What is the purpose of confusing HTML links in spam emails?

Summary

Confusing HTML links in spam emails serve a multifaceted purpose: to deceive users and evade spam filters. These links utilize techniques such as URL shortening, redirects, HTML obfuscation, and masking to hide the true destination, making the link appear legitimate and trustworthy. This obfuscation aims to confuse both humans and less sophisticated spam filters, increasing the likelihood of clicks and inbox delivery. Furthermore, these links often incorporate tracking mechanisms, sometimes embedding personalized data to monitor user behavior.

Key findings

  • Dual Deception: Confusing links are designed to deceive both human recipients and spam filters.
  • Obfuscation Techniques: Spammers employ various methods, including URL shortening, redirects, and HTML masking, to hide the true destination URL.
  • Filter Evasion: Complex HTML structures and obfuscation techniques are used to bypass spam filter detection.
  • Tracking Implementation: Obfuscated links often include tracking mechanisms to monitor user interaction and behavior.
  • Brand Spoofing: Techniques like using trusted brands and unicode domains make the links appear legitimate, particularly on mobile devices.

Key considerations

  • URL Verification: Always verify the destination URL before clicking, especially in unsolicited emails, by hovering over the link (when possible) or using URL scanning tools.
  • Mobile Caution: Exercise extra caution when clicking links on mobile devices, as it's often harder to preview the destination.
  • Sender Authenticity: Carefully examine the sender's address and email content for irregularities or inconsistencies.
  • Security Software: Utilize security software with anti-phishing and anti-malware capabilities to protect against malicious links.
  • Personal Data: Be aware that clicking on obfuscated links may expose your personal data and online behavior to tracking.

What email marketers say
7Marketer opinions

Confusing HTML links in spam emails serve multiple purposes, primarily centered around deception and evasion. They are used to hide the true destination URL from both recipients and spam filters. This is achieved through techniques such as URL shorteners, redirects, cloaking, masking, and unusual formatting. The aim is to make the link appear legitimate or unrecognizable to automated systems, tricking users into clicking while also bypassing spam filters.

Key opinions

  • URL Obfuscation: Spammers use URL shorteners, redirects, and other methods to hide the actual destination of the link.
  • Spam Filter Evasion: Confusing HTML links are designed to bypass spam filters by making the link look legitimate or unrecognizable.
  • User Deception: Techniques like cloaking, masking, and using trusted brands are employed to trick users into clicking on malicious links.
  • Mobile Vulnerability: Deceptive links are especially effective on mobile devices where users cannot easily hover over the link to preview the destination.
  • Bypass Detection: Obfuscation in URLs is to evade detection to prevent people from recognizing that it is malicious.

Key considerations

  • URL Preview: Always preview URLs before clicking, especially in unsolicited emails.
  • Mobile Awareness: Be extra cautious when clicking links on mobile devices due to the difficulty in previewing URLs.
  • Brand Trust Verification: Verify the legitimacy of the sender, even if the link appears to be from a trusted brand.
  • Filter Awareness: Understand that spam filters are not foolproof and may be bypassed by sophisticated obfuscation techniques.
  • Security Software: Consider security software to provide another layer of protection.
Marketer view

Email marketer from Mailjet shares that confusing HTML links are used to obfuscate the actual destination URL from users and spam filters. This makes it harder to identify the link as malicious. They often use redirects or URL shorteners to achieve this.

June 2024 - Mailjet
Marketer view

Email marketer from Norton explains that the reason that spam emails use cloaking and redirects is to hide where you are actually going, and to get around spam filters. The email will still look like a legitimate link that you trust.

February 2022 - Norton
Marketer view

Email marketer from Neil Patel Digital explains that spammers use URL shorteners and redirects to hide the true destination of the link. This makes it difficult for recipients to know where they are going when they click on a link, and it also makes it more difficult for spam filters to identify malicious links.

March 2024 - Neil Patel Digital
Marketer view

Email marketer from Reddit user u/ScamBuster explains that deceptive links are made to look legitimate by using trusted brands, using redirects, or even using unicode domains. This will trick a user into clicking, especially on mobile where the user can't hover over the link.

November 2022 - Reddit
Marketer view

Email marketer from Reddit user u/cybersecurityanswers explains that the purpose of confusing links is that they hide the true destination of the link. This way, recipients might click on it without realizing the risk. Redirects and URL shorteners are common techniques.

January 2023 - Reddit
Marketer view

Email marketer from SendPulse states that confusing HTML links, especially those with redirects and unusual formatting, are used to bypass spam filters. The goal is to make the link look legitimate or unrecognizable to automated systems while still leading the user to a malicious site.

June 2021 - SendPulse
Marketer view

Email marketer from VadeSecure shares that the intent of obfuscation in URLs is to evade detection. This can be masking, redirects and many other methods to prevent people from recognizing that it is malicious, or to trick systems into believing it is legitimate.

November 2022 - VadeSecure

What the experts say
3Expert opinions

Confusing HTML links in spam emails serve several purposes. Primarily, they aim to confuse humans and basic spam filters by using complex code. Additionally, these links are employed for tracking purposes, sometimes incorporating personally identifiable information like email addresses. Ultimately, the objective is to evade detection by both users and filters to increase the likelihood of the email reaching the inbox and the link being clicked.

Key opinions

  • Confusion Tactic: Confusing HTML links aim to disorient both humans and basic spam filters lacking sophisticated HTML parsing capabilities.
  • Tracking Mechanism: Obfuscated links enable spammers to track users who click on the links, sometimes embedding personalized data for enhanced tracking.
  • Detection Avoidance: The use of confusing HTML is a strategy to bypass detection by users and spam filters, increasing deliverability and click-through rates.

Key considerations

  • HTML Interpretation: Be wary of emails with unusual or complex HTML structures, as they may be attempts at obfuscation.
  • Privacy Implications: Consider the potential privacy implications of clicking on obfuscated links, as they may be used to track your online behavior.
  • Filter Limitations: Recognize that spam filters are not always effective at detecting sophisticated obfuscation techniques and exercise caution.
Expert view

Expert from Email Geeks explains that the confusing HTML link with the Microsoft domain is there to confuse humans (and, perhaps, really crappy spam filters) that don’t talk HTML. The `target=“blank”` attribute makes them think the spamware may be a bit vague on it too.

January 2025 - Email Geeks
Expert view

Expert from Word to the Wise Team explains that confusing HTML links are used to avoid detection by users and spam filters, making it more likely that the user will click the link and that the email will be delivered to the inbox.

February 2023 - Word to the Wise
Expert view

Expert from Spam Resource explains that obfuscated links are often used for tracking. They mention that one client saw spammers use a URL rewriting scheme that included the original recipient's email address, allowing the spammers to track who clicked the link.

August 2022 - Spam Resource

What the documentation says
3Technical articles

Confusing HTML links in spam emails are primarily used to disguise the actual destination URL, making it appear legitimate and trustworthy. This is achieved through various techniques, including URL shortening, redirects, and HTML formatting. The ultimate goal is to deceive users into clicking on these links, leading them to malicious websites while bypassing their suspicion.

Key findings

  • URL Disguise: Spammers use various methods to hide the true destination of a link, making it difficult to identify malicious intent.
  • Deception Technique: The primary aim is to deceive users by making the link appear safe and trustworthy, increasing the likelihood of a click.
  • Phishing Tactic: Confusing links are a common tactic in phishing and spam campaigns to lead users to malicious websites.

Key considerations

  • Verify URLs: Always verify the destination URL before clicking on any link, especially in unsolicited emails.
  • Hover Preview: Hover over links to preview the destination URL, but be aware that this can also be spoofed.
  • Trust No One: Be cautious of emails from unknown senders or with suspicious content, even if they appear to be from legitimate sources.
Technical article

Documentation from Microsoft explains that attackers use various techniques to hide the true URL of a link, including URL shortening, redirects, and HTML formatting. This is done to deceive users into clicking on malicious links by making them appear safe.

August 2023 - Microsoft Support
Technical article

Documentation from Cisco explains that one tactic used by spammers is to make the URL look trustworthy to prevent recipients from recognizing it as malicious and to get them to click on the link. This is called masking and is often performed using confusing HTML.

February 2022 - Cisco
Technical article

Documentation from Google Support explains that a common tactic used in phishing and spam is to disguise the actual URL behind a misleading link. This can be done using HTML or URL shortening services to make the link appear legitimate while leading to a malicious website.

July 2023 - Google Support