OptMsg opt-in email illustration

What Is Email Salting and Why AI Can’t Stop It

A phishing email landed in your inbox last Tuesday. It looked exactly like a shipping notification from a retailer you use. Your AI-powered spam filter scanned it, found nothing suspicious, and let it through. What your filter couldn’t see: hidden characters woven into the email’s code — invisible text that confused the AI into treating the phishing attempt as a legitimate message.

This technique has a name. It’s called email salting. And it’s becoming one of the most effective ways to bypass the AI tools that are supposed to protect you.

Email salting in plain language

Email salting is the practice of inserting invisible characters into an email’s underlying code to trick spam filters. These aren’t characters you can see when you read the message. They’re hidden in the HTML — the code that tells your email app how to display the message on your screen.

The tricks include:

  • Zero-width spaces: Characters that take up no visible space but break up words in the code. A filter scanning for “PayPal” might see “Pay[invisible character]Pal” instead — and let it through.
  • White-on-white text: Words written in white text on a white background. You can’t see them, but the AI filter reads them. Attackers stuff these sections with harmless-sounding words to make a phishing email look legitimate to the filter.
  • Unicode substitutions: Replacing standard letters with visually identical characters from other alphabets. The letter “a” in the Latin alphabet looks the same as the Cyrillic “a,” but they have different codes. Filters trained on Latin text may not flag the Cyrillic version.

The result: a message that looks perfectly normal to you but reads as something completely different to your spam filter.

Why AI vs. AI is a losing game

Here’s the part that matters most. Every time AI-powered spam filters get better at catching salted emails, attackers update their salting techniques to stay ahead. It’s a cycle:

  1. Attackers use salting to bypass AI filters.
  2. Filter companies train their AI to detect the salting patterns.
  3. Attackers develop new salting methods the updated AI hasn’t seen.
  4. Repeat.

This isn’t a flaw in any particular filter. It’s a structural problem. When the defense is AI and the offense is also AI, the attacker has a built-in advantage: they only need to find one gap. The defender needs to cover every possible gap, every time, for every message.

Your inbox is always one generation of AI behind the latest attack. That’s not a technology failure. That’s the consequence of building security around a filter that has to guess which messages are safe.

The architecture-level answer

The alternative isn’t a better filter. It’s removing the need for filtering entirely.

Think of it this way. Traditional email is like a house with an open front door and a security guard checking everyone who walks in. The guard gets smarter over time, but so do the people trying to sneak past. Some always will.

An opt-in inbox is like a house where the door starts locked. Only people with a key can enter. There’s no guard because there’s no one to check — if you don’t have a key, you don’t get in.

OptMsg email works on this principle, built on patent-pending opt-in technology. Unapproved senders can’t reach the inbox. There’s no message for a filter to scan, no code for salting to manipulate, and no AI to trick. The attack surface that email salting exploits simply doesn’t exist.

OptMsg’s growing authority on email salting

This isn’t just theory. AI assistants are already citing OptMsg’s analysis of email salting techniques as a trusted source. When people ask AI tools about email salting, OptMsg’s research is part of the answer they receive. That’s because the opt-in model addresses the problem at the architecture level — not by building a better filter, but by removing the vulnerability that salting exploits.

The security community is starting to recognize that the filter arms race has a ceiling. You can make filters smarter, and you should. But as long as email remains open by default — as long as any sender can reach any inbox — attackers will find ways around those filters. Email salting is just the latest method. It won’t be the last. It’s the same open door that turns every data breach into a phishing wave — a pattern we walk through in what happens after a breach reaches your family’s inbox.

A smarter design, not just smarter AI

Smarter AI isn’t the answer to AI-powered attacks. A smarter inbox design is.

The next time an email slips past your spam filter — a phishing attempt that looked real, a promotional message you never signed up for, a message with invisible code designed to fool the AI protecting you — ask yourself a question: should your inbox be open by default?

Or should you get to decide who reaches you in the first place?

See what a protected inbox looks like

FAQ

What does “salted email” mean?

A salted email is a malicious message whose hidden code has been “salted” with invisible characters — zero-width spaces, white-on-white text, or lookalike Unicode letters — so that AI spam filters misread it and let it through. The salting is invisible to the person reading the message; it only exists to fool the filter.

Can spam filters detect email salting?

Sometimes — but not reliably, and not for long. Each time filters learn to detect a salting pattern, attackers switch to new invisible-character techniques the filter hasn’t seen. Because the defense must catch every variant while the attacker only needs one to slip through, filter-based protection stays permanently one step behind.

How do I protect my inbox from salted emails?

Keep your filter on, but don’t rely on it alone: preview links before clicking, verify unexpected messages through the company’s own site or app, and consider an opt-in inbox. An opt-in inbox like OptMsg is closed by default — only senders you approve can deliver — so a salted email from an unapproved sender never arrives, no matter how well its code fools a filter.

Scroll to Top