{"success":true,"data":{"id":"href-non-standard-port","label":"Link uses a non-standard port (:8080 / :8443 / etc.) — legit sites never expose these","description":"A link href includes an explicit `:port` that is not 80 (http) or 443 (https) — e.g. `https://login.example.com:8443/reset`. Legitimate public-facing services always sit behind a reverse proxy or CDN that terminates TLS on port 443; they never expose a non-default port in email links. Phishing kits routinely host on :8080 / :8443 / :2082 / :2083 because the attacker is running on a compromised shared-hosting account or residential broadband without control of the standard ports.","tier":"warning","category":"other","isThin":false}}