type.inbound
// window of lines around a copy/paste-into-browser instruction
and any(regex.iextract(body.current_thread.text,
'(?P<window>(?:[^\n]*\n){0,2}[^\n]*(?:cop(?:y|ied)|past(?:e|ed))\b[^\n]{0,50}?\b(?:in|into|to)\s+(?:your|a|the|any)\s+(?:web\s+)?browser[^\n]*(?:\n[^\n]*){0,3})'
),
// bare hostnames within that window, parsed once
any(map(regex.iextract(.named_groups["window"],
'(?:^|[\s:(])(?P<host>[a-z0-9-]+(?:\.[a-z0-9-]+)+\.[a-z]{2,})(?:/\S*)?(?:[\s.,;)!]|$)'
),
strings.parse_url(strings.concat("https://",
.named_groups["host"]
)
).domain
),
.valid
// never hyperlinked anywhere in the message and not the sender's own domain
and .root_domain not in map(body.links,
.href_url.domain.root_domain
)
and .root_domain !~ sender.email.domain.root_domain
// free app hosting
and .root_domain in $free_subdomain_hosts
)
)
Playground
Test against your own EMLs or sample data.