URL Defense is Proofpoint's click-time protection feature that rewrites URLs in emails and analyzes link destinations in real-time when users click them. This protects against malicious links that may have been safe when delivered but became dangerous later.
Prerequisites
Before configuring URL Defense, ensure you have:
- Administrator access to the Proofpoint Essentials console
- URL Defense feature included in your Proofpoint subscription
- Understanding of trusted domains that may need exclusions
- Communication plan to inform users about rewritten links
How URL Defense Works
When URL Defense is enabled:
- Email Arrival: Proofpoint scans incoming emails for URLs
- URL Rewriting: All URLs are rewritten to Proofpoint's format
- User Click: When a user clicks a link, the request goes to Proofpoint
- Real-Time Analysis: Proofpoint analyzes the destination for threats
- Access Decision: Safe links proceed; malicious links are blocked
Rewritten URL Format:
Original: https://example.com/page
Rewritten: https://urldefense.proofpoint.com/v2/url?u=https-3A__example.com_page&d=...
Step 1: Enable URL Defense
Check Feature Availability
- Log in to the Proofpoint Essentials Admin Console
- Navigate to Administration > Account Management
- Click Features
- Look for URL Defense in the feature list
- If not visible, contact your Proofpoint account manager
Enable the Feature
- In Account Management > Features
- Locate the Enable URL Defense checkbox
- Check the box to enable the feature
- Click Save to apply changes
Note: Changes may take up to 15-30 minutes to propagate across all Proofpoint servers.
Step 2: Access URL Defense Settings
Once enabled, configure URL Defense settings:
- Navigate to Security Settings in the left sidebar
- Expand Malicious Content (or Targeted Attack Protection)
- Click URL Defense
You'll see the following configuration options:
| Setting | Description |
|---|---|
| URL Rewriting | Enable/disable URL rewriting |
| Domain Exclusions | Domains to skip rewriting |
| Sender Exclusions | Senders whose emails skip rewriting |
| Block Page Settings | Customize the warning page |
Step 3: Configure URL Rewriting Options
Standard URL Rewriting
The default configuration rewrites all URLs in inbound emails:
- Ensure Enable URL Rewriting is checked
- Select Rewrite all URLs for maximum protection
- Click Save
Selective Rewriting (Advanced)
For organizations needing granular control:
- Choose Rewrite URLs selectively
- Configure which URLs to rewrite based on:
- URL risk score
- Email spam score
- Sender reputation
Step 4: Configure Domain Exclusions
Some URLs shouldn't be rewritten. Add exclusions for:
- Internal application links
- Trusted business partner domains
- SSO or authentication portals
- Known SaaS applications that break with rewritten URLs
Add Domain Exclusions
- In URL Defense settings, find Exclude URLs that contain specified domains/IP addresses
- Click Add or enter domains in the text area
- Enter domains one per line:
internal.yourcompany.com
trustedpartner.com
saas-app.com
- Click Save
Warning: Be cautious when excluding domains. Excluded URLs bypass click-time protection entirely.
Step 5: Configure Sender Exclusions
Exclude specific senders from URL rewriting:
- Find Exclude rewriting emails sent by specified senders
- Enter sender email addresses or domains:
[email protected]
*@internal-alerts.yourcompany.com
- Click Save
When to Use Sender Exclusions
| Sender Type | Reason for Exclusion |
|---|---|
| Internal systems | Automated alerts with internal URLs |
| Trusted partners | Business-critical communications |
| SaaS notifications | Application links that require original URLs |
Step 6: Customize the Block Page
When Proofpoint blocks a malicious URL, users see a warning page. Customize it to match your organization:
- Navigate to Block Page Settings (if available)
- Configure:
- Organization logo
- Custom warning message
- Contact information for IT support
- Click Save
Sample Block Page Message
The link you clicked has been identified as potentially malicious.
This page may attempt to steal your credentials or install malware.
If you believe this is an error, please contact the IT Help Desk:
[email protected] | Ext. 4357
Step 7: Test URL Defense
Verify URL Defense is working correctly:
Test URL Rewriting
- Send a test email containing a URL to a protected user
- Open the email and inspect the link
- Verify the URL has been rewritten to
urldefense.proofpoint.com - Click the link and confirm it resolves correctly
Test Malicious URL Blocking
Proofpoint provides safe test URLs:
- Send an email containing Proofpoint's test URL (contact support for current test URLs)
- Click the link in the delivered email
- Verify the block page appears
- Confirm the warning message displays correctly
Step 8: Monitor URL Defense Activity
View URL Click Reports
- Navigate to Reports in the admin console
- Select URL Defense or Targeted Attack Protection
- Review metrics:
- Total URLs analyzed
- URLs blocked
- Most clicked URLs
- Top targeted users
Investigate Blocked URLs
- Go to Logs > Log Search
- Filter for URL Defense events
- Review blocked URL details:
- Original URL
- Reason for blocking
- User who clicked
- Timestamp
Troubleshooting URL Defense Issues
Links Not Being Rewritten
Symptoms: URLs appear in original format, not Proofpoint format.
Solutions:
- Verify URL Defense is enabled in Features
- Check if the sender is on an exclusion list
- Check if the domain is excluded
- Wait 30 minutes for settings to propagate
- Contact Proofpoint support if issues persist
Legitimate Sites Being Blocked
Symptoms: Safe websites trigger the Proofpoint block page.
Solutions:
- Note the exact URL being blocked
- Check the block reason in the URL Defense log
- Submit the URL to Proofpoint for review
- Temporarily add to exclusion list if urgent
- Follow up to ensure false positive is resolved
Broken Links After Rewriting
Symptoms: URLs don't work after being rewritten by Proofpoint.
Solutions:
- Identify the problematic domain
- Check if URL encoding is causing issues
- Add the domain to exclusions if necessary
- Report to Proofpoint for investigation
Users Complaining About Slow Links
Symptoms: Users report delays when clicking links.
Solutions:
- This is normal (1-3 second analysis time)
- Educate users about the security benefit
- Check Proofpoint service status for outages
- Review network connectivity to Proofpoint servers
Best Practices for URL Defense
- Start with full protection - Enable for all URLs, then add exclusions as needed
- Minimize exclusions - Each exclusion creates a potential security gap
- Document exclusions - Keep a record of why each exclusion was added
- Review exclusions quarterly - Remove exclusions that are no longer needed
- Train users - Explain why links look different and what block pages mean
- Monitor reports - Review URL Defense reports weekly for threats
Understanding URL Defense Reports
| Metric | What It Shows |
|---|---|
| Total Clicks | All links clicked by users |
| Permitted Clicks | Safe links allowed through |
| Blocked Clicks | Malicious links stopped |
| Time-of-Click Threats | Links that became malicious after delivery |
| Top Targeted Users | Users clicking the most risky links |
Communicating URL Defense to Users
Send a notification to users explaining the feature:
Subject: Important Update to Email Link Protection
We've enabled enhanced link protection for all incoming emails. You'll notice that links in emails now show a different format (urldefense.proofpoint.com). This is normal and provides additional security by checking links when you click them.
What to expect:
- Links in emails will look different
- There may be a brief delay when clicking links
- Dangerous links will show a warning page
If you encounter issues with specific links, please contact IT support.
Next Steps
After configuring URL Defense:
- Configure email filtering - Set up filter policies
- Manage sender lists - Configure safe senders and block lists
- Configure DLP - Prevent data loss
Additional Resources
Need help implementing Proofpoint URL Defense? Inventive HQ provides expert email security configuration and user training. Contact us for a free security assessment.