ZeroFont Phishing

ZeroFont Phishing image
What is it?
Hidden text in emails using font-size:0 or similar CSS tricks. Appears in preview pane but not in the visible body to falsely reassure recipients.

Testing?

  • Inspect raw HTML > Look for <span style="font-size:0px"> or display:none tags.
  • Compare preview vs body > If preview mentions “secure” or “verified” but body doesn’t, flag it.
  • Search for suspicious phrases > Hidden text often says “This email is safe” or “Verified sender.”
  • Automation > flag any zero-font or hidden text in email HTML.
  • Cross-Client checks > test in Gmail, Outlook, Apple Mail - as we all know behavior varies.
  • Educate users and peers > remind them 'Preview text can be manipulated - verify sender and links before clicking.'

See also - how to identify people using AI when applying for jobs...
Explore MoT
Leading with AI - The London Edition image
Fri, 19 Jun
A half-day educational experience to navigate the world of AI
MoT Software Testing Essentials Certificate image
Boost your career in software testing with the MoT Software Testing Essentials Certificate. Learn essential skills, from basic testing techniques to advanced risk analysis, crafted by industry experts.
This Week in Quality image
Debrief the week in Quality via a community radio show hosted by Simon Tomes and members of the community
Subscribe to our newsletter