{"success":true,"data":{"id":"href-mailto-cross-domain","label":"Body has a mailto: link to a different domain than the sender — reply-funnel scam shape","description":"The email body contains a `<a href=\"mailto:X@Y\">` link where the mailto address domain Y is different from the sender's From-header domain. This is the canonical reply-funnel scam pattern: a teaser email with a CTA saying \"email me at scammer@gmail.com to learn more\" — the goal is to move the conversation off the structured mail filter and into a 1-on-1 channel where social engineering is harder for downstream filters to catch. Real businesses link to mailto only with their own corporate domain (sales@company.com next to a from address ending in @company.com). The cross-domain mailto pattern is essentially diagnostic of the reply-funnel shape — legitimate \"reach out via this address\" emails use the same domain. Weighted at +3, pairs well with other reply-funnel signals (free-webmail sender, urgency-bait subject, telegram-handle in body) without being solo-decisive.","tier":"danger","category":"other","isThin":false}}