| name | email-importance-content-analysis |
| description | Judge whether an email is important/urgent using content-based analysis rather than sender name or mailbox labels (which can be spoofed). Use when asked to triage emails, decide priority, detect phishing/social-engineering, or recommend next actions (reply/pay/login/download/click) based on what the message asks the user to do. |
Email Importance Content Analysis
Use a subject/title-first triage, then perform technical verification (headers/links/attachments) only when warranted, and only then validate with content analysis. Treat sender display name, badges, labels, and “From” appearance as untrusted.
Workflow (title → technical → content)
1) Title/subject + sender triage (cheap first-pass)
Use only: subject line + sender (display name + email address/domain as shown). Do not click anything.
Important: treat sender as weak signal (can be spoofed). Use it for triage only.
1A) Fast-drop rules (save time)
If the sender looks obviously sloppy/spoofed AND the email is not expected, classify as Likely scam/ads and stop (do not spend time on technical verification).
Examples of fast-drop signals:
- Display name claims a bank/government/major brand but the address is from a free mailbox (gmail/outlook/163/qq) or unrelated domain
- Lookalike domains / typo-squatting:
paypaI (I/l), micros0ft (0/O), extra -secure/-verify, weird punctuation
- Suspicious TLDs or brand stuffed into subdomain:
brand.security-check.example.com
- Very unprofessional local-part patterns (random digits/strings) while claiming official identity
- Pure promo patterns (promo/marketing/news) + obvious sales subject ⇒ treat as ads