Enhancing Phishing Defenses: The Impact of Timing and Explanations in Warnings for Email Clients

Francesco Greco, Giuseppe Desolda, Paolo Buono, Antonio Piccinno · Computer Standards & Interfaces · 2025

• Show the warning after seeing the email content : in the case of phishing emails, the warning should be visualized after visualizing the email content. • Adopt explanation messages in the warning. Including explanation messages in the warning dialog helps users detect more phishing emails. • Adopt hybrid warnings to improve the overall defense: while for phishing emails warnings must be shown after and with an explanation, in case of false positive emails, the warning must be visualized as a pop-up when the user hovers over the link and without explanation. Phishing attacks continue to represent a significant risk to digital security due to their reliance on exploiting human vulnerabilities before those of computer systems. To try to limit the effectiveness of this threat, this paper explores new strategies to design warnings shown to users in the presence of suspicious phishing emails. A controlled experiment was conducted with 900 participants to investigate the impact of two factors on warning effectiveness: the warning activation timing (before or after the opening of an email) and the presence of explanation messages in the warning. The study results indicate that warnings displayed after users have read the content of the email significantly reduce click-through rates, demonstrating greater effectiveness in preventing phishing. Furthermore, the presence of explanations also determined a lower click-through rate. Nevertheless, displaying warnings without explanation and simpler warnings for false positive emails may be necessary. The details of these findings were presented as lessons learned that can drive the design of more effective warning systems.

Read the paper · More papers on PaperTik