{"success":true,"data":{"id":"subject-contains-email-address","label":"Subject contains a literal email address — fake-conversation shape, not a real reply","description":"The subject line contains a literal email address (e.g. `Re: Payment for john@acme.com — action required`). Phishers embed an address — usually the victim's own, or a plausible corporate one — to fake a threaded-conversation shape so the email feels personal and invites trust. Legitimate transactional email almost never puts a raw address in the subject; companies reference \"your account\" or an order number instead. Detection is guarded against three false-positive classes: it does not fire on actual replies or forwards (subjects starting with Re:/Fwd:/Sv:/Aw:/etc. are excluded — genuine conversation threads legitimately carry addresses from the original message into the subject), it does not fire when the address is an automation mailer local-part (`noreply@`, `no-reply@`, `donotreply@`, `mailer-daemon@`, `postmaster@`, `bounce@`, `notifications@`, `alerts@` — legitimate bug trackers and CI systems sometimes route via these), and the email regex requires a proper TLD of 2-24 chars so random `@` characters in punctuation don't match. Weight: +3, pairs with other signals (urgency, display-name-spoof) rather than solo-triggering.","tier":"warning","category":"subject","isThin":false}}