Understanding Email Risk Scores

When Gini scans your emails, it assigns a risk level to help you understand how safe each message is. Here's what each level means.

The Risk Levels

Safe (Green)

What it means: This email appears to be legitimate.

What Gini found:

  • Sender address matches the organization they claim to be
  • Links go to expected, trusted websites
  • No suspicious language or urgent demands
  • Content matches normal email patterns

What to do: Open and interact with the email normally.

Caution (Yellow)

What it means: Some elements raised minor concerns, but the email might be okay.

What Gini found:

  • Sender is from a less common domain
  • Contains links that couldn't be fully verified
  • Some unusual elements, but nothing clearly malicious
  • Could be legitimate or could be suspicious

What to do:

  • Read carefully before clicking any links
  • Verify the sender if you're unsure
  • When in doubt, go directly to the website instead of clicking links

Warning (Orange)

What it means: Multiple red flags detected. This email is probably risky.

What Gini found:

  • Sender address doesn't match who they claim to be
  • Contains suspicious links
  • Uses urgent or threatening language
  • Asks for personal information

What to do:

  • Don't click any links
  • Don't download attachments
  • If it claims to be from a company you use, contact them directly through their official website

Dangerous (Red)

What it means: Strong indicators of a phishing scam. Do not interact.

What Gini found:

  • Known scam patterns detected
  • Fake sender pretending to be a trusted organization
  • Links lead to known malicious sites
  • Clear attempt to steal information

What to do:

  • Do not click anything in the email
  • Do not reply
  • Delete the email
  • Consider reporting it as spam/phishing

What Creates Risk

Suspicious Sender Addresses

Legitimate: support@amazon.com Suspicious: support@amaz0n-alerts.com

Scammers create addresses that look similar to real companies.

Dangerous Links

Gini checks where links actually go. A link might say:

"Click here to log into your bank"

But actually lead to:

scammer-site.com/fake-bank-login

Urgent Language

Phishing emails often create panic:

  • "Your account will be closed in 24 hours!"
  • "Unauthorized access detected!"
  • "Act immediately or lose access!"

Real companies rarely demand urgent action via email.

Requests for Sensitive Information

Legitimate companies never ask for these via email:

  • Passwords
  • Social Security numbers
  • Complete credit card numbers
  • Bank account details

When Risk Scores Are Wrong

No system is perfect. Occasionally:

False Positives: A legitimate email might be flagged as risky

  • This can happen with new senders or unusual email formats
  • If you trust the sender, you can mark it as safe

Missed Threats: A dangerous email might appear safe

  • New scam techniques may not be detected immediately
  • Always use caution with unexpected requests, even in "safe" emails

Best Practices

Regardless of risk level:

  1. Be skeptical of unexpected emails - Especially about money or accounts
  2. Verify independently - Go to websites directly rather than clicking links
  3. Check the sender carefully - Look for misspellings in email addresses
  4. When in doubt, don't click - You can always contact the company directly

Questions?

For more details, see:

  • What Gini Looks for in Phishing Emails
  • How to Review Flagged Emails
  • How Email Protection Works