Description

Catches messages where the sender address is spoofed to match the recipient (failing DMARC), simulating a self-forwarded email. The HTML body contains a hidden (display:none) block mimicking Outlook-style forward/reply headers (From/Sent/Subject), used to disguise injected lure content such as fake remittance receipts or finance document notifications. An NLU classifier confirms the thread content carries malicious intent rather than benign forwarding.

References

No references.

Sublime Security
Created Oct 6th, 2026 • Last updated Oct 6th, 2026
Source
type.inbound
// self sender
and (
  sender.email.email == recipients.to[0].email.email
  and not coalesce(headers.auth_summary.dmarc.pass, false)
)
// a hidden quoted reply header... we can use translate() lowercases
// and strip spaces so `DISPLAY:NONE` or `display: none` would both match
// https://developer.mozilla.org/en-US/docs/Web/XML/XPath/Reference/Functions/translate
and any(html.xpath(body.html,
                   '//*[contains(translate(@style, "ABCDEFGHIJKLMNOPQRSTUVWXYZ ", "abcdefghijklmnopqrstuvwxyz"), "display:none")]'
        ).nodes,
        // outlook-style headers... long to/cc lists can sit between sent and subject
        regex.icontains(.raw, 'From:.{0,1000}Sent:.{0,1000}Subject:')
)
and any(ml.nlu_classifier(body.current_thread.text).intents, .name != 'benign')
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started