type.inbound
and length(body.links) > 0
and length(headers.reply_to) > 0
and (
any(headers.reply_to,
network.whois(.email.domain).days_old <= 30
and .email.email != sender.email.email
)
or network.whois(sender.email.domain).days_old <= 30
)
and any(distinct(body.links, .href_url.domain.root_domain),
network.whois(.href_url.domain).days_old < 14
)
Playground
Test against your own EMLs or sample data.