Embedded Hostile links

Pramod Daya pramod at mindspring.co.za
Mon Aug 23 10:49:45 UTC 2021


I'm seeing embedded hostile links in HTML formatted emails - which are not getting picked up by spearphishing detection.  When I look at the email as plain text, they don't show up..   I tried creating a rule to identify the suspicious sites (usually bit.ly) and I can't seem to detect it with a spamassassin rule that search the body of the email.   Is spamassassin not able to view HTML formatted emails ?

Any advice would be welcome.

Thank you,
