When Gini scans your emails, it assigns a risk level to help you understand how safe each message is. Here's what each level means.
The Risk Levels
Safe (Green)
What it means: This email appears to be legitimate.
What Gini found:
- Sender address matches the organization they claim to be
- Links go to expected, trusted websites
- No suspicious language or urgent demands
- Content matches normal email patterns
What to do: Open and interact with the email normally.
Caution (Yellow)
What it means: Some elements raised minor concerns, but the email might be okay.
What Gini found:
- Sender is from a less common domain
- Contains links that couldn't be fully verified
- Some unusual elements, but nothing clearly malicious
- Could be legitimate or could be suspicious
What to do:
- Read carefully before clicking any links
- Verify the sender if you're unsure
- When in doubt, go directly to the website instead of clicking links
Warning (Orange)
What it means: Multiple red flags detected. This email is probably risky.
What Gini found:
- Sender address doesn't match who they claim to be
- Contains suspicious links
- Uses urgent or threatening language
- Asks for personal information
What to do:
- Don't click any links
- Don't download attachments
- If it claims to be from a company you use, contact them directly through their official website
Dangerous (Red)
What it means: Strong indicators of a phishing scam. Do not interact.
What Gini found:
- Known scam patterns detected
- Fake sender pretending to be a trusted organization
- Links lead to known malicious sites
- Clear attempt to steal information
What to do:
- Do not click anything in the email
- Do not reply
- Delete the email
- Consider reporting it as spam/phishing
What Creates Risk
Suspicious Sender Addresses
Legitimate: support@amazon.com Suspicious: support@amaz0n-alerts.com
Scammers create addresses that look similar to real companies.
Dangerous Links
Gini checks where links actually go. A link might say:
"Click here to log into your bank"
But actually lead to:
scammer-site.com/fake-bank-login
Urgent Language
Phishing emails often create panic:
- "Your account will be closed in 24 hours!"
- "Unauthorized access detected!"
- "Act immediately or lose access!"
Real companies rarely demand urgent action via email.
Requests for Sensitive Information
Legitimate companies never ask for these via email:
- Passwords
- Social Security numbers
- Complete credit card numbers
- Bank account details
When Risk Scores Are Wrong
No system is perfect. Occasionally:
False Positives: A legitimate email might be flagged as risky
- This can happen with new senders or unusual email formats
- If you trust the sender, you can mark it as safe
Missed Threats: A dangerous email might appear safe
- New scam techniques may not be detected immediately
- Always use caution with unexpected requests, even in "safe" emails
Best Practices
Regardless of risk level:
- Be skeptical of unexpected emails - Especially about money or accounts
- Verify independently - Go to websites directly rather than clicking links
- Check the sender carefully - Look for misspellings in email addresses
- When in doubt, don't click - You can always contact the company directly
Questions?
For more details, see:
- What Gini Looks for in Phishing Emails
- How to Review Flagged Emails
- How Email Protection Works