Gmail shows "Be careful with this message" when it has a reason to doubt an email, most often because it couldn't confirm the email really came from your domain. The line under the heading gives the reason, and when it's about verifying the sender, the fix is to make SPF or DKIM pass for your own domain in the service that sent the email.
The email is still delivered, but many people won't click a link or open an attachment under a yellow banner.
Read the line under the heading
The sentence below the heading says why. Ask a recipient for a screenshot, or send an email to your own personal Gmail account, then find the matching row.
| What the warning is about | What Gmail means | What you can do |
|---|---|---|
| Gmail couldn't verify the sender, often with a question mark next to the sender's name | Neither SPF nor DKIM passed, so Gmail can't tell the email came from you. | Authenticate your domain (see below). |
| The email claims to be from the recipient's own company | A Google Workspace check for unauthenticated email using the company's domain. | Authenticate every tool that sends as yourbusiness.com, including website forms. |
| The sender's name matches someone in the company, but the address is outside it | A Workspace protection against people impersonating staff. | Send work email from your company account, not a personal one. |
| The address looks like one the recipient knows, such as an O swapped for a zero | A lookalike address. | Send from one consistent domain. If it isn't you, someone may be imitating you. |
| The email may be phishing, or a link or attachment may be harmful | The content looks like a trick, or could harm the device. | See "Warnings about links and content" below. |
| "This message could be a scam" | It looks like a scam but came from someone in the recipient's contacts. | Check your account hasn't been hacked: change your password and turn on two-step verification. |
| Gmail hasn't scanned the message | Gmail's own checks didn't run. | Nothing. It's a fault on Google's side. |
The most common cause: Gmail couldn't verify you
Gmail checks two things to confirm who sent an email:
- SPF: a DNS record that lists the servers allowed to send email for your domain.
- DKIM: a digital signature that proves the email came from your domain and wasn't changed on the way.
Google's help says an email that arrives with a question mark next to your address wasn't authenticated, and that unauthenticated email is very likely to be rejected.
You can check one email yourself. Open it in Gmail on a computer, then click the Down arrow below the sender's name. Look for "Mailed by" and "Signed by". If "Signed by" is missing, or shows another company's domain instead of yourbusiness.com, DKIM isn't signing with your domain. That can also make Gmail show "via" next to your name.
This usually happens when:
- your website, online store or booking system sends email as yourbusiness.com through your web host
- a new tool (a CRM, invoicing app or newsletter service) sends as you, and you never added its DNS records
- you use Google Workspace and never turned on DKIM
Warnings inside your customer's company
Google Workspace admins choose what happens to email that trips each of these protections: keep it in the inbox with a warning (the default), move it to Spam, or hold it in quarantine. So the same problem can be a banner for one customer and a missing email for another.
One setting trips up many small businesses: it flags unauthenticated email that claims to come from the company's own domain. If your website form sends inquiries to your Workspace inbox "from" yourbusiness.com without SPF or DKIM, your own staff see the warning.
How to fix the authentication warnings
Step 1: find out what sent the email
Send an email from the same app to your private test address. The report names the sending service and shows whether SPF, DKIM and DMARC passed for yourbusiness.com, and whether they matched your From address (alignment).
Step 2: turn on DKIM for that service
Google Workspace: in the Google Admin console go to Apps → Google Workspace → Gmail → Authenticate email. Generate a DKIM key for yourbusiness.com, add the TXT record it shows at google._domainkey.yourbusiness.com, then click "Start authentication".
Other services: turn on DKIM signing for yourbusiness.com in the service that sends this email, and add the DKIM record it gives you to your DNS. Most services call this "domain authentication".
Step 3: check your SPF record
If Google Workspace sends your email, your SPF record should include it. For other services, add the include: value from their help pages to the same record. Keep only one SPF record.
v=spf1 include:_spf.google.com ~all
Step 4: add DMARC and test again
If you have no DMARC record, add this TXT record at _dmarc.yourbusiness.com. It starts in monitoring mode (p=none), so nothing changes for your email yet. Change the rua address to a mailbox you read.
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
Then send another test. When SPF or DKIM passes for yourbusiness.com, the authentication warnings should stop for new email. Emails that already arrived may keep their banner.
Warnings about links and content
Our test checks authentication and Gmail's sender rules, not your wording or links. If the warning is about phishing or a harmful link:
- link to your own website rather than shortened links
- never ask people to enter a password or card details from an email link
- avoid password-protected attachments, which can't be scanned for malware, and documents containing scripts
- make the sender name and address match who you really are
Checked against: Gmail Help, Check if your Gmail message is authenticated · Gmail Help, Report spam in Gmail · Gmail Help, "This message could be a scam" warning · Google Workspace Admin Help, Advanced phishing and malware protection · Google Workspace Status Dashboard, Gmail incident of January 24, 2026 · Google Workspace Admin Help, Set up DKIM.