Skip to content
Avanet

Sophos Email: configure Time-of-Click URL protection

Time of Click rewrites links in inbound email and reassesses the destination when a user clicks. This article covers the downstream administration: branding warning and block pages and exempting individual destinations. Enabling the feature and selecting actions for Risky and Unverified URLs belong in the core URL protection policy.

Safe short path: record the starting state, configure user pages under Global Settings > Products and Services > Email > Time-of-Click Block and Warn Pages, and check them with Preview. Keep the URL Allow List empty wherever possible. If an exception is unavoidable, allow a full URL before considering a domain or wildcard, then test it with a newly delivered pilot message.

Warning: A URL Allow List entry is not a cosmetic option. Matching links in messages processed in the future are neither rewritten nor checked by the Malicious URL scan. A broad domain or wildcard therefore creates a persistent protection gap.

Prepare the prerequisites and change

You need an active Sophos Email configuration with Time of Click URL Protection enabled and administrator access to global email settings. Block and Warn Pages can’t be configured in EMS mode. Exceptions require documented approval from the security owner; a custom logo must be prepared exactly to specification.

Before changing anything, record:

  • the current state of Configure block and warn pages, the logo, and all four text fields;
  • all current URL Allow List entries;
  • the ticket, owner, justification, and expiry or review date for each exception;
  • a pilot recipient and test messages that will be sent after the change;
  • the rollback: restore the previous text or logo and delete newly added allow-list entries.

Make warning and block pages clear

  1. In Sophos Fusion, click the Global Settings icon.
  2. Open Products and Services > Email > Time-of-Click Block and Warn Pages.
  3. Turn on Configure block and warn pages.
  4. If required, upload a logo with Browse. It must be exactly 100 px wide by 60 px high, use JPEG, JPG, or PNG, and be no larger than 500 KB. Check the displayed preview.
  5. Under risky URLs, write separate Custom Block Page and Custom Warn Page messages.
  6. Under unverified URLs, also write separate Custom Block Page and Custom Warn Page messages.
  7. Open Preview for every page. Check the logo, wrapping, useful next step, and clear distinction between blocked and warned.
  8. Click Save.

A useful block message says that the link wasn’t opened and identifies the internal support channel. A warning says that the destination is risky or hasn’t been verified and that users should continue only in an expected business context. Don’t expose confidential contacts, ticket details, or internal system names on this user-facing page.

Keep the four messages distinct. Risky is a risk verdict; Unverified means Sophos couldn’t verify the destination sufficiently. Using identical wording makes triage harder for users and support.

Add a URL exception using least privilege

Use an exception only when rewriting or scanning breaks a confirmed business workflow, the responsible owner has validated the destination, and no narrower technical fix is available. Microsoft Teams meeting-link validation is one example: teams.microsoft.com may need an exception. That removes Time-of-Click protection from every matching link on that domain, so approval and regular review remain essential.

  1. Click Global Settings and open Products and Services > Email > URL Allow List.
  2. Click Add.
  3. Enter the narrowest proven value. Supported examples include a full URL such as https://meet.example.com/join/pilot, a domain such as example.com, or a wildcard such as *.example.com. These are placeholders; replace them with the approved business destination.
  4. Click Add to confirm.
  5. Record the exact entry, reason, owner, and review or expiry date in the change.

A full URL limits the exception more than a whole domain. *.example.com includes all subdomains and is appropriate only when that broad scope is genuinely required. Copy the scheme, host, and path from the observed link; don’t add speculative variants.

The Allow List affects only messages processed in the future. A link that Sophos rewrote and delivered before the exception remains rewritten. Validation must therefore use a new message.

One boundary can’t be overridden: if a message contains a URL on the Internet Watch Foundation criminal list, Sophos deletes it regardless of policy or Allow List. The link also isn’t shown in Sophos Fusion or Message History.

Validate the behavior safely

After saving, send new messages to the pilot recipient. Never click production malicious links or forward unknown samples as test material. Use only internally approved test destinations or a controlled case from your own tenant for Risky and Unverified tests.

  1. Clean link: a normal, newly delivered URL must follow the expected Time-of-Click path without a warning or block page.
  2. Risky: an approved controlled test destination must show the configured Risky warning or block page, according to the URL policy.
  3. Unverified: a controlled unverified destination must show its separate page.
  4. Narrow exception: a new message containing the exact Allow List destination must retain the original, unmodified link. If a full URL was entered, a similar link outside its path must still be rewritten.
  5. Presentation: open the pages in managed browsers and check logo, text, controls, and support guidance.

The change passes only when all three protection cases behave as intended and the control link outside the exception remains protected. Record time, sender, recipient, original URL, observed behavior, and the Allow List entry. An old email can’t prove a new exception.

Roll back and operate the setting

If behavior is unclear, don’t disable Time of Click. Remove the new exception instead: under Global Settings > Products and Services > Email > URL Allow List, select it and click Delete in the upper left. Multiple or all entries can be selected, but in production delete only values named in the change. Send another new test message and confirm that the link is rewritten again.

Restore unsuitable text or a logo to the recorded baseline, then check it with Preview and a controlled new message. Give every remaining exception an owner and recurring review. Delete and retest it when the business reason ends.

Troubleshoot by symptom

First confirm that the message was processed after the entry was added. Compare its actual scheme, host, subdomain, and path with the entry. Forwarding may preserve an old rewritten URL. After correction, send a completely new message; clicking the same email again doesn’t retest the change.

The exception matches too broadly

Look for a root-domain or wildcard entry. With security approval, replace it with the required full URL or narrower host, then test both a match and a neighboring non-match. If the necessary scope is unclear, delete the exception until it is resolved.

The logo or page text won’t save

Check 100 × 60 px, JPEG/JPG/PNG, and the 500 KB limit first. Then verify that Configure block and warn pages is on and the tenant isn’t in EMS mode. The setting isn’t available in EMS mode. After correcting it, use Preview before Save.

The wrong page appears

Determine whether the link was rated Risky or Unverified and which action the URL policy defines for that category. Global pages change presentation and wording; they don’t select Block, Warn, or Allow.

If the cause remains open, remove new exceptions and collect tenant region, time, Message-ID, original and displayed URL, exact Allow List entry, page screenshots, and recorded policy state for escalation. Protection then remains active while Sophos or your service partner investigates.