Phishing attempt detected from customers Gmail.....

I have a client using Total Security 2020. Machine/network is clean, she is using Outlook through 365 for email. She's been having an issue where one of her clients emails trigger a phishing attempt in BD. Happens when she opens it or tries to reply. The email is a trusted source and it's a gmail account! I see no malicious links or attachments etc. Just normal correspondence from a gmail account. The url being blocked is http://findresults.site/?rpid=2POQ7BC1G

I know what phishing is and I know that link is suspicious, that is not why I'm posting. Since the link is suspicious I do not want to set an exclusion. We just can't figure out why it's happening from what appears to be a normal gmail addy and it's the only email that triggers it. All other correspondence are fine.


I have the headers from Outlook I can pm if needed.....