Family Sentinel
A buyer's rubric · for families comparing options

Protected from what?

Every product sold to families says it blocks scams. Almost none of them will tell you which scams they miss. That gap is where the money actually leaves — and it is the one thing no marketing page wants to discuss. Here are six questions that separate real monitoring from a spam filter with a logo on it. Ask them of us too. Our own answers are at the bottom, including the ones where the answer is no.

The word that stopped meaning anything

Ask a company what their product does and you will hear the same sentence: your loved one is protected. It is on every box, every landing page, every bundled add-on your parent's internet provider slipped into the bill.

The trouble is that protected has been stretched to cover four completely different things: a spam filter that sorts junk mail, a virus scanner that checks attachments for malware, a credit monitor that tells you after your identity was already used, and actual review of the messages arriving in the inbox. Those are not variations of one product. They fail in different places, and three of the four are blind to the way seniors are most often defrauded today.

Because the word covers everything, it distinguishes nothing — so families end up choosing on price and logo, and the honest products lose to the loud ones. The fix is not a better adjective. It is a set of questions specific enough that a vague answer becomes obvious.

These six are the ones we would ask. We wrote them to be answerable: a company either does the thing or it does not, and you will be able to tell from the reply.

The six questions

Question one

Does it read what's inside the attachment — or only check it for a virus?

The fastest-growing scams against older adults arrive as a perfectly clean PDF. A fake invoice, a fake Medicare statement, a fake renewal notice for antivirus software. No link to click. No malware. Just a phone number, and a total that looks alarming.

A virus scanner opens that file, finds no executable code, and marks it clean — correctly. It did its job. But nothing has read the words on the page, so nothing has noticed that the number in the letterhead has appeared in eleven other scam reports, or that a "Geek Squad renewal" is addressed to somebody who has never owned a Geek Squad subscription. The scam succeeds because the file really is harmless. The harm happens on the phone call afterwards.

A good answer sounds likeWe extract the text from attachments and check it the same way we check the message body — phone numbers, amounts, the brand being claimed.
A weak answer sounds likeAll attachments are scanned for viruses and malware. (True, and beside the point.)
Question two

Can it catch a scam sent from a real account that passes every authentication check?

This is the question that separates the categories, and almost nobody asks it.

SPF, DKIM and DMARC are the checks that prove a message genuinely came from the domain it claims. They are essential and we run all three. But they answer "is this sender who they say they are?" — not "is this message safe?" When a criminal takes over a real account at a real title company and replies inside a real email thread with new wire instructions, every authentication check passes perfectly, because the message is genuinely from that company.

That is the single most expensive fraud pattern in America right now, and any product whose logic reduces to "authentication passed, therefore fine" will forward it to your parent with no comment at all.

A good answer sounds likeAuthentication is one signal among many. We weigh the content, the request, the payment method and the history of that sender with this inbox.
A weak answer sounds likeWe verify every sender with SPF, DKIM and DMARC. (Necessary. Nowhere near sufficient.)
Question three

When it isn't sure, what happens — and is there a person?

Every system meets messages it cannot confidently call. What happens next is the fork in the road, and it decides whether the product is useful a year from now.

An automated system with nobody behind it has only two settings, and both fail. Alarm on everything uncertain, and the family learns within a fortnight to swipe the notifications away — so the real one, when it comes, is swiped away too. Stay quiet on everything uncertain, and the product is calm and useless. There is no threshold that fixes this, because the problem is not the threshold; it is that no threshold can separate "unusual" from "dangerous" without judgement.

So ask what sits in the uncertain middle. If the answer is a confidence percentage, the answer is nobody.

A good answer sounds likeUncertain messages go to a person who looks at them before the family is alarmed — which is why our alerts are rare enough to still be worth reading.
A weak answer sounds likeOur model is 99.8% accurate. (That is a claim about the easy cases, not the hard ones.)
Question four

When it flags something, does it say why — in words the person can act on?

A risk score of 78 is not information. Neither is a message moved silently to a folder nobody opens. The people being targeted are not going to audit a quarantine queue, and the adult child getting the alert is usually at work, reading it on a phone, with thirty seconds to decide whether to call.

An explanation has to survive that. "This says it is from Medicare, but it was sent from a web address registered nine days ago, and it asks them to confirm their Medicare number" is something a person can act on immediately. A number between 0 and 100 is something a person learns to ignore, which is worse than no alert at all — because a fatigued family stops reading the alerts before the real one arrives.

A good answer sounds likeEvery alert states the specific signals in plain language, and what to do next.
A weak answer sounds likeOur AI assigns a risk score and quarantines high-risk mail automatically.
Question five

Who gets told, how fast — and how would you know if it silently stopped working?

Three things hide in this question, and the third is the one nobody asks.

Who. If the only person alerted is the one who received the message, the product depends on an older adult recognising they were nearly fooled and then volunteering it. Shame is the reason elder fraud goes unreported; a design that requires someone to admit being deceived in order to get help is working against the grain of the actual problem.

How fast. A monthly report is a historical document. The window between a convincing message and a wire transfer is measured in hours.

And whether it is even running. Every one of these products connects to a mailbox with an authorization that can lapse — a password change is enough to end it. So ask: if the connection broke tonight, who finds out, and when? An inbox nobody is reading looks exactly like an inbox with no bad mail in it. Both are quiet. Only one is safe, and the dashboard shows green either way.

A good answer sounds likeThe family is alerted, not only the recipient, within minutes — and if a connection stops returning mail, that raises an alarm to a human.
A weak answer sounds likeYou'll receive a monthly security summary. (Also: silence on the third part.)
Question six

Will they tell you, in writing, what it cannot catch?

This is the one we would ask first, because it is the hardest to fake and the most revealing.

No product catches everything. Nothing sees the phone call that never touches email. Nothing sees the text message on a phone, the Facebook Marketplace conversation, or the person at the front door with a clipboard. A company that will not name a single limitation is not more capable than one that will — it is just less willing to say so, and you are going to find out which limitations were real at the worst possible moment.

A company willing to publish where it falls short is a company that has actually measured. It also tells you something about what happens after you buy: whether you will be told the truth when something is missed.

A good answer sounds likeHere is the published list, scam by scam, of what we detect, what we partly detect, and what we do not.
A weak answer sounds likeComplete, comprehensive protection against all known and emerging threats.

Our own answers

It would be a poor rubric if we wrote it to flatter ourselves and then declined to sit the exam. So, in order, and including the parts that are not favourable.

One — inside attachments

Yes. We extract and read the text inside PDF attachments and check it as we check the body — the phone number, the amount, the brand being claimed, the language of the request. We added this because the fake-invoice pattern is now one of the most common things we see, and a malware scan is blind to it by design.

Two — real accounts that pass authentication

Yes, and we learned it the hard way. Early on our own logic leaned too heavily on authentication headers, and we had to rebuild it after finding it could reach the wrong conclusion about a genuinely-sent message. Authentication is now one signal among many rather than a verdict. We weigh what the message asks for, how it wants to be paid, and whether this sender has ever written to this inbox before.

Three — when we are not sure

A person looks at it. Messages the engine cannot confidently call go to a working Security Architect before anyone in your family is alarmed. That is the reason our alerts stay rare enough to be worth opening, and it is the most expensive design decision we have made.

Four — saying why

Yes. Alerts name the specific signals in plain language and say what to do next. There is a score underneath, but we do not send you the score and call it an explanation.

Five — who is told, how fast, and whether it is running

Yes. We connect to the Gmail or Microsoft account they already have. Nothing about how their mail arrives changes, and we cannot send, delete or reply — that is enforced by the permissions themselves, not by our policy.

Since this page is about precision, here is the precise version. On Google we hold exactly two permissions: one to read mail, and one to read the account's settings — the forwarding rules and filters, because that is where someone who has taken over an inbox leaves fingerprints, silently forwarding a copy of everything or auto-archiving the bank's warnings so nobody sees them. Google does not publish a read-only version of that second permission, so we hold one that could change those settings, and we only ever read them. On Microsoft, both equivalents are genuinely read-only. We would rather write that paragraph than the word "read-only" on its own, because the word on its own is not quite the truth.

On the follow-up question: we monitor whether each connection is actually still returning mail, and a connection that stops working raises an alert to a human. We built that after discovering the harder way that a silently-expired authorization looks identical to a quiet week.

Six — what we cannot catch

Our Scam Library lists forty-nine scams and says, for each one, whether we detect it, partly detect it, or do not detect it yet. The "not yet" entries are published in the same place as the rest, not buried.

The honest boundary is this: we watch email. We do not see phone calls, text messages, social media, dating apps or the person at the door — and a great deal of elder fraud begins in exactly those places. Where email is one step in a longer con we often see that step and can warn you early. Where email is never involved, we will not know. Anyone telling you otherwise is selling you the word, not the thing.

If you only ask one

Ask the sixth. Ask any company what their product misses, and read the reply carefully. A straight answer tells you they have measured their own coverage and are willing to be held to it. A reply that restates the marketing tells you they either have not measured, or would rather you did not know.

That is the whole test, and it costs you one email.

Ask us the six questions.

Reply to any of them and a Security Architect answers personally — not a form response. If the honest answer is that we are not the right fit for your situation, we would rather tell you that than sell you a month.

Start your free month →

Or call directly — (940) 281-6672

hello@familysentinel.org · See how we compare →