What Happened

A SaaS product sent a “New sign-in detected” email on every login from an unrecognised device. That included the customer’s own new devices, so the alert fired for normal behaviour as well as potential risk.

The email opened with two paragraphs about the company’s security practices. Only after that explanation did it name the device and location. Customers either ignored the message after enough false alarms or, in one flagged case, missed a genuine unauthorised sign-in because it looked identical to the earlier self-triggered alerts.

The Pattern

This is Consequence-After-Caveat, also called Caveat Before Consequence, applied to the one category where the consequence is genuinely severe. The message reassures and explains before showing the detail the reader needs to check.

Consequence-After-Caveat appears in 74% of audited emails. In a security alert, repetition makes the problem worse: when every instance looks the same, readers cannot distinguish a routine alert from a real account threat. The alert system spends trust before it needs to use it.

The Rebuild

Move the specific, checkable detail to the first line: which account, which device, which location, and when. Cut the security-practices paragraph from the transactional alert entirely. The reader is not evaluating the company’s security philosophy in that moment; they are checking whether the sign-in was theirs.

Replace a multi-click “Review account activity” link with two binary actions: “This was me” and “This wasn’t me”. The response should match the decision the reader is actually making.

Composite audit case. This is illustrative, not a named real client or a claim about a specific company.

Before
New sign-in detected. We take your security seriously and use industry-standard protections. Review account activity.
After
New sign-in to Acme, 14:32 UTC: Chrome on Windows from Madrid. This was me / This wasn’t me.
Evidence from 59 teardowns · original 3.4/10 to rebuilt 9.0/10
Consequence-After-Caveat in audited email74%
Original to rebuilt average3.4/10 → 9.0/10
PatternCaveat Before Consequence
The structural fix

Put the detail the reader can check before the explanation they can skip.

Name the account, device, location, and time first, then give one binary action. For a security alert, clarity is the safety feature.

Run Free Audit →See Pro plans →

Questions people ask

Why do users ignore security alerts?

Identical-looking alerts, regardless of real risk level, train readers to stop reading closely. A routine self-triggered alert and a genuine unauthorised sign-in become indistinguishable.

What is Consequence-After-Caveat?

Consequence-After-Caveat places background, reassurance, or organisational explanation before the outcome the reader needs to understand. It delays the reason to act until attention has already been spent.

What is the highest-leverage fix for a security alert email?

Move the specific detail to the first line: the account, device, location, and time. Then reduce the response to one binary action, such as “This was me” or “This wasn’t me”.

Related reading

Transactional messages work when the consequence is visible before the caveat.

Consequence-After-Caveat

SaaS Password Reset Emails Get the Structure Right by Accident. Marketing Emails Could Copy Them.

Field Note: The Renewal Reminder That Users Read as a Threat