Family Sentinel
How protection actually works · Free explainer

Her spam filter did its job.
The scam still went through.

This is the part nobody explains: the email protection already on your parent's account is genuinely good at what it was built for, and what it was built for is bulk junk. The scam that empties a retirement account is not bulk junk. It is one message, written once, for one person — and it is designed to pass every test a spam filter knows how to run. Below is the same scam going through three generations of protection, one stage at a time.

3generations compared
5kinds of protection
Honestincluding what we miss
i.

One message. Three generations of protection.

The message below is a real pattern, not a hypothetical: a grandmother receives an email that appears to come from her granddaughter's new address, referencing a car accident and asking for help quietly. It was written by a language model, sent once, from a freshly made account. Here is what each generation of protection sees.

Inbox — 7:12 AM
From Emma <emma.whitfield.help@gmail.com>
To nana@example.com
Subject Nana please read this before you call mom
Nana, it's Emma. I'm okay but I was in an accident last night and my phone is broken so I'm using a friend's email. I'm so sorry to ask. The other driver's insurance needs a deposit today before they'll release the car and I can't reach Mom and I really don't want her to know yet — she'll be so upset with me. Is there any way you could help? I can pay you back the second my paycheck comes. I'll explain everything, I promise. I love you. Emma
Nothing here is technically wrong. The grammar is perfect. There is no link, no attachment, and no misspelling. The sending account is a real Gmail account, so it passes every authentication check there is.
i.

A spam filter

"Have I seen this before?"

  • Sender authentication (SPF, DKIM) — passes
  • No links to check
  • No attachment to scan
  • Not on any blocklist
  • Never seen this exact message before
Delivered

Spam filters compare a message against the enormous volume of junk they have already seen. This message was written once, for one person, and sent from a real account. There is nothing to match against — so it arrives, in the normal inbox, looking entirely ordinary.

ii.

A blocklist or link scanner

"Is anything on it known to be bad?"

  • Sender domain reputation — clean (it is Gmail)
  • Zero URLs to look up
  • Zero file attachments
  • No known-bad indicators of any kind
  • Nothing to look up at all
Delivered

This layer is genuinely valuable — against malware and known phishing sites it is fast and accurate. But it works by checking things against lists of known-bad things, and this message contains no things. The entire attack is a sentence.

iii.

Family Sentinel

"What is this message trying to make her do?"

  • Family-emergency plea — a named scam pattern
  • Asks her to keep it from another family member
  • Urgency and secrecy together — the two ingredients of nearly every con
  • First-ever contact from this address
  • Claims to be a known person from an unknown account
Caught — family alerted

We are not asking whether the message is known to be bad. We are asking what it wants. A request for money, wrapped in an emergency, addressed to a grandparent, with an instruction not to tell the person who would have checked — that is not a message shape that has an innocent explanation. Her son gets a phone call before she gets to the bank.

The point of this page is not that spam filters are bad. It is that they answer a different question. "Have I seen this before?" cannot catch something written for the first time, for one person, this morning.

ii.

Five kinds of email protection, and what each one misses

Nearly every email security product on earth is some blend of these five. Most of the confusion in this market comes from vendors listing all five and implying the combination is complete. It is not — each has a failure mode that the others do not fix, and knowing which one you are relying on tells you exactly what is getting through.

KindWhat it isGenuinely good atMisses
Spam & junk filtering Compares mail against the huge volume of junk already seen. Built into Gmail and Outlook. Bulk advertising, mass fraud campaigns, obvious junk — at enormous scale, for free. Anything written once for one person. AI removed the bad grammar that used to be the giveaway, so the old tells are gone.
Blocklists & reputation Databases of known-bad senders, domains, links and files. Known malware and known phishing sites, instantly and cheaply. Anything new — and anything sent from genuinely trusted infrastructure, because a real Gmail account or a real SharePoint link has a clean reputation.
Link & attachment scanning Opens links and files in a safe environment to see what they do. Malicious attachments and dangerous websites — the technical half of the problem. Scams with no link and no attachment, which is most elder fraud. A phone number cannot be detonated. Neither can a sentence.
An AI reading the words A language model judges the meaning and intent of the message. The con itself — pressure, manipulation, a request that does not match its stated purpose. Whether the story is true. It cannot know whether Emma really has a new email address, or whether this bank is the one you actually use.
History & a person who checks Knows this household's normal patterns over time, and a human verifies serious flags before anyone is alarmed. First-contact impersonation, slow-building grooming, and the difference between a real alarm and a false one. Needs time to learn what normal looks like, and cannot see anything that never touches the inbox — a phone call, a knock at the door.

What your parent has today is almost certainly the first three. They are the free, built-in layers, and they are the reason the inbox is not completely unusable. Family Sentinel adds the last two — and keeps the first three, because we do not replace anything or touch how mail is delivered.

iii.

What we miss

Every comparison table you have ever seen from a security company has the company winning every row. That is not a comparison, it is an advertisement — so here, plainly, are the things we do not catch. If any of them is the thing you are worried about, we would rather you knew now.

See exactly what we detect, scam by scam →

iv.

Four questions worth asking anyone who wants to protect your family's email

Including us. If a company cannot answer these plainly, that is your answer.

Can you send, delete, or change email in the account?

Ours is no, and not as a promise — the read-only permission we request does not contain the ability to write, and Google and Microsoft enforce that at the account level. Ask for the exact permission scopes in writing. Ours are published here, in full.

What happens when you are not sure about a message?

This is the question that separates real monitoring from a filter. Ours goes to a human — a working Security Architect looks at it before your family is alarmed, which is why our alerts are rare enough to be worth reading. A product with no person in the loop must either wake you constantly or stay quiet when it should not.

Who gets told, and how fast?

Ours alerts the family, not only the person who received the message — so nobody has to admit to being fooled in order to be protected. Minutes, not a monthly report. Ask anyone else how long their gap is, and who is on the other end of it.

What do you miss?

If the answer is "nothing", stop there. Ours is the section directly above this one, written out in plain language on a public page.

The scams that matter are the ones nobody has seen before.

That is the whole problem, and it is why we watch for intent instead of matching against a list. First month free, cancel any time, and we will tell you honestly if we are not the right fit.

Start your free month → Test yourself first →