How to submit a request to mark my portfolio as safe?

Patrick Li 0 Reputation points
2026-06-26T06:58:09.2533333+00:00

I am hosting a personal design portfolio on a .xyz domain.

I have recently learned that certain companies cannot access my portfolio as microsoft defender is marking my website as suspcious.

My website is simply just a showcase of designs I have created, hosted on vercel.com. How can I request a review of my domain to be marked as safe for viewing and unblock my site from potential hiring managers when viewing my job applications?

I have done some research and many answers lead me to 'https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site', some claiming that this site is what I am looking for but everything on this link says that it is only for reporting unsafe sites, not the reverse.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-26T06:58:32.73+00:00

    To get a personal portfolio site reviewed and marked as safe by Microsoft security systems, use the same submission and dispute channels that are used for false positives and unsafe-site reports, but indicate that the site/file/URL is clean.

    There are three main scenarios where Microsoft might be blocking or warning about the site:

    1. Microsoft Defender SmartScreen / browser warning (Edge, Windows)
      If visitors see a SmartScreen warning page when browsing to the portfolio:
      • On the SmartScreen block page, select Report that this site doesn't contain (malware/phishing) threats under the More information section.
      • Complete and submit the form.
      • Wait for the confirmation email from the SmartScreen Reputation Group.
      • If the issue is urgent, reply to that email to explain that this is a personal portfolio site and request expedited review.
      As the site owner, also reduce the chance of future blocks by:
      • Ensuring the site uses HTTPS with a valid certificate.
      • Avoiding iframes that load unknown third‑party content.
      • Using Content Security Policy (CSP) and other secure response headers.
      • Regularly scanning for webshells, trojans, or suspicious uploads.
      • Maintaining stable domain reputation (avoid frequent hosting/DNS changes).
    2. Microsoft Defender / Microsoft Security Intelligence reputation (URL or file)
      If Defender or another Microsoft security product flags the domain or associated files as suspicious or malicious:
      • Go to the Microsoft Security Intelligence submission site at https://www.microsoft.com/wdsi/filesubmission.
      • Submit the URL or any related file that is being detected.
      • When asked whether the file contains malware, select No if it is being incorrectly identified.
      • Sign in or provide an email address to receive status updates.
      • Note the Submission ID for follow‑up.
      Microsoft will analyze the submission and, if it is determined to be clean, will adjust detections so it is no longer flagged.
    3. Microsoft Defender for Endpoint / Web content filtering in organizations
      Some companies may be blocking the site due to their own Defender for Endpoint web content filtering policies (for example, categorizing .xyz as high‑risk). In that case, only the company’s security/IT admins can change the policy, but they can:
      • Open the Defender portal and go to Reports > Web protection > Web content filtering categories details > Domains.
      • Find the portfolio domain, select the ellipsis () next to it, and choose Dispute Category.
      • Provide details and a suggested category (for example, “Personal sites” or “Business and economy”) and submit.
      • For faster unblocking inside their organization, create a custom allow indicator for the domain.

    If the portfolio URL is also being blocked in email (for example, in job application emails), the receiving organization’s Defender for Office 365 admin can:

    • Use the Submissions page in the Defender portal to report good URLs to Microsoft as false positives.
    • After submission, similar URL variants (for example, different paths or query strings on the same domain) will be allowed without needing separate reports.

    In summary, to request a review and have the portfolio marked as safe:

    • Use the SmartScreen block page link if the warning appears in the browser.
    • Use the Microsoft Security Intelligence submission site to submit the URL or files as clean if Defender is flagging them.
    • Ask affected companies’ IT/security teams to dispute the category or allow the domain in their Defender for Endpoint / Defender for Office 365 policies if the block is due to their internal configuration.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.