Data & Privacy
How A Scam Email Gets Past Every Filter
Mail filtering combines sender authentication, reputation and content analysis, and targeted fraud defeats it by being indistinguishable from legitimate correspondence.

Filters remove the overwhelming majority of unwanted mail without anyone noticing. The messages that cause real harm are the ones that give the filters nothing to object to.
Authentication checks the sender's claim
Mail carries a claimed sending domain that is trivial to forge, so receiving systems check whether the sending server was authorised to send for that domain.
Additional mechanisms attach a cryptographic signature to the message and publish a policy stating what to do when checks fail.
Together these make direct impersonation of a protected domain difficult, which pushed attackers towards domains that merely resemble the real one.
Reputation does most of the filtering
Receiving systems track behaviour by sending address, network and domain, scoring each on volume, complaint rates and how long it has existed.
Bulk campaigns from new infrastructure are caught by this alone, before any content is examined, which is why most unwanted mail never arrives.
The consequence is that attackers value access to established accounts, since a message from a reputable source inherits its standing.
Content analysis looks for patterns
Classifiers trained on enormous volumes of mail weigh wording, structure, links and attachments against what legitimate correspondence looks like.
They perform well on templated fraud and poorly on short, plain messages, because a two-line note asking a colleague a question contains almost no signal.
This is why the most damaging messages are frequently the least elaborate. There is nothing in them for a classifier to catch.
Targeted fraud avoids every signal
A message sent to one recipient from a legitimate compromised account, referencing a real project, passes authentication, carries good reputation and reads normally.
Every mechanism reports that this is ordinary mail, and by the standards each is measuring, that assessment is correct.
The fraud lies in the request rather than the message, which is why controls that verify the request through another channel work where filtering does not.
Warnings are placed where signals are weak
Providers add banners for external senders, first-time correspondents and addresses resembling known contacts, because these are the cases classification cannot resolve.
Such warnings appear on a great deal of legitimate mail, and their effectiveness falls as people learn to look past them.
The remaining defence is procedural rather than technical, since a message that satisfies every automated check can only be questioned by someone who expects to verify unusual requests.
Questions readers ask
What happens if I lose my phone?
If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.
Is a passkey the same as biometric login?
No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.





