Scan report · 13 days agoPublic
Verdict

Looks safe

Automated

It runs Microsoft's Outlook Web App on the organisation's own domain; the Microsoft branding is the licensed product's, not an impersonation. It asks you to enter a password. Our automated checks did not find known threat signals on this site at the time of the scan.

What to do

No action needed. Stay alert as usual — a clean result reflects this scan only, and sites can change after they are checked.

A clean result means no known threat signals were found in this scan — it is not an absolute guarantee, and a site can change after it is checked.

Runs Microsoft's Outlook Web App on the organisation's own domain — brand accepted (mx-same-domain)

Findings

Strongest first
InfoSelf-hosted Microsoft Outlook Web App verified
Outlook Web App 15.2.1748 · organisation tie: mx-same-domain

This host runs Microsoft's licensed Outlook Web App on the customer's own domain, and the organisation's DNS ties the domain to it. The Microsoft branding is the product's, not an impersonation, so the brand claim was withdrawn. Evidence: fingerprint: Outlook Web App 15.2.1748 at technology confidence 100 (X-OWA-Version response header / versioned /owa/auth/<v>/themes/resources link / IsOwaPremiumBrowser global) · credential sink: 1 form(s) post to /owa/auth.owa on mail.cetas.com.tr · return address: url= points back to mail.cetas.com.tr · organisation: cetas.com.tr publishes MX under its own domain (mail.cetas.com.tr)

Analyst noteDecided from the server's own headers, the rendered form's sink and DNS — never from page text, which a clone copies. The one shape this cannot see is a reverse proxy in front of the real server on a domain that also publishes mail records; if that is your suspicion, check certificate and domain age.

File

The file was not analysed, so the scan carries no verdict on the file itself.

Infrastructure

IP
81.200.142.106ICTBULUT - ICT BULUT BILISIM A.S., TR · AS47952TR
TLS
CN=RapidSSL TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US · expires Feb 27, 2027
3 malicious11 suspicious

Hashes & fingerprints

Page capture

Live

Title “Outlook”

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Outlook
Load
8.99 s · 2 requests
Stack · 4IISMicrosoft ASP.NETOutlook Web AppWindows Server