As an aside, if you're sending URLs that contain login credentials in plain text, you already have big security problems. The same is true if your session ID allows anyone to masquerade as you simply by clicking a link.
That IP address, 65.52.100.214, is indeed controlled by Microsoft, as a cursory inspection of DNS records confirms. But after doing some investigating of my own, I’ve concluded that the reason for the mysterious visit is almost certainly innocent.
|