Proofpoint URL Defense

SkillAI & models

Proofpoint URL Defense fundamentals: URL rewriting (v2/v3 formats), click-time analysis and verdicts, and manual/API decoding of rewritten URLs back to their originals.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Proofpoint URL Defense skill

What this skill tells your AI

The instructions your AI receives, as published by wyre-ai/msp-claude-plugins in msp-claude-plugins/email-security/proofpoint/skills/url-defense/SKILL.md and read by ahel’s review.

Overview

Proofpoint URL Defense rewrites URLs in email messages to route clicks through Proofpoint's analysis infrastructure. When a user clicks a rewritten URL, Proofpoint performs real-time analysis of the destination before allowing or blocking access. This provides click-time protection - even if a URL was clean when the email was delivered, it will be analyzed again at the moment the user clicks.

URL Defense is a critical layer of protection because many attacks use time-delayed weaponization: a URL is clean when the email is sent but becomes malicious hours or days later.

Anti-triggers

  • The click event feed across all users and threats — this skill answers "who clicked this URL". The full permitted/blocked click stream is proofpoint-tap.
  • Removing the message that carried the link — use proofpoint-quarantine if it is still held, or proofpoint-forensics if it was delivered.
  • Turning URL rewriting on or off — rewrite behaviour is a Proofpoint policy setting, and no tool here changes it; use the Proofpoint console. The same is true on a Checkpoint Harmony tenant: that plugin exposes no policy tool either, so its URL_REWRITE configuration is console-only as well. Do not route this question to a Harmony skill expecting a tool to exist.

Key Concepts

URL Rewriting

Proofpoint rewrites URLs in email bodies and HTML attachments. The rewritten URL format is:

https://urldefense.proofpoint.com/v2/url?u=<encoded_original_url>&d=<domain_key>&c=<context>&r=<recipient_hash>&m=<message_hash>&s=<signature>&e=

Version 3 format:

https://urldefense.com/v3/__<encoded_url>__;!!<encoded_chars>!<signature>$

URL Rewrite Components

ComponentDescription
uURL-encoded original URL (v2)
dDomain key for the organization
cContext identifier
rRecipient hash
mMessage hash
sHMAC signature for integrity
eEmpty (reserved)

Click-Time Analysis

When a user clicks a rewritten URL, Proofpoint performs:

  1. URL reputation check - Is this URL on known blocklists?
  2. Real-time sandbox - Load the page in a sandbox and check for malicious content
  3. Redirect chain following - Follow all redirects to the final destination
  4. Content analysis - Check for credential harvesting forms, drive-by downloads
  5. Verdict delivery - Allow, warn, or block based on analysis

Click-Time Verdicts

VerdictUser ExperienceDescription
allowUser proceeds to destinationURL is clean
warnWarning interstitial pageURL is suspicious but not confirmed malicious
blockBlock page shownURL is confirmed malicious
isolateOpened in browser isolationURL is risky, opened in safe container

URL Encoding in v2

In the v2 rewrite format, the original URL is encoded:

  • - replaces /
  • _ replaces =
  • Standard URL encoding for other special characters

URL Encoding in v3

In the v3 format, the original URL uses a different encoding:

  • __ delimiters surround the encoded URL
  • Special characters are encoded in the trailing !! section
  • The $ terminates the URL

Field Reference

URL Analysis Fields

FieldTypeDescription
originalUrlstringThe original URL before rewriting
rewrittenUrlstringThe Proofpoint-rewritten URL
verdictstringallow, warn, block, isolate
threatIdstringThreat ID if URL is malicious
classificationstringmalware, phish, spam, clean
firstSeendatetimeWhen the URL was first observed
lastSeendatetimeMost recent observation
clickCountintNumber of clicks on this URL
blockCountintNumber of times clicks were blocked
redirectChainstring[]Full redirect chain to final URL
finalUrlstringFinal destination after redirects
certificateobjectSSL certificate details of the destination

Decoded URL Fields

FieldTypeDescription
encodedUrlstringThe Proofpoint-rewritten URL provided
decodedUrlstringThe original URL extracted
versionstringRewrite version (v2 or v3)
validbooleanWhether the URL is a valid Proofpoint rewrite

MCP Tools

ToolDescriptionKey Parameters
proofpoint_url_decodeDecode one or many Proofpoint-rewritten URLs back to the originalsurls (required, array)
proofpoint_url_analyzeAnalyze a URL for threats — returns classification, risk score, associated campaignsurl (required)

Two tools, and that is the whole domain. proofpoint_url_decode takes an array, so batch decoding is the ordinary call, not a separate tool — pass one URL in a one-element array. proofpoint_url_analyze is also the verdict tool: the classification and risk score it returns are the verdict, so there is no separate verdict call to poll.

Not available through this plugin

Click activity is not keyed by URL anywhere. URL Defense here decodes and analyses; it has no click surface. Click records live in TAP — proofpoint_tap_get_clicks_permitted and proofpoint_tap_get_clicks_blocked — and both are keyed by time window, not by URL. To answer "who clicked this link", pull the clicks for the relevant window and filter the results on the URL yourself, and remember TAP's 24-hour SIEM ceiling: outside that window you get an empty result that reads like "nobody clicked" and means "no data".

Common Workflows

Decode a Rewritten URL

  1. User or analyst provides a Proofpoint-rewritten URL
  2. Call proofpoint_url_decode with urls set to a one-element array containing the full rewritten URL
  3. Return the original decoded URL
  4. Optionally call proofpoint_url_analyze to check the URL's current threat status

Investigate a Suspicious URL

  1. Call proofpoint_url_analyze with the URL
  2. Review the classification, risk score, and associated campaigns
  3. If malicious, pull proofpoint_tap_get_clicks_permitted for the relevant time window and filter the results for this URL to see who clicked
  4. Cross-reference with the rest of the TAP click events for full context
  5. If the URL is being used in an active campaign, escalate to threat intelligence

Bulk URL Decoding

  1. Extract all Proofpoint-rewritten URLs from an email or document
  2. Call proofpoint_url_decode with the whole array in urls — one call
  3. Review the decoded URLs for any suspicious destinations
  4. Check each decoded URL against threat intelligence

Click Activity Investigation

  1. Identify a suspicious URL from TAP events or quarantine
  2. Call proofpoint_tap_get_clicks_permitted and proofpoint_tap_get_clicks_blocked for the window, then filter both result sets on the URL — there is no per-URL click tool
  3. Review which users clicked and when
  4. Permitted clicks are the exposure; blocked clicks are volume signal
  5. For permitted clicks, assess whether credentials may be compromised
  6. Initiate password resets for users who clicked on credential harvesting URLs

Re-checking a URL After Delivery

  1. Call proofpoint_url_analyze for a URL that was previously clean — URLs can become malicious after delivery, and the analysis reflects the current classification, not the one at delivery time
  2. If it now classifies as malicious, check whether users received emails containing it
  3. If they did, run the search-and-destroy sequence in the proofpoint-forensics skill

URL Decoding Reference

Manual v2 Decoding

To manually decode a v2 Proofpoint URL:

  1. Extract the u= parameter value
  2. Replace - with /
  3. Replace _ with =
  4. URL-decode the result
Input:  https://urldefense.proofpoint.com/v2/url?u=https-3A__example.com_path-3Fparam-3Dvalue&d=...
Step 1: https-3A__example.com_path-3Fparam-3Dvalue
Step 2: https-3A//example.com/path-3Fparam-3Dvalue
Step 3: https-3A//example.com/path-3Fparam=value
Step 4: https://example.com/path?param=value

Manual v3 Decoding

To manually decode a v3 Proofpoint URL:

  1. Extract the content between __ delimiters
  2. Decode special characters from the !! section
  3. Replace encoded characters in the URL
Input:  https://urldefense.com/v3/__https://example.com/path__;!!ABC123!def$
Output: https://example.com/path

Note: Always use the proofpoint_url_decode tool rather than manual decoding to ensure accuracy.

Error Handling

Common API Errors

CodeMessageResolution
400Invalid URL formatEnsure the URL is a valid Proofpoint-rewritten URL
400Unsupported URL versionOnly v2 and v3 formats are supported
401Authentication failedVerify service principal and secret
403URL Defense API not enabledEnsure your license includes URL Defense API
404URL not foundThe URL may not have been processed by Proofpoint
429Rate limit exceededImplement backoff

Decoding Failures

IssueCauseResolution
Invalid signatureURL was modified after rewritingThe URL may have been truncated or altered
Unknown versionURL does not match v2 or v3 formatIt may not be a Proofpoint URL
Expired URLURL is older than the retention periodOriginal URL cannot be recovered from the API

Best Practices

  1. Check verdicts at click time - A URL clean at delivery may be malicious when clicked
  2. Monitor click activity - Track which users are clicking rewritten URLs
  3. Train users on rewritten URLs - Users should recognize Proofpoint-rewritten URLs as a security feature
  4. Don't bypass URL Defense - Never instruct users to work around URL rewriting
  5. Use browser isolation for risky clicks - Configure isolation for suspicious-but-not-confirmed URLs
  6. Audit redirect chains - Multi-hop redirects are a common evasion technique
  7. Batch decode for efficiency - proofpoint_url_decode takes an array; pass every URL in one call rather than looping
  8. Retain decoded URLs - Log the original URLs for threat intelligence and IOC tracking
  9. Combine with TAP data - Cross-reference URL analysis with TAP events for full visibility

Related Skills

Signals

GitHub stars
45
Forks
24
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
proofpoint-url-defense
Source
github.com/wyre-ai/msp-claude-plugins
Proofpoint URL Defense: Skill · ahel