Engage - URL Click False Positive Remediation - Jan 2026

Service Update

Availability January 8th, 2026
Product(s) Engage
Who's affected All Email Security Cloud Gateway (CG) customers with Human Risk Command Center (HRCC)

Overview

Mimecast is pleased to announce URL Click False Positive Remediation. False positive remediation is an automatic process that corrects a user's Human Risk Score when a URL they clicked is initially flagged as malicious but later determined to be safe. This ensures that their risk score accurately reflects actual security risks, rather than penalizing the user for clicks that turn out to be harmless.

Considerations 

  • The score adjustment is automated, but is triggered by the Administrator adding the URL as an allowed URL in the URL Protection Tools | Managed URLs option in the Administration Console

  • Administrators can manage allowed domains or specific URLs through the URL tools, managed URLs, with changes logged in the Human Risk Command Center (HRCC) event log.

This release addresses the following two false positive scenarios:

  1. Actual detection errors. 

  2. User disagreement with Mimecast's assessment: this is done by allowing administrators to classify URLs as benign, update URLs in the URL Protection Tools | Managed URLs, and retroactively impact user scoring based on these changes.

What's changing

  • Administrators can manage allowed domains or specific URLs through the URL protection system, with changes logged in the HRCC event log
  • The system will also retroactively adjust user scores over a 30-day period to reflect the reclassification.

Recommended actions

To classify URLs, navigate to Email Security | URL Protection | Managed URLs in the Mimecast Administration Console. For more information, see Targeted Threat Protection - URL Protect - Managed URLs.

See Also...

Was this article helpful?
1 out of 1 found this helpful

Comments

0 comments

Please sign in to leave a comment.