Security Scan Report: outlook.office365.com.mcas-gov.ms

Redirected to:
https://outlook.office365.com/mail/?
Site favicon
Submitted: Sep 14, 2026, 4:59:37 PMCompleted: Sep 14, 2026, 4:59:58 PMpubliccompleted

This website contacted 7 IPs in 2 countries across 4 domains to perform 19 HTTP transactions. The main domain is outlook.office365.com and was registered 3 years 4 months ago.

Submitted URL: https://outlook.office365.com.mcas-gov.ms

Effective URL:

https://outlook.office365.com/mail/?
Redirected

The Cisco Umbrella rank of the primary domain is #99,365 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Interstitial 'Continue' page on a hostname that nests office365.com under mcas-gov.ms, then redirects to genuine Outlook. No forms, no Indicators of Compromise, no YARA or IDS hits — no credential harvesting; likely Microsoft MCAS proxy, but the deceptive hostname warrants caution.

Risk Factors (3)
Deceptive hostname structure: outlook.office365.com.mcas-gov.ms places a Microsoft brand hostname as a subdomain of a third registrable domain
174 Function() constructor calls in loaded JavaScript (code generation, requires corroboration; common in large vendor bundles)
Entry domain (mcas-gov.ms) is unranked/unknown repute and its age cannot be attributed to the page actually served at outlook.office365.com
Safety Factors (5)
Final URL resolves to the genuine outlook.office365.com mail endpoint
No credential, login, or payment form present — nothing is harvested on this page
No Indicators of Compromise, YARA, Safe Browsing or IDS evidence of phishing or malware
The URL pattern matches Microsoft Defender for Cloud Apps (MCAS) session-proxy rewriting of an Office 365 URL, which is legitimate Microsoft infrastructure behaviour
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 4 to 4
Domain age information unavailable

Details

Page Title

Continue

Scan Type

public

Domain Name Analysis

You're looking at domain 'outlook.office365.com.mcas-gov.ms' on the .ms country-code top-level domain and includes subdomain 'outlook.office365.com'. The second-level label 'mcas-gov' is 8 characters long holding two vowels versus five consonants, notching one hyphen. Breaking it apart gives three words: mc, as, gov. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://outlook.office365.com.mcas-gov.ms

Page Load Overview

3.46s
Total Load Time
595 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:73%
Script:Latin
Direction:ltr

Detection Details

Text Length:35 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
752.227.10.254Azure · CLOUDBoydton, Virginia, United States
AS8075Microsoft Corporation
220.140.151.75San Antonio, Texas, United States
AS8070Microsoft Corporation
2104.18.18.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.18.19.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
252.98.252.242Office365 · CLOUDFrankfurt am Main, Hesse, Germany
AS8075Microsoft Corporation
252.98.179.162Office365 · CLOUDFrankfurt am Main, Hesse, Germany
AS8075Microsoft Corporation
240.99.149.98Office365 · CLOUDFrankfurt am Main, Hesse, Germany
AS8075Microsoft Corporation
197--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BF01FECA5CF388915A0350FD15DAE50C797AB30B4604CD44398C8275AF84BE44943AEC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:kxv85qJmrsH+SDXrWlgF6ydBabxYOGMuESWyplKhsN7+1VM69FFuNVI:kx8SHH+WKA6ydTOaEMMsp+3tLFuNVI

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:763:EAAAAAAAAAAAAAABAAAAAAAIAAAAAAAABQCAAAQAAAQIAAAAAAARAAAAAAAACAARAAAAAAAACCAAAAAAAAAAAAAAAAAAEEAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e699992666999966
Difference Hash:0008000c0c000800
Wavelet Hash:0f0f1f07071f0f0f
Color Hash:#8797c5

Other Hashes

Crop Resistant:0008000c0c000800

Scan History

Scan history not available

Unable to load historical scan data