THE EMAIL GLOSSARY

A little less jargon.

Useful email terms, explained in the context of the decisions they support.

Short definitions, with a route into the full explanation. Provider-specific details and technical concepts are referenced in the linked guides and source library.

Spam

Unwanted email. It can include unsolicited promotions or abusive messages; not every unwanted message is necessarily a phishing attempt.

Explore spam filtering ↗

Phishing

A deceptive attempt to obtain information or induce an unsafe action by impersonating a trusted person, organization, or service.

Understand phishing checks ↗

False positive

A legitimate message incorrectly classified as spam. Investigate the result and verify the message before correcting it.

Review misplaced mail ↗

False negative

Spam that is not classified as spam. A low-risk label is not a guarantee that every request inside a message is safe.

Read about classification errors ↗

Classification threshold

A decision cutoff used to convert a score into a classification within a defined system. Different cutoffs change which items are flagged.

Understand scoring thresholds ↗

SPF

A mechanism for a domain to publish which systems are authorized to send using the relevant envelope domain identity.

Read the authentication guide ↗

DKIM

A domain-associated digital signature that can be checked against a published public key. It is not the same as message encryption.

Understand DKIM ↗

DMARC

A mechanism connecting authentication to the visible From domain through alignment, with policy and reporting capabilities.

Understand alignment ↗

Label

A category used to organize messages. Provider implementations differ; Gmail labels are not identical to traditional folders.

Build an organization system ↗

Archive

An action that can remove mail from the inbox while retaining the message. In Gmail, archived mail remains available in All Mail.

Read the archive example ↗

Inbox rule

A set of matching conditions and actions used to organize or handle messages. Personal rules are separate from a provider’s full filtering system.

Build careful filters ↗

Independent verification

Confirming a request through a known route that does not rely on the questionable message itself. This is a suggested security-review habit.

Explore verification habits ↗