Service abuse: SendThisFile with credential theft and financial language
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: Task management message sent via SendGrid
Service abuse: Trello board invitation with VIP impersonation
Service abuse: Vimeo with external plain-text links in message
Service abuse: WeTransfer callback scam
Sharepoint file share with suspicious recipients pattern
Sharepoint online with external recipients and external display name
SharePoint OTP for filename matching org name
Shopify infrastructure abuse
Spam: Attendee list solicitation
Spam: BlackBaud infrastructure abuse
Spam: Campaign with excessive display-text and keywords found
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Spam: Commonly observed formatting of unauthorized free giveaways
Spam: Cryptocurrency airdrop/giveaway
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
Spam: Fake dating profile notification
Spam/fraud: Predatory journal/research paper request
Spam: Ghostwriting services scam with manipulative language
Spam: Item giveaway spam template
Spam: Mastercard promotional content with image-based body
Spam: New job cold outreach from unsolicited sender
Spam: New link domain (<=10d) and emojis
Spam: Personalized subject and greetings via Salesforce Marketing Cloud
Spam: Sendersrv.com with financial communications and unsubscribe language
Spam: Sexually explicit content with emoji in subject from freemail provider
Spam: Sexually explicit Google Drive share
Spam: Sexually explicit Google group invitation
Spam: Sexually explicit Looker Studio report
Spam: Single recipient duplicated in cc
Spam: SMTP & Proxy Communications in Email Body
Spam: Unsolicited malformed PDF
Spam: URL shortener with short body content and emojis
Spam: Website errors solicitation
Spoofable internal domain with suspicious signals
Subject and sender display name contains matching long alphanumeric string
Subject: Suspicious bracketed reference
Suspected cross-site scripting (XSS) found in subject
Suspected lookalike domain with suspicious language
Suspected WordPress abuse with cross-site scripting (XSS) indicators
Suspicious attachment with unscannable Cloudflare link
Suspicious DocuSign share from new domain
Suspicious invoice reference with missing or image-only attachments
Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender
Suspicious message with unscannable Cloudflare link
Suspicious message with unscannable Vercel link
Suspicious newly registered reply-to domain with engaging financial or urgent language
Suspicious recipient pattern and language with low reputation link to login