Job posting forensics
Paste the listing, the recruiter message, or the whole email. You get a marked-up copy showing exactly which words are the warning signs, and why each one matters.
Runs entirely in your browser. Nothing you paste is uploaded, stored, or seen by anyone.
If it came by email, include the sender details. That is where most fakes give themselves away.
Phone Open the message in the Gmail app and tap the small arrow next to to me under the sender's name. Copy the block that appears.
Computer Open the message and click the arrow beneath the sender's name to show from, reply-to, mailed-by, and signed-by.
Other mail apps: forward the message to yourself, or just paste the sender's address on its own. Even the address alone gets you a domain check.
This tool is free and always will be. No ads, no accounts, nothing stored. If it saved you from something, you can buy me a coffee. Entirely optional, and the checker works exactly the same either way.
The most reliable signals are money moving toward the employer, hiring conducted entirely on a chat app, an offer made without a real interview, and requests for identity documents or bank details before anything is signed. A sender domain that does not belong to the company being named is also close to decisive.
Not always, but it is a strong warning sign. Any company large enough to run a hiring process has its own mail domain. Check the address after the at sign against the company's real website, and remember that the display name shown in your inbox is free text that anyone can set.
No. A legitimate employer pays every cost of hiring you and ships you equipment before you spend anything. Any request to pay a fee, buy a starter kit, or cover a cost that will be reimbursed later is fraud, including when the amount is small and described as refundable.
Those accounts are free, anonymous, and disposable, and the conversation sits outside any platform that could moderate or remove it. Real employers interview by phone or video and schedule through their own systems. A refusal to appear on camera is disqualifying on its own.
Read the domain from right to left. The part that identifies the sender is the last two labels before the ending, so careers.microsoft.hiring-portal.ru is hiring-portal.ru, not Microsoft. Then confirm that domain matches the address on the company's own website, reached by searching for the company rather than by clicking any link in the message.
Contact your bank immediately if you shared account details, and place a fraud alert with the credit bureaus if you sent identity documents. Report the incident to the FTC and the FBI's IC3, and report the listing to the job board it appeared on. Acting in the first day or two matters more than anything else.