Text-Salting Phish Bypasses AI Email Filters

eSecurity Planet · Medium sophistication
Last updated July 30, 2026

Barracuda reports seeing more than one million retail-themed phishing emails since April that use “text salting,” where attackers hide large amounts of harmless text inside the message to trick automated email security tools. The victim sees a normal-looking urgent lure (like expiring rewards points), while hidden HTML/CSS content changes how some detection engines score the email. The campaign also uses authenticated-looking sending infrastructure (e.g., DKIM) and multiple hiding techniques to improve delivery.

How the attack worked

Barracuda identified more than one million retail-themed phishing emails since April built around a technique called text salting. Recipients see a normal-looking urgent message, often claiming that rewards points, loyalty benefits, or a gift card are about to expire and encouraging immediate action. Behind that visible lure, the email's HTML/CSS contains large blocks of unrelated, benign-looking text that is hidden from the reader but present in the underlying code.

A related variant uses a technique called Zero Font, which inserts random hidden words directly inside a recognizable phishing phrase and sets the inserted text to a font size of zero. For example, the underlying HTML may read "Your pass [hidden text] word expired," while the recipient only sees "Your password expired." The campaign also relies on trusted infrastructure, authenticated domains, hidden HTML content, and CSS concealment techniques to improve delivery and reduce suspicion.

Why it succeeded

These emails work because the two layers of content serve different purposes. The visible layer is a simple, believable, urgent lure tied to something many people actually have, like rewards points or a gift card. The hidden layer is designed purely to manipulate how automated detection engines classify the message. Because some security tools scan the raw HTML or source code rather than what the user actually sees, the extra hidden text or invisible inserted words can throw off pattern-matching and signature-based detection, letting messages that would otherwise be flagged slip through to the inbox. Authenticated-looking sending infrastructure, including DKIM configured on lookalike or compromised domains, adds another layer of apparent legitimacy.

What to watch for

  • Urgent emails about expiring rewards points, loyalty benefits, or gift cards, especially when unrelated to a recent purchase or account activity
  • Generic password-expired notices that are not tied to specific account context
  • Links that may not lead to the retailer's or service's real domain, even when the email itself looks legitimate
  • Any unusual formatting or hidden HTML artifacts if you inspect a suspicious message's source

Building resistance

Employees, especially in customer support and sales roles that regularly handle retail-related email, should verify urgent expiration claims through a separate, trusted channel, such as typing the retailer's URL directly rather than clicking an embedded link. For password-reset or login requests, use a known bookmark or official portal instead of following a link in the email. Security and IT/identity teams should ensure email defenses analyze the message as it actually renders for the recipient, not just the raw HTML or source code, since that is where hidden content like text salting and Zero Font is designed to operate undetected.

Key findings

  • Barracuda identified “more than one million retail-themed phishing emails since April” using text salting.
  • The lure is visible to the user, while “large blocks of unrelated text” are hidden in the email to influence how AI/ML tools classify it.
  • Attackers used “trusted infrastructure, authenticated domains, hidden HTML content, CSS concealment techniques, and Zero Font.”
  • The visible message pushes urgency around “rewards points, loyalty benefits, or gift cards” expiring.
  • Some emails may pass authentication checks because they are configured to pass DKIM on lookalike or compromised infrastructure.

Who’s being targeted

  • Commonly targeted roles: All employees, Customer support, Sales, IT/Identity teams, Security awareness trainees.
  • Affected industries: Retail, All industries using email (cross-industry).
  • Attack channels: email.
  • Impersonated: Retail loyalty/rewards program, Account/identity support (generic).

Red flags to watch for

  • Creates urgency around expiring benefits/gift cards
  • Unexpected rewards/loyalty email not tied to a recent purchase/account
  • Link destination may not match the real retailer, even if the email looks legitimate
  • “Password expired” message is generic and not tied to your actual account context
  • Login/reset links that do not go to the company’s real sign-in domain
  • Email may contain unusual formatting/HTML artifacts if inspected (hidden content tricks)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is text salting in phishing emails?

Text salting is a technique where attackers hide large blocks of harmless-looking text inside a phishing email's HTML/CSS to change how automated detection tools score the message, while the visible message the user sees stays the same.

What is Zero Font in phishing emails?

Zero Font is a technique that embeds random hidden words inside recognizable phishing phrases and sets that inserted text to a font size of zero, so it is invisible to the recipient but can confuse signature-based detection scanning the raw HTML.

How many phishing emails used this technique?

Barracuda identified more than one million retail-themed phishing emails since April that used text salting.

How can I spot this kind of phishing attack?

Treat urgent messages about expiring rewards points, loyalty benefits, or gift cards as suspicious, and verify password-reset or login requests through a known bookmark or official portal rather than an embedded link.

Read the video transcript

You get an email: “Your rewards points are about to expire, act now.” It looks totally normal… and it passed all our filters. Behind that one line, the HTML is stuffed with hidden junk text, “text salting,” plus tricks like Zero Font, so AI email filters think it’s harmless while you just see an urgent rewards offer. Barracuda’s already seen over a million of these retail-themed emails since April, some even using authenticated-looking domains so DKIM passes. The only real tell? That “expiring rewards” or “password expired” panic, out of nowhere. If an email says rewards or a password are about to expire, don’t click the email. Type the retailer or account URL yourself and check from there.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

July 31, 2026
LogoKit Builds Real-Time Fake Login Pages

LogoKit Builds Real-Time Fake Login Pages

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

July 29, 2026
Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

July 31, 2026