Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
Microsoft Defender SmartScreen and related web protection features support two main ways to address a false positive classification such as a legitimate site being treated as unsafe, malicious, or otherwise blocked:
- Use the built-in “report” link on the SmartScreen block page
- When Microsoft Edge or Defender web protection blocks or warns on a site, the block page includes a link to report that the site is safe or that the block is a mistake.
- Use that link from an affected client to submit rickscohen.com as a false positive. This sends the URL, current classification, and user feedback directly to the SmartScreen service for review.
- This is the recommended path for SmartScreen URL reputation issues, including misclassification of active sites.
- Submit a false positive through Defender/Defender for Endpoint workflows
- For organizations using Microsoft Defender for Endpoint web protection or Web Content Filtering (WCF), admins can:
- Navigate to Reports > Web protection > Web content filtering categories details > Domains in the Microsoft Defender portal.
- Locate the domain (rickscohen.com) in the domains list.
- Select the ellipsis (…) next to the domain and choose Dispute Category.
- Provide details (priority, suggested category, and justification) and submit. The request is reviewed, typically within one business day.
- As an immediate workaround while the dispute is processed, admins can create a custom allow indicator for the domain so that users can access the site even before reclassification is complete. This is done via Defender for Endpoint indicators for IPs and URLs/domains.
- For organizations using Microsoft Defender for Endpoint web protection or Web Content Filtering (WCF), admins can:
- General SmartScreen false-positive handling
- SmartScreen determines whether a site is potentially malicious or unsafe by checking URL reputation, page content, file behavior, TLS security, user feedback, and dynamic behavior. If these signals incorrectly classify a legitimate site, the false-positive reporting mechanisms above are the supported way to request correction.
- For file or download-related SmartScreen false positives, Microsoft provides a dedicated file submission portal, but for a pure URL/domain reputation issue like rickscohen.com, the URL reporting and WCF dispute mechanisms are the appropriate channels.
In summary, to have rickscohen.com reclassified as a safe, active website:
- Use the “report this site” link on the SmartScreen/Edge block page from an affected client.
- If using Defender for Endpoint, open a Web Content Filtering domain dispute and optionally add an allow indicator for rickscohen.com so users are unblocked while the review completes.
References: