{"success":true,"data":{"id":"message-id-freewebmail-mismatch","label":"Message-ID on free webmail but From is corporate (forgery)","description":"The `Message-ID` header domain is a free webmail provider (gmail.com, yahoo.com, outlook.com, icloud.com, protonmail.com, etc.) while the `From` header domain is a corporate/branded domain. Shape: `From: support@paypal.com` with `Message-ID: <abc@gmail.com>`. Real branded senders never generate Message-IDs on free-webmail domains — their MTAs always stamp the sending-server domain. An attacker who crafts a spoofed From header but sends the email from a personal gmail mailbox leaves this fingerprint in the Message-ID that most MUAs never display. Precision rules prevent false positives on gmail-to-gmail legitimate forwards: the signal only fires when the From domain is NOT free webmail AND the Message-ID domain IS free webmail. Weighted at +5 — high-confidence forgery signal with essentially zero legitimate-use rate.","tier":"danger","category":"header","isThin":false}}