The engine uses a boundary-enforcing regex pattern to detect prohibited domain names anywhere in the draft text without triggering false positives on partial substring overlaps.