Are Pipedream Webhook and Cancel/Resume Links Being Marked as Malicious in Outlook?

This topic was automatically generated from Slack. You can find the original thread here.

Hi everyone, is anyone getting Pipedream Webhook and Cancel/Resume links being marked as malicious? I am emailing some of them, and Outlook recipients are getting a warning that the link is malicious.

I’m not able to reproduce in Google / GSuite, on a work or a personal email address. Do you have a screenshot of the exact message?

or the full text?

Yes let me get some screenshots

This was sent by one of the users that receive an email with the link

got it, I was testing the actual [api.pipedream.com](http://api.pipedream.com) links since you said you were sending out the cancel / resume links, but that looks like a workflow HTTP endpoint.

Are you seeing this only on HTTP endpoint URLs (m.pipedream.net), or also api.pipedream.com links?

and are you seeing this on multiple m.pipedream.net URLs or just this one?

Ahh yep - I got confused as that endpoint I sent actually triggers cancel/resume URLs, apologies. The only link I see this happening on is m.pipedream.net, and it is occurring on the one URL that is sent in the email template with different query string params.

got it. These issues can be notoriously difficult for us to troubleshoot, but the best thing we’ve found is for your customer to try to submit the false positive: Address false positives/negatives in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn

you may be able to do that directly, too: How to report false positives or false negatives following automated investigation in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn