Family Sentinel
What we detect

Everything we watch for
in a single inbox.

Corporate email is guarded by layers of security tooling. Family Sentinel brings that same depth to a personal or organization inbox — every message checked against dozens of threat signals in real time. Here's a plain-English tour of what we catch and flag, and alert you about before the money moves. Read-only by design.

This page is the capability list — the signals our engine looks for. If you would rather approach it from the other direction, the Scam Library catalogs the forty-nine scams themselves, and says for each one whether we detect it, partly detect it, or not yet.

Layer 1

Instant forensics — every message, in a fraction of a second.

Deterministic checks that need no guesswork: is this sender who they claim to be, and is anything in the message built to harm you?

Spoofed senders (SPF · DKIM · DMARC)

We verify the message truly came from the domain it claims. Fakes pretending to be your bank, Medicare, or a family member are caught here.

Display-name impersonation

"Chase Bank" <kevin83@gmail.com> — the friendly name says one thing, the real address says another. The #1 senior-targeting trick.

Reply-To hijacking

A message that looks normal but quietly routes your reply to a stranger's address.

Lookalike & homoglyph domains

chase-alerts-secure.com, or letters swapped for near-identical characters (paypa1.com). We catch the visual trick.

Brand-new burner domains

A "bank security alert" from a web address registered days ago — the signature of throwaway scam infrastructure.

First-time senders

Cold approaches from someone who has never written before are weighed against who normally emails this inbox.

Dangerous links

Shorteners, redirect chains, links whose visible text hides a different destination, and raw-IP links — the plumbing of phishing.

Known-bad links & senders

Every link and sender checked live against global threat-intelligence feeds of confirmed phishing and malware.

Malware & ransomware attachments

Executables, scripts, macro documents, disk images, and HTML "pages" — plus a live antivirus scan of every attachment.

Password-protected archives

A locked ZIP with the password in the email — a trick to smuggle malware past scanners. We flag the pattern.

QR-code scams (quishing)

We don't just notice a QR code — we read it, follow where it points, and check that destination like any other link. QR scams jumped hundreds of percent this year.

Fake-renewal "call this number" scams

The fake Norton/Geek Squad invoice with a phone number and no link (a "callback" scam). We know the shape — and we recognize phone numbers reused across known scams.

Layer 2

Reading for the con itself — like a fraud examiner would.

Some scams carry no bad link and no infected file — just words aimed at a trusting person. Our analysis reads a message for intent, weighing it against the con families we see every day.

Government & Medicare impersonation

Fake IRS, Social Security, and Medicare notices threatening arrest or lost benefits.

Tech-support & fake renewals

Virus warnings and auto-renewal invoices that lead to a phone call, remote access, and a drained account.

Grandkid & family emergencies

"I'm in trouble, don't tell Mom" — bail, hospital, accident. Now often paired with an AI-cloned voice call.

Romance & companionship grooming

Weeks of warmth that turn into a crisis only money can solve. Detectable because we watch the arc over time.

Investment & crypto ("pig-butchering")

Guaranteed returns, a can't-miss platform, urgency to move retirement savings. The most financially devastating con.

Prize, lottery & inheritance

"You've won — just pay the fees first."

Payment-method red flags

Gift cards, wire transfers, crypto, cash couriers, Zelle to strangers — the near-certain fingerprints of a scam.

Requests for sensitive data

Anyone fishing for a Social Security number, Medicare number, bank login, or ID photos.

Recovery scams

"We can get your money back — for a fee." The vultures that target people who've already been scammed once.

Refund & overpayment tricks

"We refunded too much — send back the difference."

Bereavement & estate predators

Fake debts of the deceased and phony estate "fees" aimed at the newly widowed.

Charity & disaster pressure

Fake charities that surge after a storm or around the holidays.

Layer 3 & account security

Patterns over time — and the inbox as a security perimeter.

The most dangerous signals aren't in any single email. They emerge across days, or hide in account settings nobody checks.

Hidden mailbox takeover

We watch for the fingerprints of a hijacked account: secret auto-forwarding rules, and filters quietly deleting bank and security alerts before they're seen.

Password-reset bursts

A flurry of reset and verification-code emails in a short window — someone actively trying to break in.

New financial-institution mail

A "welcome" or statement from a bank they've never used — a sign an account may have been opened in their name.

Being placed on a "sucker list"

A sudden surge of scam attempts — often what happens right after a first loss. Protection tightens automatically.

Engagement, not just arrival

The danger moment is when someone starts to reply to a scammer. That's when a scam turns into a loss — and when we reach the family fastest.

Breach & password-leak alerts

We watch for the protected addresses turning up in known data breaches, so a leaked password can be changed before criminals use it.

Some behavioral signals are rolled out carefully and tuned per inbox so alerts stay rare and meaningful — never a flood.

And a human, when it counts

A real Security Architect verifies every serious threat.

Automated analysis does the reading; a working Security Architect personally verifies a message before your family is ever alarmed. Every alert we send arrives in plain English, tells you exactly what to do, and carries your family's own verification phrase — so a scammer who doesn't know your phrase can't fake a warning that looks like it came from us.

  • Serious threats verified by a human, not just software.
  • Alerts to the family, not just the person targeted.
  • Every alert carries your verification phrase.
  • Plain-English "what to do now" with every alert.
  • Read-only by design — we detect and warn, never touch the mailbox or the money.

Not sure about a message? Forward it — we'll tell you.

Ask Sentinel: get a real Security Architect's verdict on anything that looks off — a suspicious email, text message, or WhatsApp. Forward it (or send a screenshot) and we'll tell you plainly whether it's safe or a scam, and what to do. It's part of every plan, and a person answers.

Ask Sentinel — forward a suspicious message

Or text a screenshot / call: (940) 281-6672 · security@familysentinel.org

See plans & start your free month →