Text salting exposes a blind spot in AI email security

An old evasion technique is finding new ways to influence modern detection systems.

Text salting

AI has made email security more powerful, but it hasn’t changed a basic reality: attackers continually adapt their techniques to influence how messages are evaluated. One technique drawing renewed attention is text salting, which researchers have observed in campaigns designed to influence how modern detection systems assess email content.

An old trick with a new target

Text salting itself is not new. More than two decades ago, spammers learned to bury nonsense text and misspelled keywords inside emails to slip past the earliest secure email gateways, which scored messages based on how many “bad” words they contained. Load an email up with enough harmless filler, and the ratio of suspicious language to safe language drops low enough to sneak through.

Modern email security has evolved significantly since the early days of keyword-based spam filtering. But as Barracuda’s research demonstrates, attackers continue to adapt longstanding evasion techniques to affect how both traditional and AI-powered detection systems assess email content.

Attackers hide benign words, random stories or ordinary-looking work notes inside a phishing email’s underlying HTML. The recipient sees only the phishing lure. The security tool may see hundreds of harmless words surrounding it and conclude that the message is legitimate. In one example from the research, attackers split the word “password” by inserting invisible filler between “pass” and “word” – a scanner searching for the phrase “your password expired” never finds it, even though that’s exactly what the recipient reads on screen.

Text salting was originally designed to confuse keyword-based spam filters. Now attackers are discovering it can also influence machine learning models and LLM-based security tools that analyze an email’s intent, purpose, sentiment, and risk.

The scale is the story

Barracuda researchers recently detected more than one million phishing emails using text-salting techniques since April. The campaigns used familiar retail-themed lures involving rewards, gift cards and expiring offers. Attackers concealed the filler content using layered techniques – CSS instructions that crop the visible window to nothing, zero-size fonts, and text positioned thousands of pixels outside the visible screen – so that if one concealment method gets caught, the others keep the copy hidden from the recipient.

Generative AI helps to make this scalable. Instead of reusing the same filler paragraph across a campaign, attackers can generate a unique, normal-sounding story for every single email – a project update, a weekend recap, a training note – making each message different enough to defeat signature-based detection while still hiding the same malicious link underneath.

Why this matters for MSPs

There’s an important lesson here for MSPs: AI-powered security is only one layer of defense.

Attackers don’t need to defeat security tools outright. They only need to influence how those tools assess a message. Text salting is designed to do exactly that, making phishing emails appear more legitimate than they really are.

Many of the campaigns identified by Barracuda also used compromised legitimate websites or lookalike domains with valid DKIM authentication. This means a malicious email can pass authentication checks while still delivering a convincing phishing lure, reinforcing the need for layered detection and user awareness.

Three steps MSPs should take now

First, ask security vendors how their tools distinguish between the email source code and what the recipient actually sees. Effective defenses should identify hidden content, unusual HTML-rendering behavior and significant differences between the machine-readable and user-visible versions of a message. If a vendor can’t answer that question clearly, that’s worth noting.

Second, make sure email security decisions aren’t based too heavily on content analysis. Sender reputation, behavioral anomalies, authentication results, embedded links, message structure, and historical communication patterns all provide important context. No single signal should determine whether a message reaches the inbox. A clean DKIM record is a good signal – it isn’t a guarantee, since attackers can configure it too.

Third, reinforce the human layer. Customers should know that authentication checks and professional-looking messages do not guarantee legitimacy. Regular training, simple reporting procedures and a rapid response process can limit the damage when a salted message slips through. The retail-themed lures behind this latest wave – expiring rewards, gift cards, redemption deadlines – work precisely because they create urgency. A quick reminder that urgency itself is a red flag can go a long way.

This isn’t an argument against AI-powered email security. It’s a reminder that every defensive innovation becomes something attackers will study, test and try to manipulate.

Technology changes quickly. The fundamentals of strong security do not. Layered controls, continuous testing and informed users remain essential.

When was the last time you asked your email security provider to demonstrate how its platform handles the difference between what a scanner reads and what your customer actually sees?


Pranati Sethy, Senior Threat Analyst at Barracuda Networks

Pranati Sethy is a Senior Threat Analyst for Barracuda Networks, specializing in leading advanced threat detection with rapid investigation to safeguard our customers. With deep, hands-on experience in both threat intelligence and data security, she thrives in fast-paced, multitasking environments where agility is paramount. Her core mission is to always stay ahead of the curve, proactive and vigilant, ensuring Barracuda customers remain steps ahead of emerging cyber threats and sophisticated attackers.

×