Add an Inky-style caution banner to phishing tests
Your client’s users are used to seeing a “Caution: External” banner on email that comes from outside their company — the yellow strip their mail security adds to real outside mail. Because we deliver simulations straight to your users’ mailboxes, our phishing tests arrive without that banner. For a sharp user, a missing banner is a tell: real outside mail has one, this “outside” email doesn’t. Turning on our Inky-style banner puts that familiar marker back on the test, so it looks like the external mail they get every day.
The banner is a ready-made yellow “Caution: External” strip with Safe · Spam · Phish · More · FAQ links, rendered at the top of every phishing test for that client. You pick a size and we handle the rest — there’s nothing to paste in.
You’ll need
Section titled “You’ll need”- A client whose users see external-mail banners on real outside email (anyone running Inky or a similar external-mail warning).
- A decision on which size fits: a light one-line strip, a two-line version, or a full teaching banner.
- The client’s logo set in their branding, if you want it shown — the two larger sizes include it.
Turn on the banner
Section titled “Turn on the banner”-
Open the client and go to its phishing settings — the same area where you set the phishing test interval.
-
Find the “Inky-style External Banner” section and open the Variant dropdown. Pick a size:
- Micro — a single line (“Caution: External” plus the links). The lightest footprint.
- Mini — two lines: the caution line with the recipient’s address and the client’s logo, then the links.
- Verbose — a full caution headline with short “why this looks suspicious” callouts. Use this when you want the banner itself to teach.
-
Check the Preview. The panel next to the dropdown renders the exact banner your users will see. Switch sizes until it looks right.
-
Save your changes.
You’ll know it worked when
Section titled “You’ll know it worked when”- The Preview panel shows the yellow banner for the size you chose.
- The custom External Email Header field below is now greyed out — the banner takes that spot, so the two are never used at once.
- The next phishing test to land for that client shows the “Caution: External” banner at the top of the message.
Frequently asked
Section titled “Frequently asked”Which size should I pick? Match what your client’s users already see. If their real external banner is a slim one-liner, Micro blends in best. Mini is the natural default — it names the recipient and carries the client’s logo, so it reads like a real security banner. Verbose turns the banner into a teaching moment with spelled-out red flags; it’s the most educational but also the most obviously “this is a warning,” so reserve it for clients who want the coaching baked into every test.
What do the Safe, Spam, and Phish links do? They’re a live part of the test. If a user clicks Phish, that counts as reporting the message — a success, the same as using the Report Phishing button. If a user clicks Safe, that counts as a click — a failed test, the same as clicking a link in the body. So the banner isn’t just decoration: it’s another way the user’s judgement gets measured.
Doesn’t showing a “Caution” banner give the test away? It’s the opposite — it makes the test more realistic. Your client’s users see this banner on all their external mail, real and simulated, so it’s background noise to them, not a warning that stands out. A simulation that’s missing the banner is the thing that looks off. The lesson still lands: the user has to actually read the sender and the request, not just glance for a banner.
What’s the difference between this and the External Email Header field? Same spot on the email, two ways to fill it. The Inky-style banner is our ready-made version — pick a size and you’re done. The External Email Header is a blank field for pasting your own HTML if you want a completely custom banner. Choosing a banner size disables the custom field so you don’t accidentally set both; set the size back to Off if you’d rather hand-build one.
Does it show the client’s logo? The Mini and Verbose sizes include the client’s logo when one is set in their branding. Micro never shows a logo — it’s a single line by design. If a larger size isn’t showing a logo, set one in the client’s branding first.
Does this work for manually configured clients? The banner appears on tests we deliver directly through the client’s Microsoft 365 or Google Workspace connection. Manually configured clients don’t get it.
Do I need to set anything up on the client’s Inky (or their mail security)? No. This banner is ours, rendered into the simulation before it’s sent — it doesn’t touch the client’s mail security and needs nothing configured on their side. It only affects your phishing tests, not the client’s real mail.
Related
Section titled “Related”- Report Phishing button — the in-mailbox report action for users; the banner’s Phish link records a report the same way.
- Read phishing activity — where clicks and reports from the banner show up for each client.
- Phish verification page — how a customer’s IT team confirms a suspicious email was one of your tests.