Family Sentinel

Email security tips you can share

34 scam-prevention graphics, each showing what the message actually looks like and the one detail that gives it away. Every one is free to share, print and post — no sign-up, no attribution fee, no catch.

Every example below is invented. We do not reproduce real scam messages, and no real company is impersonated in any of these images — a convincing forgery of a named bank is still a forgery, whoever makes it.

Using these

You may share these images unaltered, free of charge, with attribution to Family Sentinel (familysentinel.org). No permission request needed. Libraries, senior centres, churches, chambers of commerce, caregiver groups and employers are all welcome to use them in newsletters, on lobby screens, in slide decks and on printed handouts.

If you would like a version crediting your own organisation alongside ours, or a printable letter-size sheet, get in touch and we will send one.

We also give a free, educational “Spot the Scam” talk for community groups. No sales pitch and nothing to sign up for.

Who the message is really from

Every one of these turns on the same fact: the name and address you see in an inbox are typed by whoever sent the message. None of it is verified by the act of arriving.

Pin explaining display-name impersonation, showing a sender whose friendly name reads as a bank while the real address is a personal gmail account

Display-name impersonation

The name says your bank. The address says otherwise.

This is the most common trick aimed at older people and it takes no technical skill at all — the sender simply types a company name into the 'from' field. One tap exposes it every time.

What arrives

  • From: Meridian Bank Security
  • <service.alert@mail-mrdn-verify.co>
  • Unusual sign-in. Confirm it was you.
  • The name is typed. The address is not.

The tell

The friendly name is typed by the sender and proves nothing. Expand it to see the real address: Meridian Bank <kevin83@gmail.com>

What to do

On a phone, tap the sender name to expand it. On a computer, hover over it. Never trust the name alone.

Pin explaining lookalike and homoglyph scam domains such as paypa1.com and chase-alerts-secure.com

Lookalike and homoglyph domains

One character changed, and it is a stranger's website.

Real companies send from their own domain. Anything with extra hyphenated words bolted on — secure, alerts, verify, support — is a different website that anyone can register for a few dollars.

What arrives

  • Real: meridianbank.com
  • Sent: rneridianbank.com
  • Two letters wearing one letter's coat.
  • Read it slowly and it comes apart.

The tell

Read the part before .com character by character. paypa1.com uses a digit one; chase-alerts-secure.com is not chase.com at all.

What to do

Never reach a bank through a link in a message. Type the address yourself, or open the app you already have.

Pin explaining fake IRS, Social Security and Medicare impersonation scams and how to verify them safely

Government and Medicare impersonation

No agency opens with a threat and a deadline.

The fear is the product. Being contacted by the government is frightening enough that people stop checking, which is precisely what the deadline exists to cause.

What arrives

  • SOCIAL SECURITY - FINAL NOTICE
  • Your number has been suspended for fraud.
  • A warrant will be issued today.
  • Press 1 now to speak to an officer.

The tell

Real agencies write by post first, and never demand instant payment by email or phone. Arrest is never the opening move.

What to do

Close it, then call the agency on the number from your own card or statement — never one printed in the message.

Pin explaining Reply-To hijacking where a reply is quietly routed to a stranger's address

Reply-To hijacking

The message is real. The reply address is not.

This is how invoice and payment redirection fraud usually works: the conversation is authentic, so there is nothing suspicious to notice until the answer has already gone to the wrong person.

What arrives

  • From: bookkeeping@ashgrove-title.com
  • Reply-To: bookkeeping@ashgrove-titIe.com
  • Wiring details for closing have changed.
  • You see the first line. You reply to the second.

The tell

Nothing looks wrong until you reply. Check the address in the To field AFTER you hit reply, before you send.

What to do

For anything about money, start a fresh email to the address in your own contacts rather than replying to the thread.

Pin showing a spoofed email whose visible address is real but whose SPF, DKIM and DMARC checks all fail

Spoofed senders (SPF, DKIM, DMARC)

The address can be genuine and the sender still fake.

This is why 'but it came from their real email address' is not reassurance. The checks exist precisely because the visible address proves nothing on its own.

What arrives

  • From: Meridian Bank <alerts@meridianbank.com>
  • Hidden authentication results:
  • spf=fail dkim=none dmarc=fail
  • The address is real. The sender is not.

The tell

Three hidden checks - SPF, DKIM and DMARC - record whether the domain authorised the message. A forgery fails them while looking perfect.

What to do

Do not judge by the address alone. For anything about money, contact the company through a route you chose yourself.

Pin showing a phishing email sent from a domain registered six days earlier

Brand-new burner domains

Real institutions do not email you from new domains.

Throwaway domains are registered in bulk, used for days, and abandoned before anyone can report them. A genuine institution's domain is decades old.

What arrives

  • From: secure-meridian-alerts.com
  • Urgent: verify your account within 24 hours.
  • Domain registered: 6 days ago
  • The real bank's domain is 27 years old.

The tell

Scam infrastructure is disposable and is burned after each campaign. Age is the one thing a lookalike cannot fake.

What to do

If a message is urgent and the domain is unfamiliar, treat the age as the answer and go to the real site yourself.

Money, prizes and "investments"

The tell is almost always a payment you cannot reverse, requested under a deadline you did not set.

Pin explaining pig-butchering crypto investment scams and the withdrawal fee tell

Investment and crypto (pig-butchering)

The app shows your money growing. The money is gone.

The most financially devastating con in circulation and the one most likely to take an entire retirement. The dashboard exists to make the balance feel real long after the money has left.

What arrives

  • Sorry, wrong number! But you seem nice.
  • ...eleven weeks of daily conversation...
  • My uncle's platform returned 22% again.
  • Withdraw $40,000? Tax deposit required first.

The tell

Small withdrawals work perfectly — that is the hook. The large one triggers a sudden tax or fee you must pay first.

What to do

A platform you reached through a person rather than your own bank is not an investment. Stop before the second deposit.

Pin explaining fake antivirus renewal callback scams where the phone number is the attack

Fake renewal and callback scams

No link to click. That is the design.

Calling reaches a person who talks you into remote access to your computer, and from there into your bank. The absence of a link is exactly what lets these reach an ordinary inbox.

What arrives

  • INVOICE - auto-renewal processed
  • Total Defender Premium: $429.99
  • No link. To cancel call 1-888-555-0193
  • Nothing to click means nothing to scan.

The tell

There is deliberately nothing to click, so nothing for a filter to inspect. The phone number is the attack.

What to do

Do not call. Check your actual card statement for the charge — if there is none, there is nothing to cancel.

Pin explaining recovery scams that target people who have already lost money to fraud

Recovery scams

The people offering your money back already took it once.

Victim lists get resold, which is why the follow-up arrives so fast. That is why we treat any unsolicited recovery offer as an automatic red flag rather than a judgement call.

What arrives

  • We recovered funds for a client like you.
  • Your case reference is already open.
  • Court filing fee of $650 to begin.
  • They knew the exact amount you lost.

The tell

Any upfront fee is the scam. Nobody legitimate charges in advance to recover stolen money.

What to do

Report free at ic3.gov and reportfraud.ftc.gov. Tell family you were approached — a second attempt is the pattern, not bad luck.

Pin explaining refund and overpayment scams and why an uncleared deposit is the tell

Refund and overpayment tricks

The refund is fake. The money you send back is real.

Banks show pending deposits as available before they clear. The scam lives entirely inside that gap, and the loss lands on the victim when the original payment reverses.

What arrives

  • We refunded $500. Our error - we sent $5,000.
  • Screenshot of your balance attached.
  • Please return $4,500 in gift cards.
  • The deposit was never real.

The tell

The deposit has not cleared, whatever the balance says. A cheque can bounce weeks after you have spent it.

What to do

Never return funds from a deposit you did not expect. Call your bank on the number on your card and ask if it has truly cleared.

Pin showing a prize notification demanding a processing fee before releasing winnings

Prize, lottery and inheritance

Winnings are never released by paying a fee.

This one persists because it costs the criminal nothing to send, and the fee is usually small enough to feel like a gamble worth taking.

What arrives

  • CONGRATULATIONS - claim reference 44-A1
  • You have been awarded $2,400,000.
  • Processing tax of $890 due before release
  • Reply with your bank details to proceed.

The tell

Real prizes deduct tax from the winnings. Being asked to send money to receive money is the whole scam, every time.

What to do

Ask one question: did I enter this? You cannot win a draw you never entered, and no fee will ever produce the prize.

Pin showing a fake disaster relief appeal asking for gift cards days after the event

Charity and disaster pressure

Generosity is the target, and the timing is deliberate.

Fake appeals appear within hours of a disaster because urgency and sympathy suppress the checking people would normally do.

What arrives

  • Hill Country Flood Relief Fund
  • Families are waiting tonight. Please act now.
  • Gift cards or Cash App only
  • Fund registered 2 days after the flood.

The tell

Pressure to give immediately, and a payment method with no trail. A real charity is glad to receive it next week.

What to do

Give through the charity's own website, typed yourself. Check the name at give.org or charitynavigator.org first.

Scams that use your family against you

These work by making you act before you check. Every one of them is defeated by the same move: hang up, and call back on a number you already had.

Pin explaining the grandchild emergency scam with AI voice cloning and the family code word defence

Grandchild and family emergency

It sounds like them because it is their voice.

Thirty seconds of audio from a social media video is enough to clone a voice convincingly. The script itself has not changed in decades, and the request for secrecy still gives it away.

What arrives

  • Grandma? I'm in trouble, I had an accident.
  • My nose is broken so I sound different.
  • Please don't tell Mom and Dad.
  • A lawyer will call you about the bail.

The tell

Secrecy is the giveaway. A real emergency wants MORE family involved, not fewer. “Don't tell Mom” is the script, not the situation.

What to do

Agree a family code word today. Any call asking for money has to produce it. A cloned voice cannot know it.

Pin explaining romance scam warning signs and the grooming arc that precedes the money request

Romance and companionship grooming

Weeks of warmth, then a crisis only money can solve.

This one is cruel because the relationship is real to the person in it, which is also why families find it so hard to interrupt. Watch the shape of the story rather than arguing about the person.

What arrives

  • Six weeks of good-morning messages.
  • Never able to video call. Always a reason.
  • My contract payment is frozen overseas.
  • Could you cover the customs fee, just once?

The tell

They can never video call and never meet. Then comes an emergency. The crisis always arrives after the attachment does.

What to do

Reverse-image search their photos. Never send money to someone you have not met in person, however long you have talked.

Pin explaining bereavement and estate scams that target recently widowed people with fake debts

Bereavement and estate predators

A bill arrives for a debt that died with them.

Grief plus paperwork is the opening these people wait for, and the timing is not coincidence — obituaries are where the targeting list comes from.

What arrives

  • Re: the estate of the late Robert Hayes
  • An outstanding balance of $2,340 remains.
  • Family is expected to settle this.
  • Obituary details quoted back to you.

The tell

Obituaries are public, so the details being right proves nothing. Knowing the name and date is not evidence the debt is real.

What to do

Send nothing without a written validation notice, and let the executor or estate attorney handle every claim.

Pin showing a sextortion blackmail email quoting a breached password as fake proof

Sextortion and blackmail email

They have a leaked password, not a video.

These are sent in bulk to millions of addresses with no footage behind any of them. Shame is what makes people pay, which is why so few report it.

What arrives

  • I recorded you through your camera.
  • Proof - your password is:
  • Sunflower1998
  • Send $1,900 in Bitcoin within 48 hours.

The tell

That password came from a public breach dump, not from your computer. Quoting it proves a leak, not access.

What to do

Do not pay and do not reply. Change that password anywhere it is still used, and turn on two-step sign-in.

What a link says and where it goes are two different things, and on a phone the second one is hidden by default.

Pin explaining QR code phishing, known as quishing, and why the code hides the destination

QR-code scams (quishing)

A QR code is a link your filter cannot read.

It is a picture, so there is no address for a scanner to test — and a phone carries less protection than a computer, which is precisely why the attack moves you there.

What arrives

  • PARKING VIOLATION - pay within 5 days
  • Scan the code below to settle the fine.
  • The code hides the address entirely.
  • Your filter cannot read a picture.

The tell

There is no visible address to check, and scanning moves you to a phone. The code exists to hide the destination.

What to do

Treat a QR code in an unexpected message exactly as you would a suspicious link: don't scan it. Go to the site yourself.

Pin explaining why a password-protected ZIP attachment with the password in the email is malware

Password-protected archives

A locked file with the key beside it is not security.

One of the very few email patterns with essentially no innocent explanation — the combination itself is the evidence, whatever the covering story says.

What arrives

  • Attached: Invoice_4471.zip (encrypted)
  • Password: invoice2026
  • The lock stops the scanner, not you.
  • You are the one who opens it.

The tell

Encryption stops the scanner, not the recipient. The password is there to defeat the antivirus, not to protect you.

What to do

Do not open it. Nobody legitimate sends a locked archive and its password in the same message.

Pin explaining hidden email forwarding rules left behind after a mailbox takeover, and where to find them

Mailbox takeover

Changing the password does not remove their rule.

The quietest sign an account has already been broken into, and almost nobody looks. If you check one thing after a scare, check this one.

What arrives

  • Rule added to your mailbox:
  • IF from contains 'bank'
  • THEN forward to r.k.mail99@proton.me
  • AND mark as read, AND delete.

The tell

It survives the password reset and leaves no other trace. Locking them out does not delete what they set up.

What to do

Gmail: Settings → See all settings → Filters and Blocked Addresses, then Forwarding and POP/IMAP. Delete anything you don't recognise.

Pin showing how an adversary-in-the-middle page relays a password and two-factor code to steal the session

MFA bypass (adversary-in-the-middle)

They did not beat your code. They let you enter it.

Text codes, authenticator apps and push approvals are all relayable, because none of them is tied to the site you are actually on. A passkey is.

What arrives

  • You typed your password. It worked.
  • The real code arrived. You entered it.
  • The page passed both straight through.
  • You are signed in. So are they.

The tell

The login genuinely succeeds, so nothing looks wrong. What is stolen is the session, not the password.

What to do

Use a passkey or security key for email and banking. They refuse to sign for a lookalike site, so there is nothing to relay.

Fake jobs, gig apps and marketplace deals

The fastest-growing category, and the one that targets working adults rather than retirees. In a survey of 585 real "is this a scam?" posts, fake job offers and marketplace deals were the two most common things people asked strangers to check.

Pin showing a fake recruiter message that moves to Telegram and asks for an equipment fee

Fake recruiters and job offers

A real job never costs you money to start.

The most common scam people ask strangers about online, and it targets working adults rather than retirees. The move to an encrypted chat app is the moment it stops being a hiring process.

What arrives

  • Talent Team - Remote Data Associate
  • $38/hr, no experience needed. Start Monday.
  • Add me on Telegram to continue: @tt_hiring_9
  • Equipment fee $215, reimbursed first paycheck.

The tell

The conversation moves off the platform fast, to WhatsApp or Telegram. Then equipment, training or a fee comes up before you are paid.

What to do

Look up the company yourself and apply through its own careers page. Never pay for a job, and never accept a cheque to buy your own equipment.

Pin showing a task app screen demanding a deposit before a balance can be withdrawn

Task and commission app scams

You are not earning. You are funding your own trap.

The early small payouts are real, which is what makes people trust the larger ask. Losses here are often a person's entire savings, paid in willingly over several days.

What arrives

  • Account balance: $1,480.00
  • Withdrawal request: DECLINED
  • Deposit $500 to unlock combo task 42
  • Complete to release your full balance.

The tell

Withdrawals stop and a deposit is demanded to unlock them. Every deposit reveals another one.

What to do

Stop at the first request for money. No legitimate work asks the worker to pay in before being paid out.

Pin showing a marketplace buyer insisting on an irreversible payment app and sending an overpayment for a courier

Marketplace and buyer-seller scams

Some payment apps have no buyer protection. That is why they ask.

Bank-transfer apps are built to work like handing over cash, which means there is nobody to appeal to afterwards. That is precisely the feature being used.

What arrives

  • Still available? I'll take it, full price.
  • My assistant will send the payment now.
  • Zelle only - my card is locked for travel
  • Sending $50 extra for the courier, refund him.

The tell

They push a method with no reversal, then send a fake payment screenshot. The urgency is about the payment rail, not the item.

What to do

Meet in person, pay in person, and check the money is actually in your account - not just that a screenshot says so.

Pin showing an unordered parcel addressed to a misspelled name as evidence of a data leak

Brushing and unordered parcels

The free parcel means your details are already out there.

Sellers post cheap goods to real addresses so they can write fake verified reviews under your name. Harmless in itself, but it proves your details are circulating.

What arrives

  • Delivered: 1 parcel, no sender details
  • Contents: a phone case you did not order
  • Addressed to: Margret Ellison
  • Your name is spelled Margaret.

The tell

The misspelling is the clue - it identifies which leaked list you are on. Somebody has your name and address and is using them.

What to do

Keep the item, you are not obliged to pay. Then check your accounts for orders you did not place, and freeze your credit.

Texts, calls and pop-ups

Not everything arrives by email any more. These are the three off-email routes that reach the most people.

Pin showing a fake delivery fee text and why the small amount is deliberate

Fake delivery texts (smishing)

No real carrier charges you by text message.

The most-reported text scam in the country, and the fee is set low on purpose - nobody stops to ask a family member about $1.95.

What arrives

  • Your parcel is on hold at the depot.
  • Unpaid postage of $1.95 is due.
  • Pay to reschedule: parcel-redeliver-fee.info
  • Parcel returns to sender in 24 hours.

The tell

The tiny amount is deliberate: it is small enough to pay without thinking. The card number is the target, not the fee.

What to do

Never tap the link. Track any parcel in the carrier's own app, or by typing their address yourself.

Pin showing a fake virus warning pop-up whose phone number gives the scam away

Tech-support pop-ups

A real virus warning never gives you a number to call.

Calling leads to remote access, then to your bank while you watch. If someone is already connected, turn the machine off at the power button.

What arrives

  • ** SECURITY ALERT - DO NOT RESTART **
  • 5 threats detected. Your data is at risk.
  • Call support now: 1-888-555-0142
  • Closing this window may damage your files.

The tell

Antivirus software fixes things quietly. A phone number in a virus warning is the entire scam.

What to do

Do not call. Close the browser completely, restarting the computer if it will not close. Never let a caller connect to your screen.

Pin showing a caller asking a person to confirm their Medicare and Social Security numbers

Requests for sensitive data

The organisation that issued it already has it.

A Medicare number is worth more to a criminal than a card number, because it cannot easily be reissued and unlocks fraudulent billing for years.

What arrives

  • Benefits Review - courtesy call
  • To send your new plastic card, I just need to
  • confirm the number printed on the old one
  • and the last four of your Social.

The tell

Confirming is not the same as providing. Nobody legitimate needs you to read out a number they issued you.

What to do

Hang up and call back on the number from your card or statement. A real organisation will never mind you verifying them.

For small businesses and nonprofits

The same techniques, aimed at whoever pays the invoices. These are the most expensive email attacks there are, and none of them requires the attacker to break anything.

Pin showing a vendor email announcing changed bank details, the classic business email compromise

Vendor bank-detail change

One changed account number, and the payment is gone.

The single most expensive email attack for small businesses. The attacker usually reads the mailbox for weeks first, so the request arrives at exactly the moment a payment is genuinely due.

What arrives

  • From: accounts@ashgrove-supply.com
  • Please note our banking has changed.
  • Use the new details on this invoice.
  • Same logo. Same signature. New account.

The tell

The request arrives inside a real-looking thread, often after a mailbox was quietly read for weeks. Nothing about the message is urgent, which is why it works.

What to do

Call the vendor on the number you already had - never one in the email - and confirm any change of bank details before the first payment.

Pin showing a fake executive email requesting gift cards urgently and in secret

Executive impersonation

No executive buys gift cards by email.

It targets whoever is newest and most eager to help. The fix is cultural rather than technical: a stated rule that verifying a request from the boss is always the correct thing to do.

What arrives

  • From: Dana Whitfield, CEO
  • Are you at your desk? I'm in a meeting.
  • Need 8 gift cards for client thank-yous.
  • Send me the codes, I'll reimburse Friday.

The tell

Urgency, secrecy, and a task that cannot be verified in person. The display name is right; the address is a free mail account.

What to do

Verify by a second channel - walk over, or call the number in your directory. Make it policy that no one is ever in trouble for checking.

Pin showing a payroll diversion email requesting a direct deposit change before payday

Payroll diversion

Nobody notices until payday, and then it is gone.

Losses land on the employee, who simply does not get paid - which makes this the version of BEC most likely to damage trust inside a small team.

What arrives

  • Subject: Direct deposit update
  • I've switched banks - new details attached.
  • Please apply before this cycle closes.
  • Sent from a lookalike of a staff address.

The tell

A routine HR request, timed just before a payroll run. There is no alarm to trigger, because nothing looks like an attack.

What to do

Require every bank-detail change to be confirmed by phone or in person, and notify the employee at their old contact details when one is made.

Pin showing a fake Microsoft 365 sign-in page identifiable only by its web address

Microsoft 365 credential phishing

The page is perfect. The address bar is not.

One stolen mailbox becomes every other attack on this board - the vendor change, the payroll request and the fake invoice all get sent from a real internal account.

What arrives

  • Subject: Action required - password expires today
  • A sign-in page that looks exactly right.
  • login.microsoftonIine-verify.com
  • A capital I wearing a lowercase l's coat.

The tell

Everything is copied except the address, and the address is the only part not under the attacker's design control. Check the bar, not the page.

What to do

Never sign in from a link in an email. Open a new tab and go to the service yourself, and move the organisation to passkeys where you can.

Pin showing a fake renewal invoice priced low enough to be approved without question

Fake and duplicate invoices

It is priced to be approved, not questioned.

These are sent in bulk on the assumption that a fraction of businesses pay small invoices without checking. The pricing is the attack.

What arrives

  • INVOICE 20418 - annual listing renewal
  • Amount due: $487.00
  • Small enough to approve without asking.
  • You never signed up for a listing.

The tell

The amount sits just under whatever your business waves through. Nobody escalates a four-hundred-dollar invoice.

What to do

Match every invoice to a purchase order or a named person who ordered it. No name, no payment - regardless of how small the figure is.

Pin showing a ransomware attachment asking the reader to enable editing to bypass protection

Ransomware delivery

The warning bar you clicked past was the defence.

Any message whose instructions are about defeating a security prompt is telling you what the security prompt is for.

What arrives

  • Attached: Remittance_Advice.docm
  • "Document created in an earlier version."
  • Click Enable Editing to view content.
  • That bar is the last thing standing.

The tell

Office blocks the dangerous part by default and asks first. The message's only job is to talk you past the question.

What to do

Never enable content on a document you did not expect. Verify with the sender first, and keep offline backups you have actually restored from once.

If one of these already happened

Speed matters more than anything else after a scam, and most of what needs doing in the first hour is free.

What to do if you clicked →