Prompt
How do I send security alert emails?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
To send security alert emails safely and effectively:
-
Use a trusted email service
- Send through your company’s mail system or a transactional email provider.
- Make sure SPF, DKIM, and DMARC are set up so messages don’t get flagged as spam.
-
Keep the message clear and actionable Include:
- What happened
- When it happened
- What the recipient should do
- Who to contact for help
-
Avoid sensitive details in the email body
- Don’t include passwords, full tokens, or unnecessary personal data.
- If needed, point users to a secure portal to review details.
-
Use strong subject lines Examples:
Security Alert: New Login DetectedAction Required: Password Reset NeededAlert: Suspicious Activity on Your Account
-
Verify the recipient and severity
- Send only to the affected user, security team, or designated distribution list.
- For high-severity incidents, use more than one channel: email + SMS + ticketing/incident system.
-
Log and monitor delivery
- Track whether the email was delivered, opened, and acknowledged.
- Retain logs for incident response and auditing.
-
Don’t make the alert itself look like phishing
- Use a consistent sender address.
- Include your organization’s contact info.
- Link to your official domain, not shortened links or random attachments.
Example template
Subject: Security Alert: New Sign-In Detected
Body: Hello [Name],
We detected a new sign-in to your account from [device/location] on [date/time].
If this was you, no action is needed.
If you don’t recognize this activity, please:
- Reset your password immediately
- Review recent account activity
- Contact security at [contact info]
Thank you,
[Security Team / Company Name]
If you want, I can also help you with:
- a template for employees
- a template for customers
- or how to send these automatically from code (e.g., Python, Node.js, SMTP, SES, SendGrid).