SAT - M365 Masked URL Update 06/2026

Updated 3 hours ago by admin

Below are the steps to add our 3 domains, which are now available as Masked URLs within our simulations, to your allowlisting. Please note that these only need to be added within your Defender > Advanced Delivery > Simulation URLs to the Allow section, as described.

Adding these additional URLs assists in preventing false-positive clicks when included in simulations.

Defender Changes

  1. Navigate to https://security.microsoft.com/
  2. Expand the ‘Email & Collaboration’ dropdown.
  3. Select ‘Policies & rules
  4. Select ‘Threat policies
  5. Under ‘Rules’, select ‘Advanced delivery’.
  6. Select the ‘Phishing simulations’ tab.
  7. Click on ‘Edit
  8. Our 'Domains' and 'Sending IPs' should already be populated and are unchanged as part of this update.
  9. Add the 'Simulation URLs to allow' using the information provided below:

Simulation URLs to allow (Masked URL) - those in BOLD are new, and require adding:

*.clouduss.com/*

*.microsoft-notifications.co.uk/*

*.dropbox-notifications.co.uk/*

*.gmaillogin.co.uk/*

*.file-transf3rs.com/*

*.noreply-amazon.co.uk/*

*.hr-staff-updates.com/*

*.e-cards-mail.com/*

  1. Once added, click ‘Save’.


How did we do?