Notion and Linear make the recurring pattern clear: these alerts name a new login, then supply location and device context. Repeated Close, Linear and Doppler sends keep the focus on review and account recovery.
Updated Oct 4, 2026
Most subjects identify a recent access event with compact wording. Notion uses "A new device logged into your account", while Linear repeats "New login to Linear" and Close repeats "New sign in". OpenAI names the account in "New sign-in to your OpenAI account", and Doppler uses "New Dashboard Login". Fivetran is the clear variation with "[Fivetran] Password Changed", which reports a completed password action rather than a login.
The order also shows repeated alerts without changing the core subject. Close sends "New sign in" twice, Linear sends "New login to Linear" twice, and Doppler sends "New Dashboard Login" twice. Preview text adds operational detail: Linear uses "Login detected with Chrome on Linux from Helsinki, 18, FI" in one email and changes only the location in the later version. Close reuses "We noticed a new sign in to your Close account" in both sends.
Every email in this collection is a security alert, and the content consistently identifies an account event and provides guidance for what to do next. Notion, Linear, OpenAI, Doppler, Close and Customer.io include combinations of time, location, device, browser, operating system or IP address. That detail gives the recipient context for reviewing the activity and deciding whether further account action is needed.
The next step varies by the event and brand. Notion advises resetting the password and enabling multi-factor authentication when the login was unrecognized. Close advises changing the password and enabling two-factor authentication when the activity was unauthorized. Linear directs recipients to review active sessions, while Doppler directs them to manage active sessions or reset the password. Customer.io explains how to reset the password. Fivetran confirms a password change and directs the recipient to support if help is needed.
Personalization appears in 50% of all the emails in this collection. The personalized emails are Notion's email, both Doppler emails, one Close email and Customer.io's email. A single CTA appears in 40% of all the emails in this collection: Notion's email, both Linear emails and Customer.io's email. The relevant subjects include "New Dashboard Login" and "New sign in to your Customer.io account".
The visual treatment ranges from branded color to plain text. Doppler uses purple on a dark background, Close uses blue, Customer.io uses green, the later Linear email uses blue and purple, and OpenAI uses black and white. Fivetran is the only plain-text email, accounting for 10% of all the emails in this collection.
Security alerts notify users about sensitive account activity: a new login, a changed password or a new device. They have to be clear and calm, with an obvious next step if something is wrong.
Include the action, time, device and approximate location.
A single "Secure my account" button beats a list of instructions.
Tell users you will never ask for their password by email. It helps them spot phishing that imitates you.
What the 10 examples in this collection have in common.