However, pusher-robot makes a good point that this is not so bad if only the URLs from the message were being sent back to MS, especially if B had voluntarily opted in to this URL verification service.Not sure if there would be any practical way to use a MITM attack to modify messages between A and B in a meaningful and non-obvious fashion.