Attachments
7 signals in this category. Every entry links to a full explanation, severity tier, and false-positive notes.
- Archive attachment (.zip/.rar/.7z — common spam delivery)warning
archive-attachment - Attachment filename mixes Latin with Cyrillic/Greek (homograph)threat
attachment-filename-mixed-script - Attachment has no filename — malformed bulk mailer or deliberate content-scanner evasionwarning
attachment-no-filename - Bidi override in attachment filename — invoice.exe masquerading as invoice.pdfthreat
attachment-rtl-override-in-name - PDF + credential harvest subjectthreat
pdf-embedded-form-phishing - Password-protected PDF with phishing indicators in bodythreat
pdf-password-phishing - Tracking pixelwarning
small-tracking-image
Want to see them in action?
Connect your Gmail in 10 seconds and Gorganizer will show you exactly which signals fired on every email — colour-coded by severity, with full explanations.
Get started