• Sublime Core Feed

Description

Detects messages where the sender's display name contains emoji characters alongside financial symbols ($ £ € ¥ ₿) in the subject line. The sender's domain is not present in the Alexa top 1 million sites and has DMARC authentication issues.

References

No references.

Sublime Security
Created Aug 21st, 2025 • Last updated Jan 12th, 2026
Source
type.inbound
// Check for emoji in sender display name using Unicode ranges
and regex.contains(sender.display_name,
                   '[\x{1F600}-\x{1F64F}]|[\x{1F300}-\x{1F5FF}]|[\x{1F680}-\x{1F6FF}]|[\x{1F1E0}-\x{1F1FF}]|[\x{2600}-\x{26FF}]|[\x{2700}-\x{27BF}]'
)
// Check for financial symbols in subject
and regex.contains(subject.subject, '[\$£€¥₿]')
and (
  headers.auth_summary.dmarc.pass is null
  or headers.auth_summary.dmarc.pass == false
)
and sender.email.domain.root_domain not in $alexa_1m
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started