{"success":true,"data":{"id":"script-in-body","label":"<script> tag in email body — near-perfect attack indicator (exfiltration / redirect)","description":"HTML body contains a `<script>` tag. Legitimate emails NEVER contain script tags — modern email clients (Gmail, Outlook, Apple Mail) strip them for security, and no legitimate newsletter platform or transactional email provider ships them. Any presence is a near-perfect attack indicator: the only entities that embed scripts in email bodies are attackers trying to exfiltrate data, redirect the user on preview, or run XSS-style exploits against legacy/mobile clients that don't strip reliably. Weighted at +5 (same as iframe-in-body — another client-side-execution vector).","tier":"danger","category":"body","isThin":false}}