanning performed only when a message is received.

Users may notice that links in emails appear longer and contain the domain safelinks.protection.outlook.com. This is normal behavior and does not indicate that the message is suspicious or dangerous. These rewritten links are used solely to perform a security check before opening the destination website.

In some cases, particularly in plain text (TXT) emails, the entire rewritten URL may be displayed, starting with something like: https://eur02.safelinks .protection .outlook.com/.... Such URLs typically also contain the original destination address encoded in the url=. Although the link may appear unusual or untrustworthy, it is simply a security modification applied by the Safe Links service. This allows the link to be checked again at the moment the user clicks it.

Safe Links protection is available in school email accounts and in Microsoft Teams. It operates automatically and requires no action from the user. If a link is identified as potentially risky, a warning page is displayed with information about the possible threat. This allows the user to return safely and avoid opening a malicious website.

Author: Ondřej Holý / 14.09.2026 Revision: Jiří Krčmář / 14.09.2026