High Severity

Link: Delimited encoded path parameters (~V~ scheme)

Description

This rule flags inbound messages containing a link with a repeating encoded pattern in the URL path, a technique used to obfuscate the true destination and evade static URL matching. The captured samples span a range of unrelated senders and lures - fake system/data access suspension notices, payment authorization failures, case submission confirmations, and backup storage reminders - all designed to create urgency and drive recipients to click through disguised links. The variety of spoofed sending domains and generic account/security themes suggests a shared link-obfuscation infrastructure being reused across many opportunistic lures rather than a single brand or campaign.

References

No references.

Sublime Security
Created Aug 31st, 2026 • Last updated Aug 31st, 2026
Source
type.inbound
and any(body.links, regex.count(.href_url.path, '(?:~V~[NPQRSfhjlm]+)') >= 3)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started