Summary
- RFC 5173 defines three different views of an email body: undecoded wire-oriented material, selected MIME parts and best-effort extracted text. A match identifies the view and comparator that succeeded, not a single semantic body.
- Consequential filtering must retain the message hash, engine and extractor version, transform, selector, conversion failures and action. A true hit is not proof of sender intent or malware; a miss is not proof that the content was absent or safe.
The word “body” sounds like a stable object. MIME makes it a tree. Transfer encodings turn visible text into another octet sequence. A nested message adds another header and another body. HTML, a proprietary document and an image may or may not become searchable text depending on the implementation. RFC 5173 did not hide those differences. It made the transform part of the rule.
Before matching, the extension builds a set of strings. A header-only message without the empty separator produces no strings, so even a body test for an empty key is false. Otherwise the comparator and match type operate on strings produced by :raw, :content or the default :text. The result is therefore a receipt for a pipeline, not a statement about all meaning in the message.
Raw preserves representation, including its accidents
:raw treats the entire undecoded body as one item. It does not remove transfer encoding or interpret MIME structure. Boundary markers and the MIME headers of enclosed parts remain matchable content. Unless the surrounding environment rejects a malformed message outright, syntax errors do not exempt it from the raw test.
That surface is useful when an operator deliberately wants representation evidence. It is also easy to overread. A key can match a boundary token, a base64 sequence, an enclosed Content-Type header or a prologue the recipient never sees. The hit says those octets were present on the raw surface. It does not say a human read the word or that the sender intended its apparent meaning.
Raw also changes the scope of continuity. Because the body is one item, a wildcard can traverse material that another transform splits by MIME part. A rule migrated from raw to a part-aware transform can stop matching without any change to the message bytes.
Content selects a tree, then forbids cross-part stories
:content treats MIME as structure. A full type/subtype selects that exact type, a bare type selects its subtypes, and an empty selector chooses all types. Malformed selectors with misplaced or repeated slashes select nothing. Traversal descends recursively through multipart and message/rfc822 parts.
Each selected part is matched independently. A search expression must not cross a MIME boundary. Two fragments that appear consecutively in a mail reader but live in separate parts cannot satisfy one continuous pattern. Selecting a multipart container searches its prologue and epilogue; its children are searched only when their own types qualify. Selecting a nested message can expose its header while its inner bodies remain subject to separate type selection.
The engine decodes common transfer encodings and converts supported character sets to UTF-8. Yet the RFC explicitly permits an undecodable or unconvertible part to be treated as US-ASCII, omitted or handled by local convention. A miss may therefore mean “the selected part did not yield this key,” not “the message contained no such information.”
Text is an implementation policy disguised as a default
:text is best-effort UTF-8 extraction, and it is the default when a script names no transform. A simple implementation may equate it with :content "text". A more ambitious engine may strip markup, convert proprietary documents or apply OCR to images. The RFC does not require those engines to return the same number of strings.
This flexibility is operationally sensible and evidentially expensive. Updating a renderer, charset library, document converter or OCR plugin can change which words a rule sees. Moving the same Sieve source to another provider can do the same. The script remains constant while the effective policy changes underneath it.
A security team that records only “body rule matched” cannot later reproduce the observation. It needs the preserved message, transform, selector, comparator, match type, extraction engine, enabled conversion capabilities, failures and skipped parts. Without them, the event is a verdict without its measurement surface.
A string test is not a security classifier
RFC 5173 says this plainly: raw-body matches may be broader than intended, and text matching does not replace spam, virus or other security filtering. Recursive parsing, decoding, conversion and optional OCR also create a resource surface; implementations must be sized and restricted so malicious use cannot deny service to other users.
The control question is therefore two-sided. A false action can quarantine or discard legitimate mail because a token appeared in representation metadata. A false reassurance can deliver dangerous mail because an attachment type was not selected, conversion failed or the extractor had no capability for that media. Neither outcome is explained by the Boolean alone.
The adjacent RFC 5229 boundary remains separate. Body wildcards do not populate match variables as a side effect. That rule prevents a body hit from silently becoming captured script state; it does not make the extracted body complete or stable.
Sources
- https://www.rfc-editor.org/rfc/rfc5173.html
- https://www.rfc-editor.org/rfc/rfc5173.txt
- https://www.rfc-editor.org/info/rfc5173
- https://datatracker.ietf.org/doc/rfc5173/
- https://datatracker.ietf.org/doc/rfc5173/history/
- https://datatracker.ietf.org/doc/rfc5173/references/
- https://www.rfc-editor.org/errata/rfc5173
- https://www.iana.org/assignments/sieve-extensions/sieve-extensions.xhtml
- https://www.rfc-editor.org/rfc/rfc5228.html
- https://www.rfc-editor.org/rfc/rfc5229.html
- https://www.rfc-editor.org/rfc/rfc5703.html
- https://www.rfc-editor.org/rfc/rfc2045.html
- https://www.rfc-editor.org/rfc/rfc2046.html
- https://www.rfc-editor.org/rfc/rfc3629.html
- https://heng.lu/on-reality-layers-symbolic-power-and-why-clarity-feels-so-hostile/
- https://heng.lu/minimum-initial-specification-localized-future-decision-voluntary-adoption-internet-coordination-system/
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
