Security Alert and Authentication Email UX Audit
Evaluate critical security, password reset, and 2FA transactional emails for psychological clarity and phishing resistance.
Use this template when revamping mission-critical authentication, MFA confirmation, or password recovery transactional emails. It assesses cognitive load during high-stress user moments while ensuring high security compliance and trust.
Role: Cybersecurity Communications Director and Product UX Strategist
Context
- Platform Name: {{platform_name}}
- Risk Classification: {{platform_threat_model}}
- Current Auth Email Text: {{auth_email_payloads}}
- Token and Expiry Lifespans: {{security_token_lifespan}}
- Target User Technical Literacy: {{user_technical_literacy}}
Task
Perform a UX and security communications analysis of {{platform_name}}'s authentication and security transactional emails, establishing clear protocols that prevent phishing vulnerability, decrease user lockout panic, and streamline identity verification.
Method
- Dissect each notification in {{auth_email_payloads}} for cognitive load, clarity of intent, and ambiguity during account recovery states.
- Review device, location, and timestamp contextual cues to ensure non-technical users can identify unauthorized access attempts under {{platform_threat_model}}.
- Verify that urgency cues avoid dark patterns or panic-inducing triggers while conveying necessary security severity.
- Audit the friction introduced by {{security_token_lifespan}} against the reading and execution speed of {{user_technical_literacy}}.
- Benchmark the copy against anti-phishing design standards (omission of suspicious links, authentic signature verification cues, domain clarity).
- Formulate precise textual and structural revisions for magic links, 2FA tokens, and anomalous login notifications.
Constraints
- MUST evaluate both legitimate access flows and unauthorized attack notifications.
- MUST NOT propose masking or shortening sensitive security URLs in ways that mimic phishing mechanisms.
- Recommendations MUST accommodate the specific constraints of {{security_token_lifespan}}.
- Text suggestions must match the literacy baseline of {{user_technical_literacy}}.
Output format
- Security Communications Vulnerability Matrix (Audit of {{auth_email_payloads}} across threat vectors)
- Friction & Cognitive Load Breakdown (Evaluation based on {{user_technical_literacy}})
- Security Notification Optimization Specs (Annotated copy frameworks for Magic Link, 2FA, Password Reset, and Login Alerts)
- Anti-Phishing Authentication Protocol (Guidelines for dynamic header metadata, device identifiers, and support escalation paths)
Self-review
- Did I balance high-level security rigor with effortless user readability?
- Are the expiry warnings practical for {{security_token_lifespan}}?
- Does the analysis address threat mitigation under {{platform_threat_model}}?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.