$ ls topics/{shield,product-design}
·4 min read
Junk email anxiety
Why people treat the junk folder as a second inbox, and how that behavior changed the way we designed Shield's Security Briefing.
Ben Hathaway
Chief Technology Officer
Soon after we released Shield, a small group of early users told us it was creating more work for them. Shield was keeping more unwanted mail out of their inbox, which meant there was more mail in Junk. They felt responsible for reviewing all of it.
That feedback confused us at first. I hardly ever looked at my junk folder. It was the place mail went when I did not need to see it. These users treated theirs differently. They checked it every day, looked for false positives, and cleared it to zero. More junk meant a larger queue of work.
They were managing a second inbox.
A habit built by uncertain filters#
The habit makes sense when you look at how people learned to use email. Spam filters have always had to balance two bad outcomes: letting unwanted mail through and catching mail someone wanted. As filters tightened to catch new threats, some legitimate messages ended up in Junk. People learned that the filter was usually right, but not reliable enough to ignore.
Email clients made the problem worse. A gateway could let a clean message through, only for Outlook to move it into Junk. The user would drag it back and tell Outlook the sender was safe, then watch another message from the same sender land in Junk later. The specific layer that made the decision did not matter to the person waiting on a quote, an order, or a customer reply.
For someone whose work depends on email, a missed message can cost real money. Checking Junk becomes the rational response. The folder may contain hundreds of messages that deserve to be ignored, but one important message is enough to justify looking.
Years of that uncertainty trained people to distrust every filter in the stack. A better filter inherits the behavior created by the ones that came before it.
The gray area belongs to the user#
Perfect filtering cannot solve this problem because some email has no objective right answer. A phishing message is malicious. A newsletter or advertisement may be useful to one person and unwanted by another. The same person may want it this month and ignore it the next.
Security products still need to make a delivery decision, but accuracy is only part of the job. Even a very accurate system leaves the user with the same thought: “I may have missed something.” As long as that thought is unresolved, they will keep checking Junk.
We started calling that feeling junk email anxiety. Naming it helped us see that we had been aiming at the wrong outcome. Improving the filter might reduce how often a user finds something important in Junk. It cannot prove that nothing important is there.
The product needed to give people confidence that they had not missed anything without asking them to sort through the junk folder every day.
A briefing instead of another inbox#
That job led to Security Briefing. It gives each Shield user a focused view of the messages that did not reach the inbox, along with new senders waiting on a trust decision. A user can scan the list, inspect a message when something looks unfamiliar, take action, and get back to work.
The briefing is a focused review, separate from the mailbox itself. It answers a narrow question: did Shield keep out anything I care about?
People have different tolerances for that uncertainty, so the briefing cannot have one fixed definition of what everyone should review. One person may only want to see messages held in Jail. Another may want Junk and new-sender mail included. Preferences control which decisions and risk levels appear, along with when the notification arrives. The person who depends on every inbound lead can look more closely without imposing the same routine on someone who rarely needs email from an unfamiliar sender.
Security Briefing also preserves the evidence behind each decision. The list shows what Shield knew when the message arrived: the sender’s trust state, the delivery decision, and the risk level. Opening the message shows its current state after any changes. That gives the user enough context to correct a decision without turning review into an investigation.
The goal is a short visit with a clear end. Review what Shield kept out, act on the few messages that need attention, and leave knowing there is no second inbox waiting to be managed.
Product design inherits old behavior#
The early feedback was useful because the problem was larger than the new flow of messages into Junk. Shield had entered a workflow shaped by years of false positives, inconsistent clients, and filters people could not fully trust. Changing the filtering model did not erase what users had learned to do.
That is part of product design, especially when replacing infrastructure people have used for years. The existing behavior may look inefficient from the outside, but it often protects the user from a failure they have experienced before. Removing the reason for the behavior is not enough. The product has to replace the confidence the behavior provided.
People want to know every important message reached them. Security Briefing was built to give them that confidence without another folder to manage.
