What the indicators mean
The seal next to the sender, the warning banner and the security inspector, on Mac, iPhone and iPad.
FOLD stays quiet when a message checks out and speaks up only when something is wrong. Missing information alone never produces a warning.
The seal next to the sender
In the reader, a small symbol sits on the sender line. Click or tap it for a short explanation and the full breakdown.
| Symbol | Meaning |
|---|---|
| Green shield with check mark | Sender authenticated: DMARC passed for the sender’s domain, or a signature verified. |
| Brand logo with name | Verified brand, see brand logos. |
| Gray shield | No security information: some results exist, but no complete verdict, for example no DMARC result or only SPF. |
| Orange shield | Sender could not be verified: DMARC failed, a signature from the sender’s domain is broken, or an S/MIME or OpenPGP signature is invalid, revoked or made by someone other than the sender. |
| Red shield | Sender may be spoofed: another domain passed while the sender’s domain failed, or the message has more than one From header. |
Next to the seal, small symbols mark messages that are signed or encrypted.
The warning banner
When authentication fails, a banner appears above the sender line, before you read the address:
- Orange: Sender could not be verified, with the note that SPF, DKIM or DMARC failed or are missing.
- Red: Sender may be spoofed, because the message fails authentication for the displayed sender domain.
Details opens the breakdown. In the message list, the same two cases show a warning symbol next to the message.
Mailing lists
Mailing lists change messages on the way, for example by adding a footer, which breaks signatures legitimately. For messages with a List-Id header, a DMARC failure shows the gray shield instead of a warning.
The security inspector
On the Mac, click Security above the message, next to Header and Source. The button turns orange when there is a warning. On iPhone and iPad, open the Details menu in the message header and choose Security; on iPhone, expand the message header first.
The inspector lists:
- Brand, if a verified logo is shown, with the certificate authority.
- SPF, DKIM and DMARC with passed, failed, neutral or not verifiable.
- One DKIM signature line per signature: signing domain (
d=), selector (s=), algorithm, result, and not aligned if the domain differs from the sender’s. - S/MIME and PGP status, Signed by and the certificate or key Fingerprint.
not verifiable means the check could not be completed, for example because DNS was unreachable or the key was rotated. It is not a sign of tampering.