EXPLORE DETECTIONS
Open redirect: documentmailbox.com
Message contains use of the documentmailbox.com open redirect. This has been exploited in the wild.
Open redirect: Doubleclick.net
Doubleclick.net link leveraging an open redirect from a new or outlier sender.
Open redirect: eaoko.org
Message contains use of the eaoko.org redirect. This has been exploited in the wild.
Open redirect: easycamp.com
Message contains use of the easycamp.com open redirect. This has been exploited in the wild.
Open redirect: embluemail.com
Message contains use of the embluemail.com redirect. This has been exploited in the wild.
Open redirect: emlakarsa
Message contains use of the emlakarsa open redirect. This has been exploited in the wild.
Open redirect: emp.eduyield.com
Message contains use of the eduyield redirect which chains google amp. This has been exploited in the wild.
Open redirect: eodcnetworkdirect.com
Message contains use of the eodcnetworkdirect.com redirect. This has been exploited in the wild.
Open redirect: events.csiro.au
Message contains use of the events.csiro.au redirect. This has been exploited in the wild.
Open redirect: ExacTag
Message contains use of the ExacTag open redirect. This has been exploited in the wild.
Open redirect: fenc.com
Message contains use of the fenc.com open redirect. This has been exploited in the wild.
Open redirect: g7.fr
Message contains use of the g7.fr open redirect. This has been exploited in the wild.
Open redirect: Generic link.html redirector abuse
Detects messages that route recipients through a generic '/link.html' redirect path carrying an encoded destination in the URL fragment, then confirms via redirect-chain analysis that the link actually resolves to that embedded destination. This pattern is commonly abused in bulk spam and scam lures—such as fake storage-deletion warnings, loan offers, and discounted warranty plans—to disguise the true landing page behind a benign-looking tracking link.
Open redirect: giving.lluh.org
Message contains use of the giving.lluh.org redirect. This redirection has been abused by threat actors in the wild.
Open redirect: Google Ad Services
Message contains use of the Google Ad Services open redirect, but the sender is not Google. This has been exploited in the wild.
Open Redirect: Google domain with /url path and suspicious indicators
This rule examines messages containing image attachments that utilize Google's open redirect (google[.]com/url...). To enhance accuracy and minimize false positives, the rule conducts additional assessments for suspicious indicators, as indicated in the comments.
Open redirect: Google Web Light
Message contains use of the Google Web Light open redirect. Google Web Light was sunset on December 19 2022.
Open redirect: Hakumonkai.org
Detects inbound messages containing links or attachments with URLs that utilize the hakumonkai.org domain's redirect functionality (/fukkou/ref.php) to redirect users to external domains through the 'url' parameter.
Open redirect: HHS
Looks for use of the HHS open redirect.
Open redirect: ijf.org
Message contains use of the ijf.org redirect. This has been exploited in the wild.
Open redirect: Indeed
Detects emails containing links using Indeed '/r?target=xxxxxx' open redirect where the email has not come from indeed.com
Open redirect: IndiaTimes
Message contains use of the IndiaTimes open redirect. This has been exploited in the wild.
Open redirect: isadatalab.com
Message contains use of the isadatalab.com open redirect. This has been exploited in the wild.
Open redirect: JustPaste.it
Detects inbound messages containing JustPaste.it redirect links that forward to external destinations outside of JustPaste.it. This technique abuses JustPaste.it's redirect functionality to obscure the true destination URL, bypassing link reputation checks. The rule excludes legitimate senders from JustPaste.it itself.