skip to content

We train staff to check sender domains and spot bad grammar — what does that actually catch?

level: seniorimportance: must knowfreq 50%

answer

  1. each tell is a cost the operator declined
  2. fluent prose now costs nothing
  3. a lookalike domain is minutes and pounds
  4. the third rung has no wrong domain
  5. absence of a tell is not evidence

basics

~20 s

Only the cheapest rung. Both tells are artefacts of lures the operator paid nothing for, and both vanish once the message is sent from a real mailbox on a real domain, where prose and address are genuine.

solid answer

~50 s

Bad grammar and a wrong sender domain price one thing: an operator who invested nothing. Broken prose comes from bulk generation, and it now costs nothing to remove. A visibly wrong domain is what a display-name-only spoof or a lookalike registration leaves behind, and a lookalike costs a few pounds and a few minutes. Neither tell survives the rung where the operator sends from a mailbox they actually control at a third party: there the domain is genuinely right, the prose is the real correspondent's own, and the thread history is authentic. So the training removes the messages that would mostly have failed anyway and none of the ones that convert. Worse, it teaches a direction error: staff read a clean domain as positive evidence, when a check that does not fire proves nothing at all.

go deeper

for a junior

Know that misspelled domains and clumsy wording belong to the cheapest messages, and that neither appears when the message comes from a real mailbox the operator has taken over.

for a middle

Explain each tell as the residue of a cost the operator declined to pay, and be able to order the rungs — spoofed display name, lookalike registration, genuine third-party mailbox — with what each costs.

for a senior

Handle the reviewer's claim without dismissing it: concede what the checks buy, show the rung they cannot reach, and name the direction error where staff read an absent tell as positive evidence.

for a principal

Be ready to argue the reallocation. If the residual after coaching is the whole set of messages that convert, the spend belongs in removing what the request depends on, and you will have to make that case to people who already funded the awareness line.

## Take the claim seriously first The claim is not worthless, and an answer that simply mocks it will not land. Checking the sender domain and noticing bad prose does remove a real volume of messages, and it removes them at nearly zero cost. The defect is not that the tells are useless. The defect is treating them as a ladder when they are a single rung, and treating a pass as evidence. ## What each tell is actually pricing Think of a lure as a purchase, and each recognisable tell as the residue of a cost the operator declined to pay. **Bad grammar** is the residue of bulk generation with no per-message effort. Historically it also served a filtering purpose: an operator who intends to run a manual conversation only wants replies from people unlikely to back out, so obvious clumsiness screens out anyone attentive before the operator spends time on them. Either way, prose quality is now the cheapest thing on the list to fix. Treating fluent writing as reassuring inverts the signal: fluency indicates an operator who spent something, which is worse news, not better. **A wrong sender domain** is the residue of not controlling a mailbox on the right one. Display-name-only spoofing — where the friendly name reads as a colleague and the address is unrelated — is the free version. A lookalike registration, one character off, costs a domain registration and minutes of setup. Both leave something a careful reader can catch on the `From` line. ## The rung neither tell reaches Now consider the operator who has a foothold in a mailbox at a supplier or managed-service provider, and replies inside a live thread. The sender domain is not a lookalike; it is the correspondent's real domain, because the message really left that mailbox. The prose has the correspondent's own habits because the operator can read hundreds of that person's messages and, more decisively, because most of the visible text is quoted history the correspondent actually wrote. There is nothing on the `From` line to catch and nothing in the writing to catch. That is the entire point of the ladder framing: | Rung | What the operator pays | Grammar tell | Domain tell | |---|---|---|---| | Bulk, spoofed display name | nothing | present | present | | Lookalike domain, written by hand | a registration and some effort | absent | present, one character | | Real third-party mailbox, real thread | access to somebody else's mailbox | absent | absent | The two taught tells cover the top two rows. The messages that reach a conversion decision come from the third. ## The direction error the training installs There is a second and subtler problem. A check that fires tells you something. A check that does not fire tells you almost nothing, and people do not naturally reason that way. Staff coached on two tells will find both absent and conclude the message is fine — converting the absence of a signal into positive evidence of legitimacy. In a population where the strongest lures are precisely those that pass both, the training has produced confidence that is anti-correlated with safety. A related error is worth naming because it appears in almost every weak answer: 'the domain is correct so the sender is genuine'. A message that genuinely originates from a real mailbox proves that credentials for that mailbox were accepted. It does not prove the named person composed it. Account and human are different things, and conflating them is the assumption the whole technique is built on. ## What to say instead The useful reframe is that recipient-side tells are a cost imposed on the operator, not a barrier. You raise the price of the cheapest lure, which is worth doing precisely because it is nearly free to do — but you should size the residual honestly: after the training, the messages that arrive from real mailboxes inside real threads are entirely unaffected. That is where the argument turns to control classes. If the strongest lure is indistinguishable at reading distance, the thing to remove is not the recipient's misjudgment but the dependency: a request in a thread should not be able to complete an action that changes a standing instruction, a destination or an access grant. When the action can only be performed by the counterparty authenticating for themselves in a system of record, the operator's authentic thread has nowhere to convert. Prose and domains stop mattering because reading is no longer what stands between the message and the outcome. ## Answering the reviewer A good answer to 'we check domains and grammar, so we are fine' has three moves: agree that the checks remove the free rung; show the rung they cannot reach and why it is cheap enough to be routine; and name the direction error, because that is the part the reviewer has not considered and it is the part that turns a partial control into a false assurance.

  • So should we stop teaching the domain check?
    No — it is close to free and it removes the rung that costs the operator nothing, which is worth having. Stop presenting it as sufficient, and stop presenting a pass as reassurance. The honest framing is that it raises the entry price slightly and does not touch the messages that convert.
  • Why is fluent, well-written text arguably worse news than clumsy text?
    Because prose quality now tracks operator investment rather than operator competence. Clumsy text usually means a bulk run with no research behind it; polished text on a topic that fits your week means somebody spent effort on you specifically. Reading fluency as reassurance gets the relationship backwards.
  • What is left to distinguish, if the message itself is not distinguishable?
    The action, not the message. What the request is permitted to accomplish, whether it changes something standing rather than something one-off, and whether it can be completed inside the conversation at all. Those properties survive a perfect message, and none of them require the recipient to make a judgment call about wording.

saying these in an interview costs you the question

  • Treats a correct sender domain as evidence the request is genuine
  • Assumes attackers cannot write fluently in the target's language
  • Thinks registering a lookalike domain is slow or expensive
  • Says a correct domain proves the named person sent the message
  • Concludes a message is safe because no taught tell fired

context