3 ms·
Yes, I know I've seen someone talk about this before, I think it's their link safety checking thing: https://techcommunity.microsoft.com/t5/security-compliance
by ClassyJacket 3y ago
Yes, I know I've seen someone talk about this before, I think it's their link safety checking thing:
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/safe-links-possibly-triggering-click-to-unsubscribe/m-p/194164 https://techcommunity.microsoft.com/t5/security-compliance-a...
- EvanAnderson 3y agoIt's odd that they're, essentially, fuzzing my app.
- vaporary 3y agoAgreed, it's curious! I wonder if they would still fuzz it if you changed the URL scheme to include the identifier as part of the URL path, rather than as a parameter? e.g., hxxp://example.com/unsubscribe/abcd1234 Please report back if you try it :-)
- procflora 3y agoI could swear I've had that thing burn a one-time token for a password reset email before too, but it's hard to prove as a user. Doesn't feel great!