Body content
65 signals in this category. Every entry links to a full explanation, severity tier, and false-positive notes.
- Account phishing — suspension threat + action demandthreat
account-phishing-body - Advance-fee fraud (419) — identity claim + fund transfer requestthreat
advance-fee-fraud-body - Password-protected archive with password disclosed in body — malware deliverythreat
archive-password-in-body - Blob/JavaScript URI in Anchor Hrefthreat
body-blob-javascript-uri-href - Body mentions an attachment but the email has none — phishing primer for the next link clickwarning
body-claims-attachment-but-none - P2P payment app request (CashApp/Venmo/Zelle — no buyer protection)warning
body-contains-p2p-payment-request - Signal messenger link in body (move-off-email scam shape)warning
body-contains-signal-contact - Body drives victim to a Telegram handle — crypto-scam 1-on-1 funnelwarning
body-contains-telegram-handle - WhatsApp contact in body (move-off-email scam shape)warning
body-contains-whatsapp-contact - Fullwidth ASCII Character Evasionthreat
body-fullwidth-ascii - Cyrillic lookalike characters mixed with Latin (keyword evasion)threat
body-homoglyph-obfuscation - Body encodes text via 5+ consecutive HTML entities — keyword-scanner evasionthreat
body-html-entity-obfuscation - Body inserts zero-width chars between letters of keywords — filter evasionthreat
body-invisible-char-obfuscation - Invisible Unicode padding (ZWJ/ZWNJ/soft-hyphen evasion)warning
body-invisible-padding - Body has 10+ consecutive blank lines — pushing scam content below the preview foldwarning
body-long-whitespace-padding - Body is tiny but contains a link — classic phishing "click here to verify" templatewarning
body-minimal-text-with-link - Cyrillic/Greek Homoglyph in Bodythreat
body-mixed-script-homoglyph - Bare bank account number without invoice contextthreat
body-only-bare-account-number - OTP relay requestthreat
body-otp-relay-request - Bank/payment details claim to have changed (BEC fraud)threat
body-payment-details-override - Promotional keywords in Swedish or German body (≥2 matches)warning
body-promo-multilingual - RTL Override Bidi Character in Bodythreat
body-rtl-override-chars - Soft Hyphen Keyword Obfuscationthreat
body-soft-hyphen-obfuscation - Body contains Unicode tag characters (U+E00xx) — ASCII smuggling / prompt injectionthreat
body-unicode-tag-chars - Unsubscribe link in bodywarning
body-unsubscribe-link - Body uses "only N hours remaining" / "last X days left" pressure — FOMO scam fingerprintwarning
body-urgency-countdown - Clickbait phrases in bodywarning
clickbait-subject-body - Crypto wallet address in body — Bitcoin/Ethereum address near a payment/send/wallet context wordthreat
crypto-wallet-address-in-body - Double opt-in confirmation linkwarning
double-opt-in-body - Multiple emojis in body (marketing style)warning
emoji-cluster-body - ESP name detected (Mailchimp, SendGrid, etc.)warning
esp-name-in-body - Excessive exclamation marks (5+) in bodywarning
excessive-exclamation-body - Image-Only Spam Patternwarning
external-image-flood-no-text - Promotional content in a forwarded/reply email (thread hijack for promo delivery)warning
fake-fwd-promo-body - Inline <form> in email body (credential harvester)threat
form-in-body - From header contains Unicode tag characters (U+E00xx) — ASCII smuggling / prompt injectionthreat
from-unicode-tag-chars - Grandparent / emergency impersonation scam — family member in trouble + bail/secrecy demandthreat
grandparent-scam-body - Hidden text via CSS — display:none / visibility:hidden / white-on-white (classifier-poisoning)threat
hidden-text-in-body - Zero-width char inside link anchor text (mismatch-check evasion)threat
href-anchor-invisible-chars - Zero-width / bidi chars inside an email link — URL obfuscationthreat
href-contains-invisible-chars - HTML-only email (no plain text)warning
html-only-no-plaintext - Embedded <iframe> in email bodythreat
iframe-in-body - Inline event handler in body — onclick / onerror / onload in an HTML tag (script execution vector)threat
inline-event-handler-in-body - Investment / crypto scam — guaranteed returns + investment vehiclethreat
investment-scam-body - Invisible control characters in From header — zero-width joiner / RTL override attackthreat
invisible-chars-in-from - Invisible Unicode whitespace padding (marketing)warning
invisible-whitespace-padding - Job scam — unrealistic pay offer + upfront payment or data extractionthreat
job-scam-body - Lottery / prize scam — winning claim + fee or detail extractionthreat
lottery-prize-scam-body - HTML-only — no plain-text fallbackwarning
mime-html-only-no-plaintext - Near-empty body (image-only or link-only spam)warning
no-text-body - Off-screen text via CSS position — left/top/right/bottom: -9999px (classifier-poisoning)threat
offscreen-text-in-body - <input type="password"> in email body (credential harvester)threat
password-input-in-body - Bulk merge-tag placeholder in bodywarning
personalization-token-body - Promotional content embedded in calendar invite bodywarning
promo-content-in-calendar-body - Romance scam — fake relationship + money/gift card requestthreat
romance-scam-body - <script> tag in email body — near-perfect attack indicator (exfiltration / redirect)threat
script-in-body - SVG <foreignObject> embedded HTML (sandbox bypass)threat
svg-foreign-object-in-body - Tax Authority Impersonationthreat
tax-authority-impersonation-body - Tech-support scam — fake security alert + call-our-technician demandthreat
tech-support-scam-body - "Too good to be true" promiseswarning
too-good-to-be-true - Contains tracking pixelwarning
tracking-pixel-in-body - Trial ending tomorrow / last day (body)warning
trial-ending-body - Urgency deadline language in bodywarning
urgency-deadline-body - ZeroFont NLP evasion — 2+ invisible spans stuffed with random natural-language noise words to dilute AI classifier signalthreat
zero-font-random-word-salting - Zero-width character keyword obfuscationthreat
zero-width-joiner-keyword-obfuscation
Want to see them in action?
Connect your Gmail in 10 seconds and Gorganizer will show you exactly which signals fired on every email — colour-coded by severity, with full explanations.
Get started