Why a green tick does not mean an email is safe.
Some inboxes show a tick, a padlock or a "verified" label when an email passes its authentication checks. It feels like reassurance, and it is worth having. What it actually confirms is much narrower than it looks: that the message genuinely came from the domain in the From line and was not tampered with along the way. That is a statement about the envelope, not about whether the sender is who you should trust.
What the tick actually proves
The tick is the result of three checks working together, SPF, DKIM and DMARC. Between them they confirm two useful things:
- The email really was sent from the domain it claims, not forged by someone who does not control it.
- The content was not altered in transit between the sender and you.
That genuinely matters. It stops a criminal putting your bank's exact domain in the From line. It is a real and valuable check, and it is exactly why domain authentication is worth setting up properly.
What it does not prove
The tick says the email came from that domain. It does not say the domain deserves your trust. It cannot tell you the domain was registered last week, that it is a near-perfect lookalike of a brand you know, or that the person behind it is a criminal. Authentication was built to answer "did this really come from that domain", never "is that domain the real organisation, and is this request safe to act on".
The scam that passes every check
Picture an email from acme-invoices.com. It is not Acme's real domain, but a criminal registered it, pointed a mail service at it, and set up SPF, DKIM and DMARC on it correctly. Every authentication check now passes, because the email really did come from acme-invoices.com and really was sent by its owner. Your inbox may even show the reassuring tick. The domain is authentic. The sender is a fraud. Authentication has done its job perfectly and told you nothing about the danger.
How to judge an email properly
Keep the authentication check, then add the questions it cannot answer. Is this domain genuinely the organisation it claims, or a close imitation of it? How long has it existed? What does the wider network already know about it? A domain grade and a network lookup answer those directly, so a passing tick becomes one honest signal among several rather than a false sense of safety.
Got an email that "passed" but feels off? Forward it, free.
Send it to Sender Registry and we assess the sender, the domain, whether it is a lookalike, and what the network already knows. No account, no card. You get a plain-English verdict back.
Common questions
If an email passes SPF, DKIM and DMARC, is it safe?
No. Those checks only confirm the message genuinely came from the domain in the From line and was not altered on the way. They say nothing about whether that domain is trustworthy. A criminal can register a clean domain, set up authentication on it correctly, and send you a perfectly authenticated scam.
What does a green tick or "verified" label actually prove?
Only that the sending domain proved it is really that domain. It is a check of authenticity, not of intent. It is genuinely useful, because it stops a criminal forging a domain they do not control, but it is one signal about the envelope, not a verdict on the message inside.
So a scam email can pass every authentication check?
Yes, routinely. If the criminal owns the domain they are sending from, whether it is a throwaway domain or a lookalike of a brand you trust, they can pass SPF, DKIM and DMARC on their own domain. Authentication was never designed to tell a good sender from a bad one.
How should I judge an email then?
Treat authentication as one input among several. Look at whether the domain is genuinely the organisation it claims, whether it is a close lookalike, how long it has existed, and what the wider network already knows about it. Grading a domain and checking it against the network answers the question authentication cannot.