VBSpam Q3 2026 found that leading gateways still caught phishing at near perfect rates—NoSpamProxy reportedly reached 99.990% phishing detection—but attackers increasingly defer the harmful step to browser based redir... The practical lesson is not to discard email filtering: it is to pair it with click time URL ana...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Virus Bulletin’s Q3 2026 VBSpam comparative test reveal about phishing campaigns bypassing conventional email security by using aut. Article summary: Virus Bulletin’s Q3 2026 test found that phishing is increasingly designed to look harmless at the email gateway: attackers used authenticated or plausible sending infrastructure, attachment-free HTML, browser-side gatin. Topic tags: general, general web, academic, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, chart
Phishing emails no longer need a malicious attachment or an obviously suspicious sender to be dangerous. Virus Bulletin’s Q3 2026 VBSpam comparative test highlighted campaigns that used plausible delivery infrastructure and benign-looking HTML messages, then moved the decisive fraud step into redirect chains and browser-side code. The leading enterprise products performed strongly, but the test illustrates why an email gateway cannot be the only phishing control. 20
21
The public Q3 test ran for 16 days and evaluated 11 publicly tested email-security products against 103,969 messages, including 103,380 spam messages. Reports on the test said leading enterprise gateways achieved phishing detection rates close to 100%. Net at Work NoSpamProxy was reported as the top scorer, with a 99.995 final score, 100% malware detection, 99.990% phishing detection and no false positives. 20
21
That result matters because it is not evidence that enterprise filtering has stopped working. It is evidence that attackers are adapting their delivery methods. Instead of putting the most clearly malicious content directly in an email, they can use an attachment-free message, a legitimate-looking sending path and a URL that changes behavior only after a recipient clicks.
VBSpam is a business-focused comparative program that measures protection against spam, phishing and malware while also accounting for false positives. Its testing is designed to evaluate live, current email threats rather than a static archive of old samples. 6
12
13
One German-language “Mahnschreiben,” or overdue-payment, campaign reportedly used Amazon SES and a DKIM-aligned moolaah[.]com domain. The message had no attachment. Its link led first to a page built to look less suspicious to automated inspection, with decoy markup, hidden text, a zero-size iframe and obfuscated JavaScript.
The page reportedly collected browser and time-zone signals before using a hidden POST request to redirect the visitor to opensea[.]io. The reported assessment was a cloaked cryptocurrency or NFT-fraud route—not confirmed malware delivery. The distinction is important: the fraud logic may be intentionally withheld unless the visitor appears to be a real, appropriately profiled target. 20
A Dutch-language email impersonating McAfee and TotalAV used an HTML-only renewal pitch: it claimed the recipient had “631 dangerous viruses,” threatened account closure and offered a 90% discount.
Rather than relying on one fixed phishing page, the campaign used separate tracking, unsubscribe and call-to-action paths through redirect infrastructure. Such paths can change destination, expire or serve different content by time or location. That makes a one-time gateway URL check less reliable than analysis performed when the user actually clicks. The assessed goal was renewal or affiliate fraud and possible payment-data theft, rather than a confirmed malware download. 20
Another campaign impersonated BCR S.A. and used a PSD2-consent theme to create urgency. It reportedly encoded its destination with an IPv6-mapped address representation, an obfuscation technique that can defeat simplistic URL parsing or reputation checks. The campaign was assessed as likely credential theft, though the supplied reporting does not establish a confirmed final landing page or a more specific attribution. 20
The Q3 reporting suggests a meaningful gap between the best enterprise gateways and the publicly tested open-source Rspamd deployment. One report put Rspamd’s phishing catch rate at 62.550%, well below the leading enterprise results. 21
That figure should not be generalized to every Rspamd installation or to open-source tooling as a category: configuration, threat feeds, tuning and surrounding controls affect real-world performance. It does, however, reinforce a practical point: rapidly changing redirect infrastructure and browser-aware phishing flows can be difficult for a default or narrowly configured email layer to classify.
For context, Virus Bulletin’s separate Q2 2026 review reported a 54.810% phishing catch rate for Rspamd in that test, again describing phishing detection as behind the leading products. These are different test periods, so the percentages should not be treated as a single, interchangeable benchmark. 5
The test’s most useful operational lesson is to extend analysis from delivery time to click time.
Users remain an important final control. Payment demands, banking-consent requests and subscription-renewal warnings should be verified through the organization’s known website, app or support channel—not through the link in the message.
VBSpam Q3 2026 did not show that conventional email security has broadly failed. Top enterprise products continued to post exceptionally strong test results. 20
21 It showed something more specific: phishing operators are moving their most deceptive behavior into personalized, browser-mediated stages that a conventional gateway may not fully observe at delivery time.
The durable response is layered defense—strong email filtering combined with redirect analysis, browser-aware inspection and account protections that make a stolen password less useful.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
VBSpam Q3 2026 found that leading gateways still caught phishing at near perfect rates—NoSpamProxy reportedly reached 99.990% phishing detection—but attackers increasingly defer the harmful step to browser based redir...
VBSpam Q3 2026 found that leading gateways still caught phishing at near perfect rates—NoSpamProxy reportedly reached 99.990% phishing detection—but attackers increasingly defer the harmful step to browser based redir... The practical lesson is not to discard email filtering: it is to pair it with click time URL analysis, browser capable sandboxing, URL normalization and phishing resistant account protections.