Transactional
AuraScore 81/100

Security Alert and Authentication Email UX Audit

Evaluate critical security, password reset, and 2FA transactional emails for psychological clarity and phishing resistance.

Use this template when revamping mission-critical authentication, MFA confirmation, or password recovery transactional emails. It assesses cognitive load during high-stress user moments while ensuring high security compliance and trust.

Template

Role: Cybersecurity Communications Director and Product UX Strategist

Context

  • Platform Name: {{platform_name}}
  • Risk Classification: {{platform_threat_model}}
  • Current Auth Email Text: {{auth_email_payloads}}
  • Token and Expiry Lifespans: {{security_token_lifespan}}
  • Target User Technical Literacy: {{user_technical_literacy}}

Task

Perform a UX and security communications analysis of {{platform_name}}'s authentication and security transactional emails, establishing clear protocols that prevent phishing vulnerability, decrease user lockout panic, and streamline identity verification.

Method

  1. Dissect each notification in {{auth_email_payloads}} for cognitive load, clarity of intent, and ambiguity during account recovery states.
  2. Review device, location, and timestamp contextual cues to ensure non-technical users can identify unauthorized access attempts under {{platform_threat_model}}.
  3. Verify that urgency cues avoid dark patterns or panic-inducing triggers while conveying necessary security severity.
  4. Audit the friction introduced by {{security_token_lifespan}} against the reading and execution speed of {{user_technical_literacy}}.
  5. Benchmark the copy against anti-phishing design standards (omission of suspicious links, authentic signature verification cues, domain clarity).
  6. Formulate precise textual and structural revisions for magic links, 2FA tokens, and anomalous login notifications.

Constraints

  • MUST evaluate both legitimate access flows and unauthorized attack notifications.
  • MUST NOT propose masking or shortening sensitive security URLs in ways that mimic phishing mechanisms.
  • Recommendations MUST accommodate the specific constraints of {{security_token_lifespan}}.
  • Text suggestions must match the literacy baseline of {{user_technical_literacy}}.

Output format

  1. Security Communications Vulnerability Matrix (Audit of {{auth_email_payloads}} across threat vectors)
  2. Friction & Cognitive Load Breakdown (Evaluation based on {{user_technical_literacy}})
  3. Security Notification Optimization Specs (Annotated copy frameworks for Magic Link, 2FA, Password Reset, and Login Alerts)
  4. Anti-Phishing Authentication Protocol (Guidelines for dynamic header metadata, device identifiers, and support escalation paths)

Self-review

  • Did I balance high-level security rigor with effortless user readability?
  • Are the expiry warnings practical for {{security_token_lifespan}}?
  • Does the analysis address threat mitigation under {{platform_threat_model}}?
AuraScore breakdown
81/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering12/12 · Strong

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness3/5 · Adequate

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

emails
emails-transactional
business-strategy-marketing-sales
authentication
security-emails
ux-copywriting