type.inbound
and any(attachments,
.file_type == "pdf"
and any(ml.logo_detect(.).brands, .name == "DocuSign")
and any(file.explode(.),
length(.scan.url.urls) <= 9
and any(.scan.url.urls,
.domain.root_domain not in $tranco_1m
and .domain.root_domain not in $org_domains
and .domain.root_domain != "sublimesecurity.com"
and not strings.ilike(.domain.root_domain, "docusign.*")
)
)
and any(file.explode(.),
any(ml.nlu_classifier(.scan.ocr.raw).entities,
.name == "org" and .text == "DocuSign"
)
)
and any(file.explode(.),
any(ml.nlu_classifier(.scan.ocr.raw).entities,
.name == "request"
)
)
)
Playground
Test against your own EMLs or sample data.