Medium Severity

Evasion: Suspicious use of Unicode tag characters

Description

Unicode Tag Block characters (U+E0000–U+E007F) render invisibly in mail clients but map 1:1 to ASCII at a 0xE0000 offset. Attackers use them two ways: to smuggle hidden instructions that LLM-powered email assistants will read and act on, and to interleave invisible characters through visible text to defeat content matching. This rule flags either use in the subject, body, or a calendar attachment, discounting the England, Scotland, and Wales subdivision flag emoji, which are legitimately built from tag characters.

Sublime Security
Created Oct 4th, 2026 • Last updated Oct 4th, 2026
Source
type.inbound
and any([subject.subject, body.html.inner_text],
        regex.count(., '[\x{E0020}-\x{E007E}]') > 10
        and (
          regex.contains(., '[A-Za-z0-9][\x{E0020}-\x{E007E}]+[A-Za-z0-9]')
          or regex.contains(., '[\x{E0020}-\x{E007E}]{10,}')
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started