
Spam: Sexually explicit content with emoji in subject from freemail provider
Sublime Rules
View SourceSummary
Technical rule to flag inbound emails that originate from freemail providers and contain sexually explicit content signaled by emoji in the subject, coupled with NLU-detected topics matching 'Sexually Explicit Messages'. The rule evaluates: sender.domain.root_domain is in the $free_email_providers list; subject matches an emoji regex; and the body thread text yields an NLU topic named 'Sexually Explicit Messages'. It is categorized as Spam with low severity. Detection methods include content analysis, header analysis, natural language understanding, and sender analysis. Potential false positives exist if legitimate messages use emojis in subject lines or if the NLU classifier mislabels content.
Categories
- Endpoint
- Web
Data Sources
- Domain Name
- Network Traffic
- Process
Created: 2026-03-11