Sophos Blocked My Website: How to Get It Reclassified
To get a clean website reclassified by Sophos, email Sophos using the address in knowledge-base article KBA-000048894, 'Sample Submission - Non-Customer File and URL submissions'. Put the URL in the subject with hxxp:// or hxxps:// in place of http:// or https://, and in the body explain the miscategorisation and the category that should apply. Sophos accepts these from anyone but gives no feedback.
| Vendor | Sophos |
|---|---|
| Channel | Email (we send it for you; the vendor's own portal is below) |
| Where | Sophos KBA-000048894 — Sample Submission: Non-Customer File and URL submissions |
| Account needed | None |
| Vendor states | Sophos states that non-customer submissions are welcome but feedback will not be provided. No turnaround is stated. |
| What we have seen | Sophos states it sends no confirmation; in practice the category changes silently, usually within a few days, and the only way to know is to re-check the lookup or a Sophos-protected client. |
What a Sophos flag looks like
A Sophos block page in the browser — web page blocked, with a category such as Malicious or Phishing & Fraud — served by Sophos Firewall, Intercept X or Sophos Home. Visitors inside companies that run Sophos see it; the public usually does not.
Why clean sites end up flagged here
- A compromise that has since been cleaned, recorded by SophosLabs before the cleanup.
- A category assigned from a single past sighting, a shared IP or a previous owner of the domain.
- A new domain with login or payment pages that an automated classifier puts in Phishing & Fraud.
- A benign site placed in the wrong content category, which Sophos also treats as a misclassification.
Where to submit: Sophos KBA-000048894 — Sample Submission: Non-Customer File and URL submissions
https://support.sophos.com/support/s/article/KBA-000048894
Account: None.
What it asks for:
- Subject: the miscategorised URL, with 'http:' written as 'hxxp:' and 'https:' as 'hxxps:'
- Body: a concise explanation of the incorrect categorisation and the category that should apply
Sophos customers who want feedback use the support portal's sample submission page, which has a 'Web Address (URL)' option. The email address is in the KB article; the catalog keeps it private.
Step by step
- Get the block page. Ask the affected visitor or their IT team for a screenshot of the Sophos block page with the URL and category.
- Fix or confirm the cause. Remove anything that fits the category, or confirm from an outside network and a mobile user agent that the page is clean.
- Write the subject in hxxp form. The subject is the URL itself with 'http:' replaced by 'hxxp:' and 'https:' by 'hxxps:', as KBA-000048894 specifies. Nothing else goes in the subject.
- Write the body and send. A concise explanation of why the category is wrong and which category should apply. Send it to the address given in KBA-000048894. Send once.
- Re-check without waiting for a reply. Sophos gives non-customers no feedback. After a few days, ask the blocked visitor or their IT team to re-test, or check from a Sophos-protected client.
What to write
Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.
Subject: {hxxps://example.com/path}
{URL} is categorised by Sophos as {current category, e.g. Phishing & Fraud}. The site is {one-line description of the site} and hosts no malware or phishing. {Optional: 'Content that may have caused this ({what}) was removed on {date}.'} The correct category is {category, e.g. Business}. Please reclassify the URL.Why requests get rejected, and the fix
- The subject was a sentence ('False positive for my site') instead of the URL in hxxp form, so the request did not match the documented format. Resend with the subject exactly as the URL, 'http:' → 'hxxp:' or 'https:' → 'hxxps:', and the explanation in the body.
- The body did not name a correct category, or the flagged content was still present on re-check. State the category that should apply, clean every path and subdomain, and resend with the removal date.
Who copies this verdict
- Sophos Firewall, Intercept X and Sophos Home all use the same SophosLabs classification, so one change applies to all three.
- VirusTotal lists Sophos as one of its URL engines.
Sources
- Sophos KBA-000048894 — Sample Submission: Non-Customer File and URL submissions
- Sophos Support — Sample submission (Sample File, Spam Email, Web Address (URL), Application Control)
Longer read: why Sophos flags clean sites and how unflagdomain handles it.
Email Sophos as described in KBA-000048894, 'Sample Submission - Non-Customer File and URL submissions'. The subject is the URL with 'hxxp:' or 'hxxps:' in place of 'http:' or 'https:'; the body briefly explains the incorrect categorisation and names the category that should apply. The address is in that article.
Sophos asks for it in KBA-000048894. Writing the scheme as hxxp or hxxps stops mail systems and clients from turning the URL into a live, clickable link, which matters when the URL is suspected of being malicious. A subject in any other form does not follow the documented process.
No. Sophos says submissions from non-customers are welcome but feedback will not be provided. The category changes without notice, so the only way to know is to re-test from a Sophos-protected client. Customers who need feedback use the sample submission page in the Sophos support portal.
Sophos protects mostly business networks and endpoints through Sophos Firewall and Intercept X, plus home users on Sophos Home. Visitors outside those see nothing. Blocks often surface as complaints from customers or partners at companies that run Sophos, so a single report from one company is usually the first sign.
Yes, when a scan shows Sophos flagging the domain: a separate plain-text request goes to Sophos by email in the documented hxxp format, with your address as Reply-To. We guarantee the request is sent; Sophos alone decides whether to reclassify, and it sends no reply. We do not clean malware.