How to spot a fake recruiter email

The fastest way to catch a fake recruiter email: check whether the reply-to domain belongs to the employer. Here is how to read it.

The one check that does most of the work

A real recruiter at a real company emails you from that company's domain. If someone says they hire for Dentsu, the address ends in the domain Dentsu owns. If the reply goes somewhere else, stop.

That is the whole lesson. Everything below is detail.

A real example

I received an email presenting itself as a recruiter for Dentsu Group. The name was right. The logo was right. The tone was the usual friendly, slightly urgent recruiter voice.

The Reply-To header was careers@applyprospectplus.com.

That domain has no connection to Dentsu. Dentsu does not route its hiring through it. Anyone who replied would have been talking to whoever registered applyprospectplus.com, not to Dentsu.

Nothing in the visible email gave that away. The header did.

Where to look

Most email clients hide headers by default. Here is how to find the two fields that matter.

The From address. Not the display name. The display name is free text, and anyone can type "Dentsu Talent Team" into it. Look at the actual address after the name, usually in angle brackets or revealed on hover or tap.

The Reply-To address. This is the address your reply actually goes to. It can differ from the From address, and that is where the trick often sits. Press reply and look at the To field before you type anything. If it does not match the domain you expected, you have your answer.

In Gmail, click the small arrow beside the sender name to see "reply-to". In Apple Mail, click the sender name. In Outlook, open the message and look at the sender details. Every client can show this; it just takes one extra click.

Read the domain, not the name

A domain is everything after the @ sign, read from the right. The part that matters is the last two segments before any slash.

Large employers sometimes use a recruitment platform, and those platforms send from their own domains. That does happen. But a genuine one will name the platform, and the job will exist on the employer's own careers page. Which brings me to the second check.

Confirm on the employer's side

Do not use any link in the email. Open a fresh browser tab, type the company's website yourself, and find the careers page. Search for the role. If the job is real, it will be there, with an application route the company controls.

If the role is not listed, that is not proof of fraud on its own. Some roles are confidential. But it does mean you should not send anything until the recruiter can point you to it through a channel you found yourself.

You can also look up the recruiter by name on LinkedIn. Check that the profile is established, that it lists the employer, and that the employer's page links back to real staff. Then message them through LinkedIn, not by replying to the email. If the person is real, they will confirm. If they are not, you have lost nothing.

Other tells, in order of usefulness

None of these is as reliable as the domain check. Together they add confidence.

What the fraud is actually for

It helps to know what they want, because it tells you what to protect.

Sometimes the goal is your personal data, for identity fraud. Sometimes it is a fee dressed up as a background check or a laptop deposit. Sometimes it is a cheque scam, where you bank a fake payment and forward part of it. And sometimes the "job" is a route to laundering money through your account.

Every one of these needs you to reply first. The domain check stops it before that.

A short routine

  1. Ignore the display name. Read the From address.
  2. Press reply. Read the Reply-To address. Cancel.
  3. Ask: does that domain belong to the employer? If not, stop.
  4. Find the job on the employer's own site, in a tab you opened yourself.
  5. Contact the recruiter through a channel you found, not one they gave you.

That takes about a minute. It would have caught the Dentsu email at step two.

If you have already replied

Do not panic, and do not send anything else. I have written a separate guide on what to do next, step by step.

A tool, if you want one

I am building Proof of Sender to run the domain check for you. Paste the sender and reply-to addresses, and it tells you whether they line up with the organisation named in the email. It is early and it is free. Try it at proofofsender.com/demo.

Not sure about an email in front of you right now? Check the sender free. It runs in your browser and nothing is stored.