SAT - M365 Masked URL Update 06/2026
Below are the steps to add our 3 domains, which are now available as Masked URLs within our simulations, to your allowlisting. Please note that these only need to be added within your Defender > Advanced Delivery > Simulation URLs to the Allow section, as described.
Adding these additional URLs assists in preventing false-positive clicks when included in simulations.
Defender Changes
- Navigate to https://security.microsoft.com/
- Expand the ‘Email & Collaboration’ dropdown.
- Select ‘Policies & rules’
- Select ‘Threat policies’
- Under ‘Rules’, select ‘Advanced delivery’.
- Select the ‘Phishing simulations’ tab.
- Click on ‘Edit’
- Our 'Domains' and 'Sending IPs' should already be populated and are unchanged as part of this update.
- Add the 'Simulation URLs to allow' using the information provided below:
- Simulation URLs to allow (Masked URL) - those in BOLD are new, and require adding:
*.clouduss.com/*
*.microsoft-notifications.co.uk/*
*.dropbox-notifications.co.uk/*
*.gmaillogin.co.uk/*
*.file-transf3rs.com/*
*.noreply-amazon.co.uk/*
*.hr-staff-updates.com/*
*.e-cards-mail.com/*
- Once added, click ‘Save’.