The research for this post is now public. See this post for details. A less drastic safeguard is to ensure HTML is disabled in the email client, although the researchers have warned that future ...