Phishing Redirect Chain from Webmail to Spoofed Login Page

Detects HTTP redirect chains originating from common webmail providers to URLs containing suspicious login-related keywords or obfuscated brand look-alike domains, which is indicative of credential harvesting or phishing activity.