You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I apologise if I didn't spot it, but is XARF supporting defanged URLs in one of other way?
I just want to be sure that an XARF attachment is not being blocked by some smart mail filter rule because of malicious indicators.
The text was updated successfully, but these errors were encountered:
The schema currently doesn't allow for defanged URLs in any way, and I don't think it's something we will support in the future.
Here's the reasoning behind that:
Defanged urls often used to prevent accidental clicks from abuse-desk workers. This should be a non issue for XARF, because the schema is intended to be processed automatically.
Spam filters on abuse addresses are never a good Idea1 and should't be a reason for adding defanged urls. We even made a video about this issue a while ago: https://www.youtube.com/watch?v=1xeLcHIkTMo
Someone who runs a spam filter on their abuse address probably won't be diligent about the incoming messages anyway.
I know this won't help you, but I hope this clarifies a few things.
Footnotes
A spam filter could dislike many things about XARF reports and trying to circumvent them won't increase the quality of such reports. ↩
I apologise if I didn't spot it, but is XARF supporting defanged URLs in one of other way?
I just want to be sure that an XARF attachment is not being blocked by some smart mail filter rule because of malicious indicators.
The text was updated successfully, but these errors were encountered: