• Sublime Core Feed
High Severity

Malformed URL prefix

Description

Malformed URL prefix is a technique used to evade email security scanners.

Sublime Security
Created Aug 17th, 2023 • Last updated Sep 4th, 2025
Source
any(body.links, regex.icontains(.href_url.url, ':/\\'))
or (
  regex.icontains(body.plain.raw, 'https?:\\\\[^\\s]+')
  and (
    length(filter(body.current_thread.links,
                  strings.icontains(.href_url.rewrite.original,
                                    "safelinks.protection.outlook.com"
                  )
           )
    ) == 0
    or not all(filter(body.current_thread.links,
                      strings.icontains(.href_url.rewrite.original,
                                        "safelinks.protection.outlook.com"
                      )
               ),
               strings.icontains(body.plain.raw, .href_url.domain.root_domain)
    )
  )
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started