
Summary
This rule detects inbound emails that abuse the newslit.co email redirect service by including a link whose domain is newslit.co and whose path starts with /email/redirect/ with a non empty query parameter u. The destination of the redirect is the URL specified in the u parameter, and the rule flags messages where that destination does not point back to newslit.co. It excludes messages from newslit.co and other highly trusted sender domains that pass DMARC authentication, as well as any sender in the predefined high-trust list that passes DMARC. In effect, it looks for open redirect abuse intended to bypass content filters or to misdirect recipients to credential phishing sites. The rule is triggered as a potential credential phishing or spam event and uses URL analysis and header analysis. It is important to ensure the high-trust domains list and DMARC status sources are kept up to date to minimize false positives, and to be aware that variations in redirect patterns or encoding could affect coverage.
Categories
- Network
- Endpoint
- Web
Data Sources
- Application Log
Created: 2026-10-09