Safe Links Rewriting URLs in My Emails? How It Breaks Tracking
Stop losing tracking data. Learn how Safe Links rewriting affects email tracking and how to verify links before send to ensure accuracy and.
Why Does Safe Links Rewrite URLs in My Emails?
You click a link in your inbox, and suddenly it’s not going where you expected. Instead of landing on your campaign’s landing page, you’re routed through a long, strange URL like safelinks.protection.outlook.com. You’re not alone. This is Safe Links in action—Microsoft 365’s built-in security layer, silently rewriting every link in your email.
It’s meant to keep users safe, but the trade-off is real: tracking systems that depend on the original URL structure break. If your analytics rely on UTM parameters or custom domains, you’re losing visibility. This is why Safe Links rewriting URLs in your emails affects tracking—not because of misconfiguration, but because of how it’s designed to work.
Key takeaways
- Safe Links rewrites URLs to route them through a security proxy at safelinks.protection.outlook.com.
- Safe Links is enabled by default in Microsoft 365 organizations using Exchange Online Protection or Defender for Office 365.
- Tracking systems relying on original URL structure—like UTM parameters or custom domains—fail when links are rewritten.
How Safe Links Rewriting Breaks Email Tracking
You can’t track clicks accurately when Safe Links rewrites URLs in your emails. It strips UTM parameters, replaces your domain with safelinks.protection.outlook.com, and breaks attribution. As a result, your analytics tools can’t tell which link was clicked or whether the click came from a specific campaign. The data in your dashboards becomes unreliable.
Why UTM Parameters and Custom Subdomains Fail
Most email tracking relies on UTM parameters or branded subdomains to tag links. When a user clicks, your analytics platform records the source, medium, campaign, and more. But once Safe Links rewrites the URL, those tags are gone. The final destination is no longer your original link — it's a proxy redirect, and the original query string is stripped.
For example, a link like https://yourcompany.com/offer?utm_source=email&utm_campaign=summer2024 becomes https://safelinks.protection.outlook.com/...?url=... — all tracking parameters lost. This isn't just a minor glitch; it breaks the entire attribution chain.
Consequences for Campaign Performance and Reporting
Without working tracking, your click-through rate (CTR) in platforms like Google Analytics or HubSpot appears artificially low. You might think your email didn’t perform well — when in reality, people clicked, but the system couldn’t record it.
Conversion tracking suffers similarly. If someone clicks a link in an email and later makes a purchase, the system can't match that action to the original campaign. This creates blind spots in revenue attribution and makes it hard to assess campaign ROI.
Even worse, if you're using multiple email channels — like newsletters, transactional messages, and automated workflows — Safe Links makes it impossible to tell which source drove the most engagement. The signal becomes noise.
Microsoft’s documentation confirms that Safe Links modifies URLs for security: Microsoft describes Safe Links as a security feature that redirects links through a proxy to scan for malware. While this protects users, it comes at the cost of tracking integrity.
If you rely on click data for optimizing emails, testing subject lines, or justifying send frequency, you need to verify that links in your emails remain intact. That’s why you should test links in real inboxes before sending — and verify your list to catch issues early.
Use MailTester’s inbox placement testing to check how your emails render in real user inboxes across Outlook, Gmail, and others. Or use the bulk verification tool to clean your list and prevent tracking issues before they happen.
What Does `safelinks.protection.outlook.com` Mean for Your Links?
When you send an email through Microsoft 365, any link you include may be rewritten to pass through safelinks.protection.outlook.com. This redirects the click through Microsoft’s security system, hiding the real destination in an encoded parameter. Unless you’re using Microsoft’s own tracking or backend tools, that original URL remains invisible to third-party analytics — meaning your click tracking will fail unless you account for Safe Links rewriting.
How Safe Links Rewrites URLs in Practice
Let’s say you send a link like https://example.com/signup. In the recipient’s email client, it might appear as https://safelinks.protection.outlook.com/p/something. The original URL is preserved in a query parameter Microsoft’s backend can decode, but it isn’t visible to the user or most tracking scripts. If you rely on tools that read the visible URL only, they’ll record a click on a Microsoft domain, not your actual landing page.
This rewrite is automatic for any email sent via Microsoft 365 when Safe Links is enabled — which it is by default in most enterprise plans. The change is enforced at the mail gateway, so even if you use a custom domain as a link shortener, it still gets rewritten if the recipient uses a Microsoft email address.
Why This Breaks Traditional Tracking
Most email marketing and analytics tools parse the visible URL to count clicks and associate them with a campaign. When that URL is rewritten, they register a click on safelinks.protection.outlook.com — a black hole for data. You’ll see the click, but not where it actually led. This makes attribution nearly impossible without special handling.
Only Microsoft’s backend systems can decode the full chain. Third-party tools have no access to the original URL unless they integrate directly with Microsoft’s API or use specific techniques to reassemble the link using its internal structure. This is why you might see 1,000 clicks in your analytics dashboard but zero conversions — your data is distorted by an invisible rewrite.
The safest approach? Pre-validate your links and test deliveries before sending. Use tools that simulate the full delivery path, including Safe Links rewriting, to catch broken or untrackable URLs. MailTester’s inbox placement testing ensures your links behave as expected in real-world environments, including Microsoft 365: test your email in Outlook and other clients.
Safe Links Rewriting: Not Just a Tracking Problem
When Microsoft’s Safe Links rewrites URLs in your email, it doesn't just break tracking—it can derail A/B testing, scramble deep links for mobile apps, and break custom shorteners or branded domains. The result? Broken user journeys, lost conversions, and a damaged brand experience. This isn’t just about seeing clicks; it’s about delivering the right content, where and when it matters.
Tracking is only the tip of the iceberg
Let’s be clear: Safe Links rewriting affects more than just your analytics. If you’re running A/B tests to compare subject lines, CTAs, or layout variations, rewritten URLs can skew results. The same link, altered by Safe Links, may be counted as two separate destinations—making your test data unreliable.
Even if you’re not tracking, the underlying mechanics matter. Many mobile apps use deep links with specific paths—like app.yourcompany.com/checkout?ref=345—to pass session data or trigger in-app actions. Safe Links often strips or alters these paths, dropping parameters and sending users to a generic homepage instead. This breaks functionality, especially on iOS and Android apps that rely on precise URLs.
Short links and custom domains don’t survive unscathed
If you use Bitly, Rebrandly, or a custom domain like app.yourcompany.com, Safe Links may rewrite them into formats that don’t resolve correctly. In some cases, the rewritten URL points directly to a Microsoft-hosted sandbox instead of your intended destination. Users see 404s, redirect loops, or blank pages—no matter how strong your campaign was.
This isn’t just a technical glitch. It damages trust. When a user clicks a “Download Now” button and gets a broken page, they assume the vendor is careless or unreliable. That perception can last long after the technical fix is deployed.
Microsoft’s Safe Links is designed to protect; it’s not meant to break functionality. But without proper verification, it’s easy to ship emails with links that are technically valid but broken in practice. You can’t rely on a spam filter to preserve user experience. That’s why you need to test how your links behave in real-world conditions.
With MailTester’s inbox placement testing, you can simulate real-world email delivery—including Safe Links rewriting—before you send. Test links on Microsoft Outlook, Gmail, and mobile devices to catch issues early. It’s not just about deliverability—it’s about ensuring your message arrives intact.
Try inbox placement testing with MailTester to see how Safe Links affects your campaign, and fix problems before they hit your audience.
How to Check if Safe Links is Rewriting Your Links
If you're sending emails through Outlook or Exchange, your links might be rewritten by Microsoft’s Safe Links service. To check, send a test email to an Outlook account, click the link while logged in, and confirm if the final destination starts with https://safelinks.protection.outlook.com. If it does, tracking via the original URL will fail. You can also preview your email in a real inbox environment using tools like MailTester’s inbox-placement testing.
Step-by-step verification process
- Send a test email to a real Outlook or Exchange account. Use a personal address or a test mailbox configured with Microsoft 365. This ensures the Safe Links service is active and can intercept links.
- Log into that account and click the link. Do not right-click or copy the URL—click it directly. Pay attention to the browser’s address bar after the redirect.
- Check the final URL in your browser. If it begins with
https://safelinks.protection.outlook.com, Safe Links has rewritten it. The original destination is hidden behind a proxy, breaking most tracking mechanisms that rely on the original URL path. - Verify what’s being rewritten. You can use MailTester’s inbox-placement tester to simulate how your message appears in a real Outlook inbox and see how links transform before delivery.
Why this happens and what to do about it
Safe Links is designed to protect users by scanning URLs in real time before they reach the destination. It’s a standard security feature in Microsoft 365 and common in enterprise email systems. While effective against malicious links, it can break UTM parameters, pixel tracking, and link analytics. This occurs because the rewritten URL replaces the original link entirely.
According to the Microsoft Learn documentation, Safe Links processes URLs in the background, even when the link appears intact in the email body. The redirection is transparent to users but opaque to tracking systems.
For accurate tracking, ensure your email service provider supports link untracking or allows you to insert links in a way that survives safe redirection—such as using a dedicated tracking domain or using a real-time verification API like MailTester’s Email API to validate links before sending. You can also test link behavior across multiple inboxes using MailTester’s bulk verification tools.
When Safe Links Rewriting Hurts Deliverability and Sender Reputation
Safe Links rewriting can hurt deliverability and sender reputation when rewritten URLs lead users to broken or malicious pages, even if the original email was clean. Microsoft’s backend can record those negative interactions and use them to flag your sending domain—especially at scale. If many users click rewritten links that fail or trigger security alerts, your sender reputation may degrade over time, even without any malicious intent.
How rewired links create indirect risk
When Microsoft rewrites links in your email, it inserts a proxy layer to check for threats. If that proxy redirects to a bad or dead endpoint—whether due to a misconfigured link, a time-limited URL, or a third-party service outage—the user experience suffers. A failed redirect or a phishing-like warning can trigger a negative signal in Microsoft’s systems, which may be logged against your sending domain.
Let’s be clear: this isn’t about the original email content. Even if your message passes all spam checks and is fully compliant, repeated negative behaviors from Safe Links redirects can still impact your sender reputation. You’re not at fault for the destination, but your domain may be flagged anyway.
Why third-party tools amplify the risk
Many email tools don’t account for Safe Links rewriting during link tracking. If you're using a platform that tracks clicks based on the original URL instead of the rewritten one, you’ll get mismatched data. You may see "high click rates" on links that never actually delivered users to the intended destination—not because of poor content, but because Safe Links rewrote and failed the path.
Over time, this leads to misleading analytics and higher bounce or dropout rates, which mail filters interpret as poor sender quality. In high-volume campaigns, even small failure rates from rewritten links can compound into measurable reputational damage. Microsoft’s own guidelines stress that sender reputation is based on user engagement and security signals—including redirects gone wrong—even if the original email is clean.
It’s not just about avoiding one bad link. It’s about preventing predictable failures in the email delivery chain. You can’t control every endpoint a rewritten link hits, but you can reduce exposure by verifying your URLs before sending. Check every destination in your campaign using a tool like inbox placement testing or bulk verification to catch broken or high-risk URLs early.
For developers and teams, integrating real-time verification into your send flow ensures that every link, especially those that will be rewritten, is safe and functional. This isn’t just about deliverability—it’s about maintaining trust in your sending identity.
How to Verify Links and Test Tracking Before Sending
You can verify links and test tracking before sending by using real-time inbox placement tools like MailTester. These tools simulate how your email appears in live inboxes across major providers—including Microsoft 365—showing whether Safe Links is rewriting your URLs, if the final destination is reachable, and whether the link structure remains secure. This stops tracking failures before they hit your recipients.
Simulate Real-World Delivery Conditions
Before sending, let’s simulate the actual delivery path. Safe Links rewriting is common in enterprise email environments, especially with Microsoft 365. It rewrites your original URLs into a proxy format (e.g., https://link.protection.outlook.com/...) to scan for threats. This can break tracking pixels, UTM parameters, and redirect logic if not accounted for.
MailTester’s inbox placement test mimics delivery through real providers. It checks how links transform in transit and whether the final redirect resolves correctly—no guesswork. If the link fails to resolve or the destination is insecure, you get a clear alert. This includes detecting if a rewritten URL leads to a blocked or compromised site.
Use AI-Powered Analysis to Catch Hidden Issues
Link rewriting isn’t always obvious. The final URL might look valid, but broken UTM tags or missing tracking parameters can still sink your campaign performance. MailTester’s in-app AI assistant analyzes the full link structure post-rewrite and flags inconsistencies—like missing parameters, redirects to known bad domains, or redirects that exceed 3 hops.
This is especially important for marketers relying on third-party tools that don’t expect Safe Links interference. A link that works in a test email might fail in a corporate inbox. Using MailTester’s inbox tester before sending reveals these issues early.
For teams managing large lists, automate this check with the real-time verification API or bulk verify entire lists before sending. You get results fast—valid, invalid, catch-all, or risky—and the tool identifies if links are being rewritten or if destinations are unreachable.
According to the IETF’s standards for email encryption and routing, endpoint integrity during delivery is a known challenge. Tools that validate delivery behavior in real environments help mitigate it. MailTester gives you control over this part of the process, not just data about the list.
Best Practices to Mitigate Safe Links Rewriting
Safe Links rewrites tracking URLs in Microsoft 365 emails, which can break your analytics and hurt campaign performance. To prevent this, use a dedicated, clean tracking domain (like tracking.yourcompany.com), ensure it’s properly secured with SPF, DKIM, and DMARC, and test links in real M365 inboxes before large sends. Avoid overloading high-value links with UTM parameters that Safe Links may strip. Use tools that simulate real user behavior to catch rewriting issues early.
Design Your Tracking Infrastructure for Resilience
- Use a dedicated domain for tracking (e.g., tracking.yourcompany.com) to make rewritten versions easy to identify and distinguish from original links.
- Set up SPF, DKIM, and DMARC records for your tracking domain to ensure it’s recognized as reputable and reduce the risk of being flagged or rewritten in transit.
- Test your tracking domain’s deliverability and alignment with Microsoft’s email standards using inbox placement tools like MailTester's Inbox Tester to see how links behave in real M365 environments.
Optimize Link Structure for Compatibility
- Avoid embedding complex UTM parameters in high-value links (like sign-up or purchase buttons) that are likely to be rewritten or stripped by Safe Links.
- Keep tracking links as short and clean as possible—long, convoluted URLs are more likely to be modified or broken during rewriting.
- Verify your tracking logic works after rewriting by simulating email delivery using tools that mirror how Safe Links processes links in live mailboxes.
- Test links manually in Microsoft 365 inboxes using real user accounts, not just preview tools—some rewriting behavior only surfaces in actual client rendering.
Even a single rewritten tracking URL can distort conversion data. Consistency and validation are key.
Microsoft’s Safe Links operates by modifying URLs in real-time for security. While it protects users, it can interfere with tracking. If you use multiple domains or inconsistent structures, rewriting becomes harder to track. Standardizing on a single, verified tracking domain simplifies troubleshooting and maintains data integrity.
For developers and marketers, consider using a verification API to ensure tracking links remain valid and deliverable across platforms. MailTester’s real-time API checks individual links for deliverability and security risks before they go live.
For large campaigns, run a full inbox placement test with tools that reproduce real-world client environments. MailTester’s inbox tester checks how links appear across major email clients—including M365—with Safe Links enabled to catch rewriting issues before send.
Final note: Safe Links is designed to protect, not disrupt. By building your tracking stack with it in mind, you avoid surprises and maintain reliable campaign data.
Alternative: Letting Safe Links Run (and Accepting the Trade-Off)
Letting Microsoft’s Safe Links rewrite your URLs means giving up precise click tracking in email platforms—but if your priority is endpoint security over granular analytics, it’s a valid trade-off. You’ll lose visibility into which links users actually clicked, but you can still measure engagement through broader metrics and post-click tracking methods that survive URL rewriting.
Focus on Aggregate Metrics and Backend Data
When Safe Links rewrites every URL, standard tracking tags (like UTM parameters) get stripped or altered. You can’t rely on email service provider analytics to tell you which link drove the most engagement. Instead, shift your focus to aggregate metrics: open rates, total clicks, and conversion paths tracked via backend systems. This approach works well for high-level campaign analysis but limits your ability to A/B test specific button or CTA performance.
For instance, an email with a single call-to-action can still be evaluated by comparing overall conversions in your CRM or web analytics platform—even if the internal link was rewritten. This is especially useful for campaigns where the final outcome (e.g., form submission, purchase) happens on a landing page, not inside the email.
Use Post-Click Tracking for Reliable Conversion Insights
Since rewritten URLs can’t carry tracking parameters reliably, shift to post-click tracking. Tools like Google Analytics with campaign tags that persist after redirection, or server-side tracking via JavaScript pixels loaded on the destination page, can capture user behavior accurately. These methods don’t rely on the original email link structure—they detect activity after the click is confirmed.
For example, a pixel fired on a landing page confirms a user reached the page and can log additional actions like form fills or time spent. This approach is more resilient than pre-click tracking, especially in environments with strict safety gates like Safe Links. It aligns with industry standards: the [IAB Tech Lab’s Digital Measurement Guidelines](https://www.iab.com/) recommend layered tracking approaches to account for such disruptions.
It also means you can continue verifying email lists to avoid sending to invalid or risky addresses. Poor list hygiene increases the chance of false positives in analytics and harms sender reputation. Using a service like MailTester’s bulk verification ensures you’re only sending to valid, deliverable addresses, reducing the risk of your email being flagged—even when Safe Links is active.
Ultimately, accepting URL rewriting means accepting a less granular view of engagement. But by combining backend analytics with post-click tracking, you retain meaningful data without compromising security. It’s not about perfect tracking—it’s about reliable, actionable insight.
How MailTester Helps You Stay Ahead of Safe Links Issues
Safe Links in Microsoft 365 can rewrite URLs in real time, breaking tracking and altering user journeys. MailTester’s inbox-placement testing includes Safe Links-aware previewing, simulating how your links appear in actual M365 mail clients before you send.
Unlike tools that only check link syntax, MailTester validates URLs at the final destination, uncovering issues caused by redirects, broken links, or Safe Links modifications that might otherwise go unnoticed.
With 98.9% accuracy, it flags links that will be rewritten, broken, or unsafe before you send—ensuring your campaigns reach users as intended. Start with 100 free verifications, and keep unused credits forever, so you can test at scale without expiry pressure.
Keep reading
- Deliverability monitoring, metrics and reporting (complete guide)
- Why Transactional Emails Get Forwarded to Spam Reports
- How to Measure Engagement Signals ISPs See in 2026
- Mimecast URL Protect Link Rewriting and Click Tracking Impact 2026
- ESP Reports Delivered While Emails Sit in Spam Explained
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Does Safe Links rewrite all URLs in emails?
Yes, Safe Links rewrites all public URLs in emails sent through Microsoft 365 services, unless excluded through policies or URL exclusions.
Can I disable Safe Links rewriting for specific links?
Yes, organizations can configure Safe Links exclusions for specific domains or URLs. This is not available in standard user accounts.
Is Safe Links rewriting safe for marketing links?
It’s technically safe but breaks tracking and can interfere with landing page logic. Use it only if you don’t rely on per-link analytics.
Why do my click-through rates look lower after sending through Outlook?
Because Safe Links rewrites URLs, making tracking systems unable to capture the actual clicks. This leads to underreported CTRs.
How can I test if Safe Links is rewriting my campaign links?
Send a test email to a Microsoft 365 inbox and check the final URL in the browser after clicking. Use MailTester’s inbox-placement test for automated simulation.
Can Safe Links affect my sender reputation?
Indirectly. If rewritten links lead to poor user experiences (e.g. dead ends, malware), Microsoft may flag the sender, especially at scale.
Does Safe Links rewrite links in mobile Outlook apps?
Yes. The rewrite applies across all devices and clients, including mobile Outlook and the web version.
Are there tools that detect Safe Links rewriting automatically?
Yes, tools like MailTester offer inbox-placement testing that simulates Microsoft’s Safe Links behavior and shows rewritten URLs before sending.
What’s the difference between Safe Links and spam filters?
Safe Links inspects URLs after send and redirects through a security proxy. Spam filters block the email before delivery based on sender reputation or content.
Can I use a custom tracking domain with Safe Links?
Yes, but the original domain must be allowed in Safe Links policies. Otherwise, it may still be rewritten or blocked.