Worked examples
Six situations that actually happen. What you would see, what it means, and what to do.
Rules are hard to remember; stories are not. Each of these is a real shape of fraud or a
real everyday case. Two of them are ones where this software does not save you, and
those are the most useful ones on the page.
1. The changed bank account
You have worked with a supplier for years. An invoice arrives that looks exactly like all
the others — same layout, same signature, same tone — except the account number is different.
A note says they have switched banks.
What you see: ⛔ This message was altered after it was sent, if
the attacker intercepted and edited a genuine message. Or ℹ️ Signed, but the address is
unconfirmed, if they sent it themselves from a mailbox they control.
Why: the fingerprint of the text no longer matches what your supplier
signed, or the message is not from the key your supplier published.
What to do: do not pay. Phone the supplier on the number you already had —
never one from the message.
2. The near-miss domain
A message from accounts@your-suppIier.com. That is a capital I where an l should
be. On a screen, at speed, it is invisible.
What you see: ⛔ This address imitates one you know.
Why: the plugin has learned which domains you actually correspond with —
from your own mail, on your own machine — and this one is a near-miss of one of them. It only
warns after it has seen the real domain several times, so a first phishing mail cannot teach
it the wrong lesson.
What to do: nothing. Delete it. If it claims to be a supplier you use,
tell them: their name is being used.
3. The colleague with a new laptop
A colleague writes and you get a warning that they are using a new key.
What you see: ⚠️ This sender is using a new key, for thirty days.
Why: they set up ProtectMyMail on a new machine, or restored from their
recovery phrase, or someone took over their account. From the outside these are identical,
and pretending otherwise would be a lie.
What to do: if the message is routine, carry on. If it asks for money,
credentials or a change to anything, confirm through another channel first. That is the whole
purpose of the warning.
4. The urgent request from the director
"I am in a meeting, I need you to arrange a payment, do not discuss it with anyone." From
the director's real address.
What you see: possibly 🛡️ Verified sender. If their account was
genuinely taken over, the message really is from their mailbox and really is unaltered.
Why this matters: a green badge proves the message came from that mailbox
and was not changed. It does not prove the request is sensible, and it cannot know who is
sitting at the keyboard.
What to do: the badge changes nothing here. Urgency plus secrecy plus
money is the pattern, whatever the banner says. Phone them.
Worth stating plainly. This tool answers "is this really from that
mailbox, unaltered". It does not answer "should I do what it says". Nothing can.
5. Sending something confidential
You need to send a contract to a client and you would rather your mail provider — and
theirs — could not read it.
What happens: if your client also uses ProtectMyMail, the body is sealed
automatically. They open it normally; nobody in between can read it.
What to watch: the subject line is not sealed, and the fact that
you wrote to them at that moment is not hidden. Put the confidential part in the body, and
keep the subject bland.
6. A message from someone new
A first message from a company you have never dealt with.
What you see: ℹ️ Not protected, almost certainly — most of the
world does not use this yet.
Why that is not a warning: ordinary mail is ordinary. If every unprotected
message were flagged, you would stop reading the flags within a week, and then they are not
there on the day one turns red.
What to do: treat it exactly as you would have before installing anything.
This tool adds certainty where it can; it does not pretend to have it everywhere.
← All documentation