Filed under: Income seekers

How do I tell if a recruiter email is a lookalike-domain scam?

Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →

Part of our guide: How to spot a fake job offer →

Slow down and read the domain after the @ one character at a time, that single habit exposes most of these. The trick is a registered look-alike (extra words, a swapped letter, an odd TLD such as .top or .zone) that skims past as the real company. So the rule is simple: if the domain isn't the company's exact official one, treat the offer as fake until it's proven otherwise. This is the pattern behind every brand-name version, Apple, Amazon, Microsoft and two dozen more all get impersonated the same way.

Got a message like this? Paste it here →

Detection runs 100% locally on your device. We store nothing.

Please don’t paste other people’s personal data. Detection runs 100% locally on your device, and we store nothing.

Or check it on Telegram

The exhibit
EXHIBIT · CHECK BEFORE YOU ENTER YOUR PASSWORD.
Received via: Email EN
Hello, we reviewed your profile and would love to move forward for a remote position at our client. Please verify your identity within 24 hours to confirm your interest here: talent-openings.example/apply. Regards, Talent Acquisition Team

Illustrative example of the pattern, not a real message someone received.

How to verify it yourself

  • Copy the domain into a search engine with the word "scam" and read what comes back.
  • Check the domain's age, brand-new domains for a "big company" role are a red flag.
  • Hover every link before clicking; the visible text and the real target often differ.
  • Legit recruiters use the company's ATS (greenhouse, lever, workday), not a one-off .top form.

Source: FTC, Job Scams