Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
If the site is still blocked after submitting Report that this site doesn't contain (malware/phishing) threats and waiting two weeks, use the next escalation paths that are documented for false positives:
- Submit the site through the WDSI file submission portal: https://www.microsoft.com/en-us/wdsi/filesubmission
- This is specifically listed as a way to report a site that was incorrectly blocked.
- Include the blocked URL and details showing why the site is safe.
- If the block is being shown in Microsoft Edge, use the false-positive reporting link on the Edge block page.
- Microsoft documents this as the way to report sites deemed dangerous by SmartScreen.
- If the block is coming from Microsoft Defender for Endpoint Web Content Filtering, an administrator can review the blocked domain in the Defender portal and:
- go to the Domains tab of the WCF reports,
- select the ellipsis next to the domain,
- choose Dispute Category,
- set the priority and provide the suggested category and details.
- If the original SmartScreen report has already generated a confirmation message from the SmartScreen Reputation Group, reply to that message to present the urgency and request follow-up. Microsoft documents this as the path when the issue is urgent or a response is needed after investigation.
To reduce the chance of the site being blocked again, Microsoft recommends:
- enabling HTTPS with a valid certificate,
- blocking iframes from loading unknown third-party content,
- using Content Security Policy (CSP) and other secure response headers,
- regularly scanning for web shells, trojans, and suspicious uploaded files,
- avoiding frequent hosting or DNS changes that can affect domain reputation.