What the banners mean
Every message you open gets one line. There are deliberately few, and each says exactly what was established and nothing more.
The single most important thing on this page: a warning you see every day is a warning you
stop reading. These banners are quiet on purpose. When one turns red, it is because something
was actually established â not because something was merely unusual.
The good ones
đĄī¸ Verified sender
What it establishes. The person who sent this proved, at some point in
the last six months, that they can read that mailbox. The subject and the text in front of
you are exactly what they signed.
What it does not establish. Who they are in the world. "Verified" means
mailbox control, not identity. It also cannot tell you whether the mailbox changed hands
after the proof was made â if someone took the account over, they can send verified mail from
it. The new key warning below is what catches that.
What to do. Treat it as you would a letter you watched someone sign. For
a first-time payment instruction, still confirm by phone â see the note at the bottom.
âšī¸ Signed, but the address is unconfirmed
What it establishes. The message is cryptographically signed and has not
been altered. Somebody with a specific key wrote it and nobody changed it since.
What it does not establish. That the key belongs to that address. Nobody
has confirmed the link, so the identity is a claim, not a fact.
What to do. Read it as ordinary mail from an unknown person. If you
expect this sender to be verified and they are not, ask them to confirm their mailbox â it
takes them two minutes.
âšī¸ Not protected
What it establishes. Nothing. This is ordinary e-mail.
Why this is not a warning. Most mail is ordinary mail. Marking all of it
as suspicious would train you to ignore the banner, and then it is not there on the day it
matters.
The ones that ask you to pause
â ī¸ This sender is using a new key
What it establishes. The message is signed and intact, but this person
previously wrote with a different key.
Why it matters. That is what a new laptop looks like. It is also exactly
what a hijacked account looks like. There is no way to tell the two apart from the message.
What to do. Before anything sensitive, check through another channel â
phone, in person, a chat app. This warning shows for thirty days after a key change.
The ones that mean stop
â This message was altered after it was sent
The sender signed different text than the one you are reading. Something changed in
transit. Do not act on it, and tell the sender through another channel â if their account is
compromised, your reply goes to the attacker.
â The subject line was changed after it was sent
The body may be genuine while the subject is not. This is the exact shape of payment
fraud: a real paragraph the sender wrote, under a heading like "URGENT: change of bank
details" that they never wrote. Do not act on it.
â Signed with the wrong key
The message carries a valid signature â but not from the key that address published.
Someone holding their own key is writing in somebody else's name. This is impersonation, not
an error.
â This message carries someone else's signature
The proof attached to this message was made for a message from a different sender.
Treat it as forged.
â This message carries a signature dated in the future
The attached proof claims to have been made later than now. A clock can run fast by a few
hours; this is beyond that. Treat it as forged.
â This address imitates one you know
The domain is a near-miss of one you correspond with â rnicrosoft.com for
microsoft.com, or an extra hyphen. This is the commonest shape of a phishing attempt
and it works because the eye reads words, not letters.
A summary you can keep
| Banner | Means | Do |
| đĄī¸ Verified sender | Proved mailbox control; text and subject intact | Proceed normally |
| âšī¸ Signed, unconfirmed | Intact, but the identity is unproven | Treat as an unknown sender |
| âšī¸ Not protected | Ordinary mail | Nothing special |
| â ī¸ New key | New laptop â or a hijacked account | Confirm another way |
| â Altered / subject changed | Changed after it was sent | Do not act on it |
| â Wrong key / someone else's signature | Impersonation | Do not act on it |
| â Imitating a known address | Look-alike domain | Do not act on it |
One thing a green badge does not replace. A verified message proves it
came from that mailbox, unaltered. It does not prove the request in it is sensible. If a
message asks you to change payment details, confirm by phone on a number you already had â
never one from the message. That advice is unchanged by any technology.
â All documentation