// HOW PROTECTION WORKS

Mostly, you don't have to do anything.

OpenShield's default mode for Gmail is automatic: connect one or more Gmail accounts once, and OpenShield watches each one's Spam folder itself, flags the dangerous senders, and reports the clear-cut cases for you — no button to click, ever. It never modifies or deletes anything in your mailbox; the only thing it ever does is file an OpenShield report on your behalf. This is the feature internally called Enhanced Protection, and it's what the extension leads with now.

Because it shows you what it found, it does keep a small amount of each flagged message's content (the subject, a short snippet, and the sender's address) — visible only to you in your supporter portal, and deleted the moment you disconnect that account or request account erasure.

If a sender is already known to be dangerous, just hover it in your message list — the extension shows a single warning strip across the top of the page (styled to look like your webmail’s own notices), telling you how many people have reported the same sender and giving you one-click buttons to report it or start a data-rights request. For genuinely dangerous senders it goes one step further and stops the email from opening until you choose “Open anyway” — so a risky message can’t be opened by accident. You can still select, archive, or delete it without opening it. Nothing is sent anywhere just by hovering — the warning is just OpenShield telling you what it already knows.

You don't even have to hover. The extension checks every sender visible in your message list against the community database as you browse, and when known dangerous senders are in view it shows one summary notice up top recommending you don't open those emails. And if you're unsure about a specific message, right-click it and choose “Is it safe to open?” — the verdict (including an explicit “looks safe”) appears in the same strip, without the email ever being opened. It works on links and selected addresses too.

Even before a sender is confirmed dangerous, if other people have already reported it, hovering it shows a quieter heads-up — how many reports it has so far, and a one-click way to add yours. Those early reports are exactly what tips a borderline sender over the line into a full investigation, so adding yours genuinely helps. Where your residency gives you GDPR/UK-GDPR rights against a sender, the same strip also tells you — including that an ignored deletion demand can escalate to a settlement demand seeking compensation (see Enforce your rights).

Need to report one by hand? The manual tools are mainly there for enterprise IT and security teams triaging a specific incident — most individuals never need them, because Enhanced Protection already reports the clear-cut dangerous senders for you. When you do want to: open a spam email in Gmail or Outlook and click "Report to OpenShield", right-click a sender or link, or use the extension's "add a domain manually" form. That's the whole job — no copying headers, no filling out forms. On Gmail, we can often pull the header proof automatically; on Outlook and the Gmail mobile app, we use what's visible on screen instead.

Wondering what happened to what you reported? Your supporter portal now has a "My Reports & Impact" section listing every sender you've reported and its current status — under review, noticed, enforced, or resolved. You'll also get a notification the next time one of your reports reaches a new stage, whether or not you've ever contributed to an escrow pot.

Already dealt with a sender? Click "Mute" (in the extension's warning strip or the Gmail spam list in your portal) to stop seeing warnings about it — this only quiets your own view. It never affects the sender's public case, anyone else's warnings, or whether the community can still report it.

Curious about the bigger picture? Your portal's "Your threat landscape" section shows how many confirmed operator networks your own reports have helped expose — everything shown there is already public information (the same wall-of-shame data anyone can see), just personalized to your own reporting history.

Want to support OpenShield directly? Beyond a one-off "buy us a coffee" payment, your portal's support page now offers an optional recurring Supporter+ plan. It only ever unlocks harmless conveniences (faster sync, an optional recognition badge) — it never speeds up or changes how your reports are verified, counted, or escalated. That stays identical for everyone, always.

Want more than a warning? Active Protection is a second, separate opt-in in your connection settings: once granted, OpenShield creates a real Gmail filter (visible and removable from your own Gmail Settings at any time) for senders the platform has confirmed dangerous, so their next email skips your inbox instead of just showing a warning. It only ever labels and archives — never deletes.

Use Outlook or Hotmail? OpenShield now offers the same automatic protection for personal Outlook/Hotmail accounts — connect once in your portal, and OpenShield checks your Junk Email folder and reports the clear-cut dangerous senders for you, exactly like Enhanced Protection does for Gmail. It never modifies or deletes anything in your mailbox.

What a report carries. A manually or automatically filed report always carries the technical envelope of the one message involved (headers) beyond the minimal retention described above for Enhanced Protection — the raw technical data is thrown away the moment we've extracted the proof we need. Following a completed legal review, the platform can now also capture a copy of the message body itself from the extension, strictly to strengthen the evidence behind a report — but only ever a redacted copy: personal details (other email addresses, phone numbers, physical addresses, and financial/payment identifiers) are stripped out automatically, server-side, before anything is ever written to storage, and the unredacted text is never kept anywhere, even briefly. This doesn't change what Enhanced Protection already does, and manually pasted reports remain header-only. See our privacy policy for the full picture.

Both reporting and Enhanced Protection require being signed in — this is the one piece of friction we ask for, and it exists purely to stop the reporting system itself from being spammed or gamed. See Your account for how sign-in works.