Reading the verdicts
What each banner means — and, more usefully, what it does not mean.
Every message you open gets one line. They are deliberately few, and each one says exactly what
was established and nothing more.
The banners
- 🛡️ Verified sender
This really is that person: they proved they control that mailbox, and the
message reached you exactly as they wrote it.
- ℹ️ Signed, but the address is unconfirmed
Cryptographically signed and unaltered — but nobody has confirmed the key
belongs to that address. Anyone can claim any address. Treat the identity as unproven.
- ⚠️ This sender is using a new key
Signed and intact, but they previously wrote with a different key. That is
what a new laptop looks like — and also what a hijacked account looks like. Check another
way before anything sensitive.
- ⛔ This message was altered after it was sent
The sender signed different text than you are reading. Do not act on it.
- ⛔ Signed with the wrong key
Validly signed, but not by the key that address published. Someone may be
writing in their name.
- ⛔ This address imitates one you know
The domain is a near-miss of one you correspond with — the commonest shape of
a phishing attempt.
- ℹ️ Not protected
Ordinary mail. Nothing is wrong with it, and nothing about the sender is
proven either.
Why “not protected” is not a warning
Most mail is ordinary mail. Marking all of it as suspicious would train you to ignore the banner,
and then it is not there on the day it matters. It only speaks up when something is actually
established, or actually wrong.
Look-alike warnings need no setup
The plugin learns which domains you correspond with, from your own mail. A domain only counts
after several messages — otherwise the first message from an impostor would teach it the wrong
thing. A sender that was flagged as dangerous is never learned from. The list stays on your
computer, and you can see and correct it in the settings.
← All guides