Phishing protection
Phishing emails pose as your bank, a parcel service or a colleague to harvest credentials or money. YouniqMail checks incoming mail for the typical patterns and warns visibly, locally on your device, without mail contents going to any checking service.
What is checked
Section titled “What is checked”Several detection modules work together, each individually switchable under Settings → Security → Phishing Protection:
Sender authenticity proofs. Reputable mail servers sign their mail (DKIM) and declare which servers may send for their domain (SPF, DMARC). YouniqMail evaluates these proofs: SPF and DMARC from the verdict your mail server writes onto the mail, while it verifies the DKIM signature itself. A mail claiming to come from your bank whose authenticity check fails is highly suspect.
Suspicious traits of the mail itself. Sender and reply-to addresses that do not match, a display name faking a different domain, links leading somewhere other than their text claims: the classic sleights of hand.
You can have the authenticity results shown in every mail’s header area, by the way, not only in case of suspicion: switch on Show email authentication banner under Settings → Appearance → Email Detail. It is off by default.
The warnings
Section titled “The warnings”The warning banner sits above the text as soon as a module finds something, and names what stood out. Depending on the finding, it is a warning (Caution, Suspicious, High risk) or just a notice, for instance when a sender writes to you for the first time or the mail contains tracking pixels. The mail stays readable and you decide. From a medium risk upwards, the expanded banner offers Block sender, Move to Junk and Move to Trash.
The link preview shows at the bottom of the reading pane where a link really leads as soon as you hover over it. If the link looks suspicious, for example because its text names a different address than its actual target, the bar turns red.
The link confirmation asks before such a link opens in the browser, whether by click, by middle click or through Open Link in the context menu. It names the actual target and what stood out. The moment of pause that makes most phishing fail. You can switch it off under Settings → Security → Phishing Protection (Confirm suspicious links).
When a harmless mail gets flagged
Section titled “When a harmless mail gets flagged”It happens, say, with newsletters sent through delivery services whose authenticity records are sloppily configured. There is no exception for individual senders: the trusted senders list (Settings → Privacy) only applies to external images, not to these warnings.
The mail stays readable all the same; the banner blocks nothing. Most hints can be hidden with their cross (Dismiss), and they come back the next time you open the mail. The only permanent option is to switch off the module that raised the warning under Settings → Security → Phishing Protection, or the whole banner right there (Show warning banner). Either then applies to every mail.
What the protection cannot do
Section titled “What the protection cannot do”It checks patterns, not intentions. A well-crafted mail from a freshly registered sender triggers at most the notice that they are writing to you for the first time. The last line of defense remains you: no reputable provider asks for passwords by email, and urgency (“account will be locked in 24 hours!”) is almost always an alarm signal, precisely because it is meant to preempt thinking.
An unmasked sender can be blocked via the banner, via right-click with Block contact or under Settings → Blocked Contacts.