{"success":true,"data":{"id":"href-forced-download","label":"Link bypasses file-sharing preview page — triggers immediate binary download","description":"A link href has a query parameter that bypasses the file-sharing preview page and triggers an immediate binary download. Parameters matched (case-insensitive): `dl=1`, `download=1`, `export=download` (Google Drive force-download), `force-download=1`, `attachment=1`, `inline=0`. Legitimate file-sharing flows on Dropbox, Google Drive, OneDrive, Box, and WeTransfer all take the recipient to a preview page first where they can see the filename, size, sender context, and a visible Download button before committing. Forced-download URLs skip the preview — the browser starts saving the file the instant the link is clicked, which is the phishing-specific pattern for pushing malware payloads. Weight: +3 — moderate. Some edge-case legit flows use `dl=1` (direct download of a single file the recipient already agreed to receive), so the signal is meant to combine with other evidence (urgency language, unfamiliar sender, generic subject, attachment-like body framing) rather than solo-trigger.","tier":"danger","category":"other","isThin":false}}