Medium Severity

Open redirect: Quickbase

Description

Detects inbound emails containing links to quickbase.com that use an API parameter alongside a redirect parameter (rdr=) pointing to a destination outside of quickbase.com, indicating potential abuse of Quickbase's redirect functionality to disguise malicious links. The rule excludes emails from quickbase.com or highly trusted sender domains that pass DMARC authentication.

References

No references.

Sublime Security
Created Oct 6th, 2026 • Last updated Oct 6th, 2026
Source
type.inbound
and any(body.links,
        .href_url.domain.root_domain == "quickbase.com"
        and strings.icontains(.href_url.query_params, 'a=API_')
        and strings.icontains(.href_url.query_params, 'rdr=')
        // make sure it's not redirecting back to quickbase.com
        and not regex.icontains(.href_url.query_params,
                                'rdr=(?:https?(?:%3a|:))?(?:%2f|\/)*[^&]*quickbase\.com(?:&|\/|$|%2f)'
        )
)
and not (
  sender.email.domain.root_domain == "quickbase.com"
  and coalesce(headers.auth_summary.dmarc.pass, false)
)
// negate highly trusted sender domains unless they fail DMARC authentication
and not (
  sender.email.domain.root_domain in $high_trust_sender_root_domains
  and coalesce(headers.auth_summary.dmarc.pass, false)
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started