The Dangers of Text Salting for Your Business

Spam filters are designed to protect users from cyberthreats by automatically blocking malicious, fraudulent, and unwanted emails, such as phishing scams. Unfortunately, cybercriminals are finding ways to sneak past them, resulting in more spam landing in email inboxes.

One increasingly common technique is text salting. In this blog post, we will discuss what it is and how cybercriminals exploit it. We’ll also explain how a managed security services provider like Techmedics can help you stay safe from these tactics.

What is Text Salting and How Does It Work?

Also known as email salting, text salting is a deceptive technique used by threat actors to bypass spam email filters.  

It involves hiding large amounts of random, benign text within an email’s underlying code to fool email scanning systems into misclassifying the malicious message as safe.

Threat actors hide the text through the following methods:

  • CSS Cropping: This sets the visible window small enough that humans cannot see the hidden filler text.
  • Zero-Font: Inserting harmless, misleading words in zero-pixel size into phishing copy. This text is visible to machines but not to humans.
  • Extreme Indentation: Moving the hidden text thousands of pixels off the left or right edge of the screen so it remains invisible to the user.
  • Zero-Width Spaces: Inserting invisible spaces between letters in a keyword or malicious domain so standard keyword-based filters fail to recognize it.

Whichever technique a threat actor chooses, the end result is an email that appears more legitimate to a machine, leading it to flag the message as safe and deliver it to a user’s inbox instead of the junk or spam folder.

A text-salted phishing email normally looks like this to a human:

Subject: Urgent: Your Account Has Been Locked

Dear [name],

Your account has been locked by our system due to suspicious activity. To restore your access immediately, please click on the link below. Thank you so much for your attention to this matter.

Best,

[Company name]

However, a machine sees the following behind all the text:

Dear [name],

Your account has been locked by our system due to suspicious activity.

<span style="font-size:0px;">banana chair sunshine holiday</span>

To restore your access immediately, please click on the link below. Thank you so much for your attention to this matter.

<div style="position:absolute;left:-9999px;">

  free gift offer happy puppy

</div>

Best,

[Company name]

In this example, “banana chair sunshine holiday” is invisible to a user but visible to an email filter. “Free gift offer happy puppy” is shoved far off the screen so humans never see it.  

What Happens When Text Salting Tricks AI?

Many modern email security platforms can detect text salting techniques. For instance, they can forcibly reveal hidden text, normalize email code to strip away obfuscation, or flag emails with large volumes of hidden content or unusual formatting.

However, a recent report by cybersecurity and cloud storage company Barracuda Networks found that artificial intelligence (AI) struggles to catch text salting tactics.

According to Barracuda, many AI filters don’t account for whether text is actually visible to the user. To the AI, the email just looks like gibberish padded with neutral words, so it assumes the message is fine. But to the human recipient, the email appears clean and persuasive, exactly as the attacker intended.

What’s more, attackers are now using AI for text salting. Rather than manually stuffing emails with random hidden words, they simply let AI generate endless, natural-sounding filler paragraphs. As a result, instead of obvious gibberish, the additional text sounds like real content, making it harder for filters to flag.

Since April 2026, Barracuda researchers have detected more than a million phishing attacks using text-salting techniques designed to trick both traditional and AI-powered email security systems.

Why Should Your Business Be Concerned with Text Salting?

With some AI-powered email defenses themselves being bypassed by text salting, your business could get exposed to greater risks, such as:

  • Inbox Visibility: Employees are more likely to open and trust emails that arrive in their inbox versus those flagged as junk.
  • Higher Clickthrough Risk: If the email looks normal, even the most cautious users may ignore subtle red flags and click on fraudulent links or download malicious attachments.
  • Training Gap: Some security awareness programs teach employees to distrust emails in spam or junk folders. If text-salted phishing emails land in the inbox, that safety net vanishes.
  • Volume Effect: If more phishing emails land in employees’ inboxes, the greater the chance that someone in the organization will fall for the trap and cause a security breach.

How Can Your Business Stay Protected from Text Salting?

To lessen the chances of text-salted messages landing in employees’ inboxes, Barracuda recommends a layered approach to email security. This means strengthening analysis with controls that check message structure, sender reputation, behavioral anomalies, embedded links, and user-visible content.

Your security tools must also be able to detect and expose hidden-content abuse and differences between the message’s underlying source code and the user-facing content.

Most importantly, these approaches must be supported by regular security awareness training for employees. This way, they can easily spot the latest warning signs of email threats and prevent the risk of security incidents.

How Techmedics Can Help Secure Your Business

Another powerful way to mitigate the dangers of text-salted emails is by partnering with a reliable managed security services provider like Techmedics.

Our endpoint detection and response tools detect, analyze, and address threats across email systems and endpoints. Plus, we can educate your employees on best cyber hygiene practices, such as enabling multifactor authentication, practicing caution when opening links and attachments, and regularly updating software to close security gaps.

If your organization needs help leveraging the right email security tools, schedule a consultation with Techmedics today.

‍

Talk With a Technology Advisor

Technology challenges rarely have one-size-fits-all solutions. A consultation with Techmedics can help you better understand your options and identify practical next steps for your organization. Start with a conversation about what you're trying to accomplish and where technology may be getting in the way.

Your request has been sent.
Oops! Something went wrong while submitting the form.