1. Malicious character encodings that can crash email clients such as Apple Mail.
2. Malicious RFC 2231 continuation indices designed to cause overallocation.
3. Base64 data containing illegal characters such as null bytes.
4. Unterminated comments and quoted-strings.
5. Missing multipart parts (e.g. no terminating boundary delimiter).
6. Malicious data designed to cause CPU-intensive decoding or stack overflows (aka MIME bombs, the email equivalent of zip bombs).
7. Malicious multiple occurrences of crucial headers and parameters, which could cause clients to render an email differently from that scanned by antivirus software.
8. Encoded words containing malicious control characters (cf. Mailsploit).
While it won't prevent this exact attack because it seems to be purely size-based, @ronomon/mime was able to detect attacks such as Tim Cotten's "Ghost Emails" Gmail hack [1] as well as recent CVEs reported against ClamAV [2] and SpamAssassin [3], which are variants of a MIME multipart attack I disclosed through Snyk, "How to crash an email server with a single email" [4].
[1] https://blog.cotten.io/ghost-emails-hacking-gmails-ux-to-hid...
[2] https://blog.clamav.net/2019/11/clamav-01021-and-01015-patch...
[3] http://mail-archives.apache.org/mod_mbox/spamassassin-announ...
[4] https://snyk.io/blog/how-to-crash-an-email-server-with-a-sin...