External email warning banners — copy the variant you need

Each block below is self-contained inline-styled HTML, safe for an Exchange Online "prepend disclaimer" mail-flow rule. Rotate between variants to prevent habituation.

Variant 1 — Classic red caution (from the book)

BE CAUTIOUS: This email comes from an external address.

Variant 2 — Amber "external sender" strip

EXTERNAL SENDER — This message originated outside the organisation. Verify the sender address before clicking links or opening attachments.

Variant 3 — Question prompt (engages System 2)

External email. Were you expecting this message? Does the sender's address match who it claims to be? If unsure, use the Report Phishing button.

Variant 4 — Minimal dark tag

EXTERNAL Sent from outside the organisation — check the full sender address.

Variant 5 — "Warnings on steroids": gaze cue

Research shows an image of eyes looking toward the warning text significantly increases attention (we innately follow the gaze of others). The image below is embedded in Base64, so it needs no external hosting.

CAUTION — external email. Check the sender address before acting on this message.

Source: “Get Phishing Under Control”, Phase 2 — Helping People Detect Phishing (sections 2.1 Warning Banners & Warnings on Steroids).