DOC.04.1 / INKY FAQ EMAIL PROTECTION / SUPPORT NO SIGN-IN NEEDED

Why is there a banner on my email?

Short answer: your organization uses INKY, and it checks every message before it reaches you. The colored strip at the top tells you what it found. Gray means nothing odd, yellow means look twice, red means do not touch it. The rest of this page is the longer answer.

The three colors / what each one is telling you

Gray, yellow, red.

Each example below is what the strip looks like sitting at the top of your message. Find the one that matches what you are looking at.

Nothing unusual found in this message.

invoices@supplier.example.com External sender

Gray — nothing unusual

Nothing suspicious was found. It is still worth a glance at the sender address and the source type shown in the banner — an external webmail address on a message claiming to be from a colleague is exactly the sort of thing worth noticing.

What to doCarry on as normal. Just check the address matches who you think it is from.

Caution — something about this message is unusual.

hr-payroll@example-benefits.com External sender

Yellow — something is unusual

Not necessarily dangerous, but worth a second look. A request for sensitive personal information, or mail that is simply out of the ordinary, will earn a yellow banner.

What to doCheck who it is really from before you click a link or open an attachment. If it feels off, ask us — that is never a waste of our time.

Danger — this message looks like phishing.

it-support@rnicrosoft-alerts.example External sender

Red — likely phishing

A brand impersonation such as a fake account alert from your IT department, a known phishing link, or mail spoofed to look like it came from someone you trust. Look closely at the address in the example — an rn standing in for an m is a real and common trick.

What to doDo not click anything. In most cases, delete it and move on. If you already clicked, tell us straight away.

The banner also shows the real sender address, and whether the message came from inside or outside your organization.

Common questions / in plain English

The questions we actually get asked.

An email protection product. It uses machine learning to analyze incoming messages for phishing, spam, and other email-based threats, then adds the banner you are seeing to tell you what it concluded.

Because your IT staff deployed INKY and included you in the protected group. The banners flag possible threats, show the sender's real address, and mark whether a message is internal (from someone in your organization) or external. Seeing them means the protection is working, not that something is wrong.

Look carefully at who the mail is from and whether it is someone you actually trust. Be especially careful about clicking links in the body or opening attachments. If anything feels off, it is always fine to ask us first.

In most cases you can simply delete the message and move on. Many deployments quarantine or delete red-flagged mail before it ever arrives; in others it is still delivered but clearly marked, so you can see what was caught and why. Either way, the banner has done its job.

It is how you tell INKY it got something wrong — or right. The link sits in the bottom right corner of every banner and opens a short form where you mark the message as Safe, Spam, or Phishing. That feedback tunes future analysis, so it is worth using.

That is Phish Fence. INKY can check links at the moment you click them, not just when the mail arrived. Clicking a link in a yellow or red message takes you to a page repeating that the message looked unusual or suspicious — and sometimes a message that looked fine on arrival turns out to point somewhere that has since gone bad.

Yes. Policies and settings are adjustable, and a legitimate sender that keeps getting flagged is a fixable problem. Tell us which sender and we will tune it — that is part of running the service, not an extra.

Ask us. If you are an ACG client, contact us the way you normally would and we will look at the actual message. If a suspicious email has already been clicked or replied to, tell us straight away — that is a time-sensitive one and there is no scolding involved.

If you already clicked / do this now

Clicked something you should not have?

It happens to careful people. Speed matters far more than embarrassment, so tell us immediately rather than waiting to see what happens.

If you entered a password on a page you reached from an email, change that password now and tell us which account it was. If you approved a multi-factor prompt you did not expect, say so — that is the detail that turns a near miss into a real problem if it goes unmentioned. If you opened an attachment and something looked wrong, leave the machine on and call us.

TELL US
Immediately, not tomorrow
CHANGE IT
Any password you typed
NO BLAME
These are built to fool people

Not a client yet / email security for your team

Want banners like these?

If you landed here from someone else's email and liked what you saw, this is part of how we handle security for the businesses we look after.