What are Secure Links?
Secure Links are a filtering mechanism of Hornetsecurity ATP. Secure Links check URLs in incoming emails and only redirect them after a security check. The purpose of Secure Links is to examine URLs in incoming emails for malicious content. The mechanism rewrites the URL in the email so that when the page is opened, the ATP service acts as a web proxy and first checks the target website on various points before users are redirected to the website.
What is rewritten?
The original URL is rewritten. The mechanism rewrites the URL so that the ATP service can act as a web proxy. As soon as a user clicks on a rewritten link in an email, Secure Links checks the website based on Hornetsecurity’s domain and URL intelligence databases. These databases contain billions of phishing and malware records and are continuously expanded.
The structure is as follows:
https://atpscan.global.hornetsecurity.com + generic middle part. When opening the URL, it is scanned and you see the banner of the ATP service:
If the website passes the initial check, Secure Links further examines the website for additional indicators that may pose a threat. These include embedded links to malware or phishing forms. Only if the website passes both checks will the user be redirected to the website. After successfully completing the URL scan, the following is displayed:
Then you will be redirected to the website associated with the link. This process can be very fast, so you may only see the ATP service banner for a fraction of a second.
In some cases, the scan of a URL cannot be completed, and in this case, an appropriate warning is displayed. In this case, the user can click the link by ignoring the warning. This option can be configured by administrators in the Control Panel.
If the scan shows that the website associated with the URL is suspicious, access is denied and the user sees the following:
What can I do with an invalid URL?
In most cases, this is because the Secure Link was altered after being forwarded to another recipient. We recommend opening the original email and opening the Secure Link there. If this error message continues to appear, please contact technical support.
How can I get the original link?
If you want to convert the rewritten URL back to its original state, you can use the Link Decoder.
(Please note that the old URL decoder does not support the new URL rewriting format and therefore can no longer be used.)
How can I create an exception for Secure Links?
If you trust a specific domain, you can define an exception in the Control Panel so that the links in the emails are no longer rewritten. For more information, see: Creating an allowlist entry for links on a domain level