ZeroFont Phishing

ZeroFont Phishing image
What is it?
Hidden text in emails using font-size:0 or similar CSS tricks. Appears in preview pane but not in the visible body to falsely reassure recipients.

Testing?

  • Inspect raw HTML > Look for <span style="font-size:0px"> or display:none tags.
  • Compare preview vs body > If preview mentions “secure” or “verified” but body doesn’t, flag it.
  • Search for suspicious phrases > Hidden text often says “This email is safe” or “Verified sender.”
  • Automation > flag any zero-font or hidden text in email HTML.
  • Cross-Client checks > test in Gmail, Outlook, Apple Mail - as we all know behavior varies.
  • Educate users and peers > remind them 'Preview text can be manipulated - verify sender and links before clicking.'

See also - how to identify people using AI when applying for jobs...
Explore MoT
AI-driven testing in practice: from requirements to reliable automation image
See where AI genuinely helps, where it doesn’t, and how testers can stay firmly in control
MoT Software Testing Essentials Certificate image
Boost your career in software testing with the MoT Software Testing Essentials Certificate. Learn essential skills, from basic testing techniques to advanced risk analysis, crafted by industry experts.
Into The Motaverse image
Into the MoTaverse is a podcast by Ministry of Testing, hosted by Rosie Sherry, exploring the people, insights, and systems shaping quality in modern software teams.
Subscribe to our newsletter