Hovering over a hyperlink in the "new" outlook doesn't display the actual URL. How can this be remedied.

Anonymous
2024-06-22T00:02:14+00:00

A very dangerous behavior in the new outlook is that hoving the mouse pointer over a hyperlink in an email no longer displays the actual URL of the link.

Seeing the true URL is the #1 way people can avoid getting email scammed. Removing this tool is inviting people to get defrauded. This should not be a default behavior and I cannot see how to resolve this.

Outlook | Windows | New Outlook for Windows | For business

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

99 answers

Sort by: Most helpful
  1. Anonymous
    2024-10-11T19:54:31+00:00

    Same here, update / install of Edge WebView did not help. With all concerns around security these days this one was an amazing miss from the MS team.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-10-11T18:03:57+00:00

    Still no update on this

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-09-13T14:58:53+00:00

    Hi Joshua,

    Interesting. That's unfortunate. Hopefully a more complete solution will appear from Microsoft at some point.

    I did notice one thing, however, and I have no idea if this is related to why it sort of works with some users and not others:

    Emails composed within the new Outlook client and the consumer Hotmail/outlook.com web app will present the link's destination when hovering over it, while emails sent from the old Outlook client will show nothing. This is also the case when you send an HTML-formatted email through an SMTP relay.

    I can see two things from the email source:

    1. Emails composed via the new Outlook client have the "title" attribute set to the link's destination. As such, the hover function just shows the link's title. This is easy to fudge. You could easily have a malicious URL defined in the "href" attribute, which is where the link will take you, and have the Microsoft home page URL in the Title, making it seem the link goes to the Microsoft website when instead it goes elsewhere.
    2. The link rewritten by Safe Links doesn't use the "title" attribute. However, they do add an "originalsrc" attribute. This contains the link's original destination before it was changed to the Safe Links URL. It also seems Microsoft has put some level of protection in place, as an attempt to set this manually in a test didn't work. I assume it's related to the hash values I can see in the source of the email.

    This tells us that if the "Do not rewrite URLs, do checks via Safe Links API only" is enabled, which it is in the default "Built-In protection (Microsoft)" policy, and you see the URL when hovering over links, it could be picking up the title someone has set on the link. This could show that it's working for some emails and not others. In addition, you can whitelist URLs to bypass Safe Links rewrites, and this could also contribute to some emails where the hover function doesn't work, while for other emails, it does.

    The following examples show the difference between the two link hover responses for anyone interested.

    Title hover example.

    Safe Links hover example.

    It's not a complete solution, though. Users who don't use Microsoft Defender for email security and use third-party tools like Proofpoint may run into issues, as those solutions may not be able to present the same hover functionality that Microsoft's Safe Links system provides and have no reasonable path to using Safe Links in such an environment.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-09-09T18:01:57+00:00

    Funny enough, in message edition mode, you see the destination when you hover the link.

    Example, when replying to an email, if you are editing (cursor blinking), the hover works...

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2024-09-09T16:21:48+00:00

    Hi Lee,

    Thank you for the information, however this doesn't quite cover what we're experiencing. We have certain users within the same Microsoft 365 Tenant that are seeing the links, but many who don't. This would seem to imply that it's not based on the policy since all users are receiving the same safe links policy (verified, and it hasn't changed). This still seems to be an issue that Microsoft needs to address in the new version of Microsoft Outlook.

    Was this answer helpful?

    0 comments No comments