Five Email Red Flags You Should Never Ignore
From urgency manipulation to domain spoofing, these are the signals that distinguish legitimate emails from phishing attempts — and how Veilsort flags them automatically during on-device analysis.
Most phishing emails are not technically sophisticated. They do not exploit zero-day vulnerabilities or bypass encryption. They exploit human psychology — our tendency to trust familiar brands, respond to authority, and act quickly under pressure. Knowing what to look for is the single most effective defense. Here are five classic red flags, how Veilsort helps you reason about them with on-device AI, and — just as important — what Veilsort does not do.
1. Urgency Manipulation
"Your account will be suspended in 24 hours." "Immediate action required." "Unauthorized login detected — verify now." These are the classic tools of phishing: manufactured urgency that bypasses your critical thinking. Legitimate services rarely demand immediate action through email alone. When you share such an email with Veilsort, the on-device Foundation Model reads the body and surfaces urgency-style language in its summary and risk flags, with a verbatim supporting quote so you can verify the reasoning. According to NIST's Phish Scale framework, urgency and pressure are among the most reliable cues for identifying phishing attempts.
2. Mismatched Sender Information
Phishing emails often display a legitimate sender name but send from a completely different domain. "PayPal Support" might come from paypal-secure-alerts@random-domain.xyz. Veilsort does not parse email headers, validate SPF/DKIM, or compare From/Reply-To/Return-Path — v1.0 is text-only. What it does is read the body of the email and flag risk language that asks you to "verify your account," "confirm your details," or take action that the claimed sender would normally not request by email. If the email itself reads as an impersonation attempt, the model flags it. To verify the actual sending domain, you still need to check the message headers in Mail.app — Veilsort does not do that for you.
3. Suspicious Links and Attachments
The most dangerous element in a phishing email is the link. Displayed text that says "paypal.com/verify" but links to "paypa1-secure-login.ru" is a classic technique. Veilsort does not follow redirect chains or resolve link destinations — doing so would require network access, which is incompatible with the zero-network architecture. What Veilsort does is read the link text the email presents and reason about whether the surrounding context (urgency, credential requests, impersonation language) is consistent with a legitimate request. Attachment analysis is out of scope for v1.0; Veilsort analyzes the email body text only.
4. Requests for Credentials or Financial Information
No legitimate company will ask you to send your password, credit card number, or Social Security number via email. Ever. Veilsort's PII masking layer detects and tokenizes personal identifiers before the model sees the text, and the model itself is instructed to flag emails that solicit sensitive information. If the email asks you to reply with your password, click a link to "verify your payment method," or download a form to "update your account details," the risk flags reflect that. Each risk flag includes a domain (legal, financial, employment, privacy, reputation, or safety), a severity of low, medium, or high, and a verbatim quote from the email.
5. Unusual Language Patterns
Phishing emails from non-native speakers often contain subtle linguistic anomalies: awkward phrasing, inconsistent formality, unusual capitalization, or grammatical structures that do not match the claimed sender's typical communication style. Veilsort uses Apple's on-device Foundation Models to read the email and surface those inconsistencies in its summary and risk rationale. The model is not fine-tuned by Veilsort and Veilsort does not train a custom model on your inbox; each analysis is independent and uses the Apple-bundled model as-is.
| Red Flag | What to Check Yourself | What Veilsort Does On-Device |
|---|---|---|
| Urgency | Deadline threats, pressure language | Foundation Model surfaces urgency in summary + risk flags with verbatim quote |
| Sender mismatch | Display name vs. actual domain (check headers in Mail.app) | Reads email body; flags impersonation-style requests (does not validate headers/SPF/DKIM) |
| Suspicious links | Display text vs. href destination | Reads link text + surrounding context; does not follow redirects or resolve destinations |
| Credential requests | Asks for passwords, payment info | PII masking + Foundation Model risk flag with domain and severity |
| Language anomalies | Awkward phrasing, inconsistency | Apple Foundation Model reasoning over email body (no custom fine-tuning) |
None of these checks require a server. PII masking, Foundation Model inference, and result rendering all run locally on the device. The result is an analysis that helps you reason about whether an email is safe — without sending that email to a third party to get a second opinion. Veilsort does not replace checking headers in Mail.app or basic skepticism about unexpected links, but it gives you a private, on-device second read on what the email is actually asking for.