Help the elimination of over stimulation of banners:
Organizations receive many recurring emails from vendors, customers, financial institutions, healthcare providers, and business partners that may legitimately trigger caution banners. Over time, users learn which messages are trustworthy, but that knowledge is not currently leveraged within the INKY banner experience.
This proposal introduces:
Community Trust Indicators ("Marked Safe" System)
Five-Tier Security Banner Classification Model
New Purple Classification for Sensitive Content
Progressive Banner Color Changes Based on Trust Validation
User, Group, Administrator, and Security Provider Trust Levels
The goal is to improve security awareness while reducing alert fatigue and helping users make better decisions.
Many emails generate recurring caution banners despite being regularly validated by users.
Examples:
Banking notifications
Customer invoices
Vendor ACH requests
Payroll communications
Healthcare correspondence
Internal applications
Users eventually ignore banners because they see the same trusted message repeatedly.
This creates:
Banner fatigue
Reduced effectiveness of warning systems
Increased likelihood of users overlooking actual threats
Allow users to mark emails as:
β "Safe"
INKY would then track:
Sender
Domain
Message characteristics
Similar email fingerprints
Future matching emails would display trust indicators directly in the banner.
π€β
Marked Safe by You
You have previously reviewed and approved similar messages.
π₯β
Marked Safe by Group
Multiple users within your organization have previously approved similar messages.
π‘οΈπ₯β
Trusted by Organization
Your IT or Security Administrator has validated and approved this communication.
ππ‘οΈ
Verified by SCRProtect
Your managed security provider or security operations center has globally approved this sender/content.
Current banner classifications provide excellent visibility into threats but could benefit from greater granularity.
Proposed Security Scale:
Yellow banners should remain dedicated to:
Examples:
Display name does not match sender
Executive impersonation
CEO fraud
CFO fraud
Examples:
Appears to come from internal staff
Originates from external infrastructure
Internal name spoofing attempts
Examples:
Microsoft
Amazon
UPS
FedEx
DocuSign
Adobe
Appears legitimate but originates from unrelated domains.
Examples:
Visual deception intended to trick users.
Many emails are not dangerous but contain information that requires extra care.
Current banners do not clearly distinguish:
Security threat
Confidential information
These are fundamentally different concerns.
Meaning:
"The email appears legitimate but contains information that should be handled carefully."
Examples:
Banking details
ACH instructions
Routing numbers
Account numbers
Wire transfer information
Banner Text:
Financial information detected. Verify before sharing or forwarding.
Examples:
Social Security Numbers
Date of Birth
Driver License Numbers
Passports
Banner Text:
Personal information detected. Handle according to company policy.
Examples:
Passwords
Recovery codes
MFA codes
API keys
Encryption keys
Banner Text:
Credentials detected. Do not forward unless explicitly authorized.
Examples:
Customer lists
Contracts
Internal financials
Employee data
Strategic planning documents
Banner Text:
Confidential company information detected. Distribution should be limited.
Examples:
Patient information
Medical records
Healthcare identifiers
Banner Text:
Protected health information detected. Follow HIPAA handling procedures.
When a user validates a previously flagged message, the banner should evolve.
π‘ Potential Sender Forgery
π Safe β Verified by You
Display:
π€β Marked Safe by You
π Verified by Group
Display:
π₯β Marked Safe by Group
π Trusted by Organization
Display:
π‘οΈπ₯β Trusted by Organization
π Verified by SCRProtect
Display:
ππ‘οΈ Verified by SCRProtect
This preserves historical visibility while reducing unnecessary concern.
Allow administrators to:
Approve trusted senders
Approve trusted domains
Approve specific brand impersonation exceptions
Set trust expiration periods
Revoke trust status
Export trust history
Audit user trust decisions
Users will stop seeing repeated warnings for known-safe communications.
Yellow banners become focused solely on sender identity concerns.
Purple banners educate users on handling sensitive information.
Trust decisions become shared organizational knowledge.
Users participate in the validation process while security teams maintain oversight.
The addition of Trust-Based Validation Indicators, Orange Verified Safe Banners, and a new Purple Sensitive Content Classification would significantly enhance INKY's effectiveness by reducing warning fatigue, improving user confidence, and providing a more mature risk-classification model aligned with real-world security operations and modern MSP/SOC workflows.
Please authenticate to join the conversation.
In Review
Email Security
22 days ago

Jason Johnson
Get notified by email when there are changes.
In Review
Email Security
22 days ago

Jason Johnson
Get notified by email when there are changes.