Gray: Neutral
We found no suspicious indicators. Confirm that the displayed sender and message context still make sense.
Email Security
We place a clear, color-coded banner above each analyzed message. Use the color and explanation together to decide whether to proceed, pause, or report the email.
At a glance
The banner explains why the message received its rating. Always read that explanation, even when the color looks familiar.
We found no suspicious indicators. Confirm that the displayed sender and message context still make sense.
The sender is outside your organization but is recognized as a trusted contact. Stay alert for unusual requests.
Something is unusual. The message may be legitimate, but verify it before clicking, opening, replying, or sharing information.
The service considers the message likely malicious. Do not interact with it; report it and follow your organization’s security policy.
Frequently Asked Questions
Select a question to see the answer.
We have an email security service that analyzes messages for phishing, spam, malware, impersonation, and other warning signs. It places a banner at the top of each analyzed email so you can quickly see the sender’s address, whether the message is internal or external, and what we found.
The banner appears in your normal email client on desktop, web, and mobile—no separate inbox is required.
A yellow banner does not automatically mean the email is malicious. It means something deserves a closer look, such as a first-time sender, an unusual request, a questionable link, or bulk marketing content.
Treat the message as dangerous. Do not click links, open attachments, reply, or follow its instructions. Use Report This Email, then delete the message unless your IT team asks you to preserve it for investigation.
Some organizations quarantine red-level messages automatically. If one reaches your inbox, the visible warning gives you a final opportunity to avoid the threat.
Caution banners identify unusual characteristics, not only confirmed attacks. A legitimate first-time sender, newsletter, external service, or message with an unexpected request may receive a yellow banner. If you know the message is safe, report it as safe so the classification can improve.
The link in the banner opens a reporting page where you can classify the message as safe, spam, or phishing and add context. Reports help your IT team review questionable messages and help us improve future classifications.
If your organization enables personal lists, reporting may also let you allow or block that sender for your own mailbox.
The service can check a link at the moment you click it. Phish Fence may remind you that the source message was suspicious, or it may block a destination that became known as dangerous after the email arrived. Do not bypass a warning unless you have independently verified the site and your IT team’s policy permits it.
No. We remove the banner when you reply to or forward a message. This keeps your organization’s internal security guidance private and lets forwarded mail be analyzed again when appropriate.
Individual users cannot manually remove banners from received messages. Depending on your organization’s settings, the reporting page may let you add a sender to a personal allow or block list. Personal choices affect only your mailbox; organization-wide changes are managed by your administrator.
Still unsure?