Email Security for Families: The Guide Nobody Gives You
Table of Contents

Email Security for Families: The Guide Nobody Gives You

How phishing emails target families through school impersonation and package scams, how to set up safe email for kids, and how to verify suspicious messages.

The email arrives at 7 p.m., subject line: “Action Required: Your Child’s School Portal Password.” It looks exactly like every other email from the district — same logo, same signature, even the same footer with the principal’s name. Your kid sees it, clicks the link on their Chromebook, and enters their login credentials on what turns out to be a fake page designed to harvest school account logins. This scenario isn’t hypothetical — it’s one of the most common attack patterns CISA documented in its 2023 K-12 cybersecurity report [1]. Families get email security guidance for work, but almost none for home, where kids are learning email habits that will follow them for decades.

Key Takeaways

  • The Anti-Phishing Working Group (APWG) recorded 4.95 million phishing attacks in 2023 — the highest annual total ever recorded [2].
  • School impersonation is a growing category — attackers spoof district email domains to steal student and parent credentials for school portal access.
  • DMARC, DKIM, and SPF are email authentication standards that, when implemented by a school district or email provider, make spoofing significantly harder — but many districts still haven’t implemented them.
  • Kids need a different email setup than adults — Gmail with Family Link, Apple’s iCloud mail under Family Sharing, or ProtonMail for teens each have different trade-offs.
  • The “from” name in an email is not verified — teaching kids this single fact prevents a significant percentage of phishing clicks.

How Phishing Emails Target Families

School Impersonation

Attackers register domains that are one letter off from real school district domains — pittsburghusd.org becomes pittsburghusd.com or pittsburgusd.org. They clone the district’s email template and send “urgent” messages about password resets, tuition payments, or required forms. Parents and students see the familiar logo and assume the email is legitimate.

The CISA K-12 report found that 56% of successful attacks on school district systems began with a phishing email — often targeting students and parents rather than staff, because students are less trained [1].

IRS and Government Scams

The IRS does not initiate contact via email. However, families receive millions of fraudulent “IRS notice” emails annually, particularly during tax season. These are designed to create urgency and fear — tactics that work on children who may not know the IRS’s contact conventions.

The FTC received reports of over $10 billion lost to fraud in 2023, with imposter scams (government agency impersonation) representing the largest category [3].

Package Delivery Scams

“Your package could not be delivered” emails are among the most clicked phishing lures, precisely because most families are expecting packages at any given time. Kids who shop online — or whose parents do — are conditioned to respond to these messages. The link leads to a credential harvesting page or malware download.

”Reply-All” Risks in Family Email

This is underappreciated: when a parent or student replies to a school email that was sent to all parents in the class, every recipient can see the reply. More relevantly, if a malicious actor is on a school mailing list (or spoofing the sender), a “reply-all” from a student or parent can expose their email address, confirm the account is active, and create a dialogue the attacker can exploit.

Teach kids: never reply-all to school group emails, and never reply to an email asking for personal information — legitimate institutions don’t do this.

Email Authentication: What DMARC, DKIM, and SPF Mean for Families

These three standards work together to prevent email spoofing. You don’t need to implement them — your email provider does — but understanding them helps you know which email providers are protecting your family.

  • SPF (Sender Policy Framework): Allows a domain to specify which servers can send email on its behalf. An email from noreply@pittsburghusd.org should only come from servers the district has authorized.
  • DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to emails. The recipient’s server checks the signature against the sender domain’s published key.
  • DMARC (Domain-based Message Authentication, Reporting & Conformance): Tells receiving servers what to do when SPF/DKIM checks fail — reject, quarantine, or accept the email. A properly configured DMARC policy with reject enforcement means spoofed emails from your district’s domain never reach your inbox.

What this means for your family:

  • Gmail and Apple Mail both enforce DMARC — emails that fail authentication are filtered or rejected.
  • Many school districts have not yet implemented DMARC (particularly small districts). CISA’s 2023 K-12 report found that fewer than 30% of school districts had implemented DMARC with enforcement [1].
  • ProtonMail uses DMARC, DKIM, and SPF on all accounts.

You can check whether any domain has DMARC configured by going to mxtoolbox.com/dmarc and entering the domain.

Setting Up Email for Kids: A Comparison

Email OptionBest AgePrivacyParental ControlDMARC SupportCost
Gmail + Family LinkUnder 13Google data practicesHigh — parent approves contactsYesFree
iCloud Mail + Family SharingUnder 13Apple data practicesModerate via Screen TimeYesRequires Apple device/ID
Gmail without Family Link13+Google data practicesNone built-inYesFree
ProtonMail13+End-to-end encryptedNone built-inYesFree/paid tiers
Outlook / Microsoft 365 for FamiliesAll agesMicrosoft data practicesFamily Safety integrationYesMicrosoft 365 subscription

Family Link lets parents manage a child’s Google account, including:

  • Approving apps and services.
  • Seeing activity reports.
  • Setting content filters.
  • Managing which contacts can email the child.

Limitation: Once a child’s Google account switches to a regular account (at 13 or when the parent grants it), parental controls disappear. Plan for this transition explicitly.

ProtonMail for Teens

ProtonMail is an end-to-end encrypted email service based in Switzerland (under Swiss privacy law). Messages between ProtonMail users are encrypted so that even ProtonMail cannot read them. For a privacy-conscious teenager, ProtonMail is significantly more private than Gmail.

Limitation: End-to-end encryption only applies to ProtonMail-to-ProtonMail messages. Emails sent to Gmail or Yahoo are encrypted in transit but not end-to-end.

How to Verify Suspicious Emails: Teaching the Skill

This is the single most transferable skill you can give your children about email. Walk them through this process with a real email (even a legitimate one) so the habit is built:

Step 1: Check the actual sender address (not just the name)

In any email client, the “From” display name can say anything — “School District IT” or “Amazon” — but the underlying email address cannot be easily faked when DMARC is enforced. Click or hover over the sender name to reveal the actual address.

Red flags:

  • schoolname@gmail.com (a real school uses its own domain)
  • noreply@amazon-security.com (note: amazon.com, not amazon-something.com)
  • Any address with extra characters or number substitutions

Step 2: Don’t click — type directly

If an email says “click here to reset your school portal password,” don’t click. Open a browser and type the school portal address directly. Legitimate services don’t require you to click email links for security actions.

Hover over any link (on desktop) to see the actual URL in the bottom bar. On mobile, long-press the link to preview the URL. If the display text says “schoolportal.org” but the actual URL is “sc00lportal.com,” it’s a phishing link.

Step 4: When in doubt, call

If an email from the school asks your child to do something that seems unusual — submit payment, update a form, verify information — call the school’s main number (from the school website, not from the email) and ask if the email is legitimate.

How to Set Up Gmail for Family Use (Step-by-Step)

  1. On the parent’s phone, open the Family Link app (download from Google Play or App Store).
  2. Tap the + icon → Add child.
  3. Choose Create Google account for your child.
  4. Enter the child’s name and birth date. If under 13, parental controls activate automatically.
  5. Set up Content restrictions → under Email, you can limit who can contact your child.

For All Family Accounts: Enable Gmail’s Safety Features

  1. Open Gmail on a computer → click Settings (gear icon) → See all settings.
  2. Go to Filters and Blocked Addresses → create a filter for common phishing lures (e.g., filter emails with “urgent action required” or “verify your account” that come from unfamiliar senders).
  3. Under Accounts and Import → verify the recovery phone and email are current.
  4. Enable 2-Step Verification: go to myaccount.google.com → Security → 2-Step Verification. Use an authenticator app (Google Authenticator, Authy), not SMS.

What to Watch For Over 3 Months

Month 1: Audit email accounts and set up authentication. Make sure every family member’s email account has two-factor authentication enabled (authenticator app, not SMS). Verify recovery options. If your child doesn’t have email yet and is under 13, set up Gmail with Family Link rather than a regular account.

Month 2: Run a family phishing drill. Forward a suspicious email (or find a safe example at phishtank.com) and walk through the verification steps together. Ask: “How would you check if this email is real?” This is more effective than telling kids what to do — having them work through the steps themselves builds the habit.

Month 3: Check your school district’s email security. Go to mxtoolbox.com/dmarc and check whether your school district’s domain has DMARC configured. If not, consider raising it at a school board meeting or with the district’s IT contact — this is a technically straightforward fix that would protect all families in the district.

Frequently Asked Questions

My child got an email saying they won a prize and need to claim it. What should I do? This is almost certainly a phishing or prize scam — a common category targeting young email users. Do not click any links. Do not reply. Check the sender address (it will not be from a legitimate organization). Delete the email. Use it as a teaching opportunity: legitimate prizes don’t require clicking email links to claim them.

Is it safe for my 10-year-old to have an email account? With the right setup, yes. Gmail with Family Link provides meaningful parental oversight for kids under 13. The key decisions are: who can email your child (restrict to known contacts), what happens when a suspicious email arrives (parent reviews), and whether the child understands not to click unfamiliar links. Start with supervised use and gradually increase independence.

What’s the “from” name trick in phishing emails? Email clients display a friendly name (“Amazon Customer Service”) alongside the actual sender address. Phishers set the display name to something trustworthy but use a fraudulent email address. Teaching your child to always click on or hover over the sender name to see the underlying address is the single most effective anti-phishing habit.

Should my family use a custom domain email for more security? A custom domain (e.g., yourfamilyname@yourdomain.com) allows you to fully control DMARC, DKIM, and SPF settings, which can make spoofing your addresses harder. Services like Fastmail and ProtonMail for Business offer custom domain support. This is a worthwhile step for technically inclined families, but it’s not necessary for most — the most important practices are authentication and verification habits, regardless of email provider.


About the author

Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.

Sources

  1. CISA. (2023). “K-12 Report: Cybersecurity and the Education Sector.” Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/resources-tools/resources/k-12-report

  2. Anti-Phishing Working Group. (2024). “Phishing Activity Trends Report, Full Year 2023.” APWG. https://apwg.org/trendsreports/

  3. Federal Trade Commission. (2024). “Consumer Sentinel Network Data Book 2023.” FTC. https://www.ftc.gov/reports/consumer-sentinel-network-data-book

  4. FBI Internet Crime Complaint Center. (2024). “2023 Internet Crime Report.” FBI IC3. https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf

  5. National Cybersecurity Alliance. (2023). “Email Security Best Practices for Families.” StaySafeOnline. https://staysafeonline.org/resource/phishing/

  6. Proton AG. (2024). “ProtonMail Security Model.” Proton. https://proton.me/blog/proton-mail-encryption-explained

Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.