# Use the submission route when a URL exception must address a high-confidence verdict

> Why can a directly created URL allow entry fail to override malware or high-confidence phishing?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:29+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity
- Reading time: 2 minutes

## What you need to know

Why can a directly created URL allow entry fail to override malware or high-confidence phishing?

## Potentially affected

Microsoft 365 cloud-mailbox URL exceptions in the Tenant Allow/Block List.

## DSE recommendation

Classify the actual filtering verdict before choosing the supported URL false-positive submission route.

## Article

## Source facts

Direct URL allow entries in the Tenant Allow/Block List override bulk, spam, high-confidence spam and ordinary phishing verdicts only. Overriding malware or high-confidence phishing requires the URL submission route with its allow option. An allow entry does not stop Safe Links from wrapping the URL. Separately, at time of click, a URL allow entry overrides all filters associated with that URL entity. Microsoft directs non-Microsoft phishing-simulation URLs to advanced delivery, not this list. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure).

## Applicability

This decision concerns a suspected URL false positive in a cloud-mailbox environment. Keep mail-flow verdict overrides distinct from the documented time-of-click behavior; this is not the workflow for a planned phishing simulation.

## DSE recommendation

Classify the actual filtering verdict before choosing the supported URL false-positive submission route. Have an authorized reviewer establish why the destination is believed clean and retain the relevant message and URL evidence. Do not respond to an ineffective direct entry by creating progressively broader exceptions. Keep the investigation of the verdict distinct from any request to change URL rewriting behavior.

## Verification

Review the entry’s Override verdicts value and whether its details link to a submission. Compare the approved URL with the actual filtered entity and examine appropriate mail-flow evidence for the intended verdict override. Evaluate time-of-click behavior separately rather than using an allowed click to prove the entry’s mail-flow verdict coverage. Retain the decision and a removal or reassessment date; no exception or live click is claimed to have been performed here.

## Official references

[Microsoft Learn: Tenant Allow/Block List URLs](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure). Source reviewed September 9, 2026.

## Primary reference

- Name: Allow or block URLs using the Tenant Allow/Block List - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Use the submission route when a URL exception must address a high-confidence verdict,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
