What the banners mean

Every message you open gets one line. There are deliberately few, and each says exactly what was established and nothing more.

The single most important thing on this page: a warning you see every day is a warning you stop reading. These banners are quiet on purpose. When one turns red, it is because something was actually established — not because something was merely unusual.

The good ones

đŸ›Ąī¸ Verified sender

What it establishes. The person who sent this proved, at some point in the last six months, that they can read that mailbox. The subject and the text in front of you are exactly what they signed.

What it does not establish. Who they are in the world. "Verified" means mailbox control, not identity. It also cannot tell you whether the mailbox changed hands after the proof was made — if someone took the account over, they can send verified mail from it. The new key warning below is what catches that.

What to do. Treat it as you would a letter you watched someone sign. For a first-time payment instruction, still confirm by phone — see the note at the bottom.

â„šī¸ Signed, but the address is unconfirmed

What it establishes. The message is cryptographically signed and has not been altered. Somebody with a specific key wrote it and nobody changed it since.

What it does not establish. That the key belongs to that address. Nobody has confirmed the link, so the identity is a claim, not a fact.

What to do. Read it as ordinary mail from an unknown person. If you expect this sender to be verified and they are not, ask them to confirm their mailbox — it takes them two minutes.

â„šī¸ Not protected

What it establishes. Nothing. This is ordinary e-mail.

Why this is not a warning. Most mail is ordinary mail. Marking all of it as suspicious would train you to ignore the banner, and then it is not there on the day it matters.

The ones that ask you to pause

âš ī¸ This sender is using a new key

What it establishes. The message is signed and intact, but this person previously wrote with a different key.

Why it matters. That is what a new laptop looks like. It is also exactly what a hijacked account looks like. There is no way to tell the two apart from the message.

What to do. Before anything sensitive, check through another channel — phone, in person, a chat app. This warning shows for thirty days after a key change.

The ones that mean stop

⛔ This message was altered after it was sent

The sender signed different text than the one you are reading. Something changed in transit. Do not act on it, and tell the sender through another channel — if their account is compromised, your reply goes to the attacker.

⛔ The subject line was changed after it was sent

The body may be genuine while the subject is not. This is the exact shape of payment fraud: a real paragraph the sender wrote, under a heading like "URGENT: change of bank details" that they never wrote. Do not act on it.

⛔ Signed with the wrong key

The message carries a valid signature — but not from the key that address published. Someone holding their own key is writing in somebody else's name. This is impersonation, not an error.

⛔ This message carries someone else's signature

The proof attached to this message was made for a message from a different sender. Treat it as forged.

⛔ This message carries a signature dated in the future

The attached proof claims to have been made later than now. A clock can run fast by a few hours; this is beyond that. Treat it as forged.

⛔ This address imitates one you know

The domain is a near-miss of one you correspond with — rnicrosoft.com for microsoft.com, or an extra hyphen. This is the commonest shape of a phishing attempt and it works because the eye reads words, not letters.

A summary you can keep

BannerMeansDo
đŸ›Ąī¸ Verified senderProved mailbox control; text and subject intactProceed normally
â„šī¸ Signed, unconfirmedIntact, but the identity is unprovenTreat as an unknown sender
â„šī¸ Not protectedOrdinary mailNothing special
âš ī¸ New keyNew laptop — or a hijacked accountConfirm another way
⛔ Altered / subject changedChanged after it was sentDo not act on it
⛔ Wrong key / someone else's signatureImpersonationDo not act on it
⛔ Imitating a known addressLook-alike domainDo not act on it

One thing a green badge does not replace. A verified message proves it came from that mailbox, unaltered. It does not prove the request in it is sensible. If a message asks you to change payment details, confirm by phone on a number you already had — never one from the message. That advice is unchanged by any technology.

← All documentation