Origin story · Part 1 of 2
Why I built Is This A Scam?
All my experience was meaningless, because I couldn't help the people who matter to me most — my mother and my father. Is This A Scam? didn't start with how to make money, or with a well-vetted business plan. It started as the problem of keeping the two of them safe from people who play by no rules.
Two parents, two completely different problems
My father is old school: the phone is for talking. What reaches him are texts and voicemails — the unpaid toll, the political rage-bait built to get your goat, the recorded voice with an urgent case number and a callback line. My mother is the emailer. What reaches her are emails — the account that needs re-verifying, the invoice for something she never bought, the notice that a subscription is about to renew at a price that would make anyone click.
And they both get the paper. The warranty about to lapse, the invoice for something nobody ordered, the official-looking letter with a deadline and a QR code printed on it. A page you can hold in your hand feels more real than any email, and a QR code hides where it goes until you are already there.
Two people, several separate ways in, and no single piece of advice that covered them all. Whatever I built for one of them had to work just as well for the other, or it was useless.
Why couldn't I just tell them what to watch for?
I tried. Repeatedly. But more importantly, they try. They don't want to end up in a bad situation.
You can tell someone a hundred times to check the sender address, and it will still not help them early in the morning or late at night when a message arrives that says their account is locked. General advice fails in the exact moment it is needed, for a reason that has nothing to do with intelligence: scams aren't puzzles, they are emotional interrupts. They are engineered to produce fear, urgency, or hope, and to make you act in the middle of that emotion. A rule you memorized last month does not stand up to that. Nothing generic does.
The other thing I got wrong for a long time was assuming the problem was knowledge. It isn't. Every one of these messages is a specific question — is this sender real, does this link go where it claims, is this invoice number a real invoice number. “Be careful with links” does not answer any of those.
By the numbers: more than 201,000 victims age 60 and over reported losses exceeding $7.7 billion to the FBI's Internet Crime Complaint Center in 2025 — a 37% increase over 2024 — with the average loss per senior topping $38,000. Source: FBI IC3 2025 Internet Crime Report.
The part I could not solve: I can't be there every time
For a while, I was the service. I was the person they forwarded things to. And that worked, in the sense that it mostly produced the right answer — and completely failed, in every other sense.
Messages don't arrive on a schedule and they don't arrive one at a time. They arrive during work, on holidays, at 11pm, while I was in the middle of something I couldn't drop. And the honest arithmetic is that I cannot be awake and available every hour of every day for the rest of my parents' lives. Any protection that depends on one person being reachable is not protection. It's a single point of failure.
There was a quieter failure too. When the person you have to ask is your own child, asking has a cost. Nobody wants to feel like a burden, or like they're being checked up on. So sometimes they don't ask.
What was I actually trying to build?
Once I stopped trying to teach and started trying to design, the goal got much clearer. I was not trying to make my parents into scam experts. I was trying to insert one small habit into the two seconds before they act: pause, and ask. Everything else — every technical decision that came later — existed to make that pause feel effortless and to make the answer worth waiting for.
What would a real answer have to look like?
A pause is only useful if something useful happens during it. So I wrote down what an answer would actually have to be, and the list turned out to be demanding:
- Specific to this message, not to the category. Not “toll scams are common” but a verdict about the exact message in front of them, naming what in it is wrong.
- Backed by evidence, not by vibes. An answer that never checked anything is just an opinion, no matter how certain it sounds. The scam sounds certain too. The answer had to come from actually looking: at the real sender, at what the document really says, and where it leads you.
- Authoritative enough to end the argument. When someone is halfway convinced they need to pay right now, “probably fine” loses. The answer has to be clear and honest enough to be the thing they act on.
- As wide as possible. A scam text and a scam voicemail and a scam letter and a scam QR code are all the same question wearing different clothes. Covering only one of them just moves the gap.
- Never shaming. If the answer makes someone feel stupid for asking, they stop asking, and you have made things worse than doing nothing.
- Always awake. The whole point was to remove the single point of failure. Scams don't keep a schedule, so the answer couldn't either.
Reading that list back, my first reaction was that it might not be buildable. It's a lot to ask — an evidence-backed, honest, judgement-free answer about anything anyone might receive, at any hour.
So the next question was the obvious one, and I spent the following ten months on it.
Read part 2: whether any of this was actually possible, how the answer is built from real evidence rather than guesswork, and the first moment I knew it worked.
Was it even possible?