Service abuse: DocSend share from newly registered domain
Service abuse: DocuSign notification with suspicious sender or document name
Service abuse: DocuSign share from an unsolicited reply-to address
Service abuse: Domains By Proxy sender
Service abuse: Dropbox Paper with copy-paste instructions
Service abuse: Dropbox share from an unsolicited reply-to address
Service abuse: Dropbox share from new domain
Service abuse: Dropbox share with suspicious sender or document name
Service Abuse: ExactTarget with suspicious sender indicators
Service abuse: FlipHTML5 with attachment deception and credential theft language
Service abuse: Free provider with SendGrid routing
Service Abuse: GoDaddy infrastructure
Service abuse: Google application integration redirecting to suspicious hosts
Service abuse: Google OAuth with suspicious redirect destination
Service abuse: HelloSign from an unsolicited sender address
Service Abuse: HelloSign share with suspicious sender or document name
Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
Service abuse: Linode Objects HTML file hosting
Service abuse: Meetup.com redirect with brand impersonation
Service abuse: Mimecast URL with excessive path length
Service abuse: Monday.com infrastructure with phishing intent
Service abuse: Nylas tracking subdomain with suspicious content
Service abuse: Payoneer callback scam
Service abuse: QuickBooks notification from new domain
Service abuse: QuickBooks notification with suspicious comments
Service abuse: SendGrid-formatted link with actor-controlled fragment
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: Suspicious Zoom Docs link
Service abuse: Task management message sent via SendGrid
Service abuse: Wix redirect through bulk mailer domains
Service abuse: Zoom with newly registered reply-to domain
Sharepoint file share with suspicious recipients pattern
Sharepoint online with external recipients and external display name
Shopify infrastructure abuse
Spam: BlackBaud infrastructure abuse
Spam: Firebase password reset from suspicious sender
Spam/fraud: Predatory journal/research paper request
Spam: Sendersrv.com with financial communications and unsubscribe language
Spam: Unsolicited malformed PDF
Subject and sender display name contains matching long alphanumeric string
Subject: Suspicious bracketed reference
Suspected cross-site scripting (XSS) found in subject
Suspected lookalike domain with suspicious language
Suspicious attachment: Duplicate decoy PDF files
Suspicious attachment with unscannable Cloudflare link
Suspicious DocuSign share from new domain
Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender
Suspicious message with unscannable Vercel link