• Sublime Core Feed
Low Severity

Spam: Sexually explicit content with emoji in subject from freemail provider

Description

Detects messages from free email providers that contain sexually explicit content and include emojis in the subject line.

References

No references.

Sublime Security
Created Mar 10th, 2026 • Last updated Mar 10th, 2026
Source
type.inbound
// sender is a freemail domain
and sender.email.domain.root_domain in $free_email_providers
// look for commonly used emojis in sexually explicit messages
and regex.icontains(subject.subject,
                    '(\x{1F346}|\x{1F608}|\x{1F609}|\x{1F351}|\x{2764}|\x{1F60D}|\x{1F618}|\x{1F48B}|\x{1F63B}|\x{1F445}|\x{1F51E}|\x{1F525}|\x{1F4F7})'
)
and any(ml.nlu_classifier(body.current_thread.text).topics,
        .name == 'Sexually Explicit Messages'
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started