Blog · Cybersecurity & AI
A fake recruiter email can pass every security check and look 100% real. Here is how to expose it, from the simplest test to the most technical analysis.
One Friday, an email landed in my inbox. Sender name: Amazon, with the logo and the verified badge. A senior marketing role, "matching my background". Every security signal was green: SPF, DKIM and DMARC all passed, sent from a real amazon.com subdomain. And yet it was entirely fake. This story is not a one-off: it shows the new generation of job scams, written and refined with artificial intelligence, built to slip past the very filters we are told to trust. Here is how these traps work, and above all how to defeat them.
Take this "Amazon" email and open it up, layer by layer. Each part has a precise job inside the trap.
1. The skin. What you see first is built to reassure: the name "Amazon", the verified badge, the logo, and a hook, "a role that matches your background". The surface is flawless, and that is exactly the point.
2. The technical skeleton. Under the skin, the envelope is genuine: SPF, DKIM and DMARC all show "pass", and the email comes from a real subdomain, email.health.amazon.com. Except that subdomain is the newsletter system of the health division: the pipe is authenticated, but hijacked from its intended use.
3. The nervous system. Then come the psychological levers: personalized flattery clearly pulled from your LinkedIn profile, the authority of a big brand, a sense of urgency, and a step-by-step progression that draws you in a little more with each exchange.
4. The hidden machinery. The heart of the setup is a "Submit your details" button that does not lead to Amazon's site, but to a tracking redirector whose destination is masked. That is the trapdoor: one click, and your data goes elsewhere.
5. The AI's DNA. In the message's code, the fraudster forgot to clean out raw tags from the ChatGPT interface (data-turn="assistant", conversation-turn-140) and signed off "in collaboration with Gemini", a competitor's AI. These are the fingerprints of manufacture: the message was written with an AI, then pasted without proofreading.
6. The predation. The real goal is not to hire you. It is to get your information first, then draw you further in: a fake interview, a request for money or a paid service. Everything else is set dressing.
Once you have seen the inside, you spot the same skeleton in almost all of these scams. Here is how to detect it every time.
Fake job offers are nothing new, but their volume and credibility have crossed a line. According to the US Federal Trade Commission, reported losses to job scams more than tripled between 2020 and 2023, and already topped 220 million US dollars in the first half of 2024 alone. In Canada, the Canadian Anti-Fraud Centre reports that more than 2,300 victims lost over 49 million dollars to these scams in 2024, and only 5 to 10% of frauds are ever reported: the real numbers are far higher.
Artificial intelligence speeds everything up. Fraudsters use language models to read your LinkedIn profile and write a message that mirrors your background, tone and career path. The result looks personal and professional, without the spelling mistake that used to give the scam away, and the volume is exploding.
The core lesson: a verified badge and green security checks authenticate the pipe, not the person behind the message. In 2026, "it looks legit" is no longer a security strategy.
Before any technical check, some behaviours should raise your guard:
| Real recruiter | Fake recruiter (scam) | |
|---|---|---|
| First contact | Posted role, professional channel | Surprise message, often by text or chat app |
| Email address | Official company domain | Generic domain, odd subdomain, or tracking link |
| Process | Interviews, exchanges, normal timelines | Near-instant offer, pressure, everything in writing |
| Information asked | After hiring, via a secure HR portal | Bank, ID or SIN from the start |
| Money | The company pays you | You are asked to pay or to cash a cheque |
| Verifiable | The role exists on the official careers site | Found nowhere but the email |
Here is the verification ladder, from the fastest move to the most technical analysis. The first three steps expose the vast majority of scams in under two minutes.
One important note: a "safe" verdict is not a 100% guarantee. A brand-new scam page that has not been reported yet can slip through. So cross-check two tools, and if either one flags any danger, do not click.
Pasting the headers into an AI assistant (step 8) is useful, but it is not an infallible verdict. When this email was tested, an AI assistant first caught the scam, then changed its mind and called it "legitimate". That is exactly the reasoning error this kind of fraud feeds on. Here are the most common traps, so you know when not to trust an AI's answer:
How to use AI without getting caught: treat it as a second pair of eyes, never as the final judge. Give it the full information (the headers AND the email's source code), always cross-check with independent verification (the official careers site, the reputation search), and be suspicious if it changes its mind or invents explanations. The rule that never fails is still the simplest one: if the role is not on the company's official careers site, it does not exist. For a thoughtful everyday use of AI, I share elsewhere how I built my own multi-AI stack.
Many job scams do not only want your data: they want to turn you into a middleman, sometimes without your knowledge. Here are the four most common setups and the reflex that protects you.
| The trap | How it works | The right reflex |
|---|---|---|
| Fake cheque and overpayment | You get a cheque "for your equipment", send part of it back, then the cheque bounces weeks later and the bank claws back the full amount | Never cash a cheque to send part of it back |
| Money mule | You receive money then forward it elsewhere for a commission: it is criminal money you are laundering | Never lend out your bank account |
| Parcel mule (reshipping) | You are "hired" to receive and reship parcels bought with stolen cards | Refuse any job that involves reshipping parcels |
| Task scams | Small early payouts, then a deposit demanded to "unlock" earnings that do not exist | Never pay to get paid |
These setups can expose you to prosecution, even if you did not know what they were. The FTC notes that task scams made up nearly 39% of job scam reports in the first half of 2024, with cryptocurrency as the preferred payment method. The rule that sums it all up: never pay to get paid, never cash a cheque to send part of it back, never lend out your bank account.
What you should never give an unverified recruiter: social insurance or security number, banking details, passport or licence copy, passwords. Turn on two-factor authentication on your accounts, consider a separate email address for applications, and if you think you have been exposed, place a fraud alert on your credit file. These steps limit the damage even if a fraudster gets some of your information.
A few free, trustworthy resources to recognize fraud and stay current:
They are three technical checks that verify where an email comes from. SPF lists which servers are allowed to send messages for a domain. DKIM adds a signature that proves the message was not altered in transit and really came from a server holding the domain's key. DMARC checks that the domain shown in the "From" field matches the ones validated by SPF and DKIM. Together they authenticate the sending channel, not the honesty of the person writing.
No. Those checks authenticate the domain and the sending channel, not the sender's intent. A fraudster abusing a legitimate subdomain or a compromised sending account can show three green verdicts while being malicious. Always confirm the role actually exists on the official careers site.
Copy the exact job title in quotation marks, followed by the company name, into Google. A query with no results at all is a first warning. Then confirm by searching for the role directly on the company's official careers site: if it is not there, it does not exist.
Yes for a first opinion, no as a final verdict. An AI can analyze the headers and flag inconsistencies, but it also gets things wrong: it can confuse "authenticated" with "honest", invent reassuring explanations, or call a link "safe" without following it. Use it as a second pair of eyes, and always cross-check with the official careers site.
Be wary of overly smooth personalization, a generic corporate tone, unusual length and, sometimes, leftover code or inconsistencies (names, pronouns, odd signatures). Careful though: the absence of typos no longer proves anything. Today most of these scams are impeccably written, precisely because of AI.
Contact your financial institution immediately if money or a cheque is involved, change your passwords, then report to the Canadian Anti-Fraud Centre (1-888-495-8501 or reportcyberandfraud.canada.ca) and your local police. Request a fraud alert from Equifax and TransUnion, and notify Service Canada if your social insurance number is involved.
Did this help? Share it, and browse the blog for more clear, practical guides.
See the blog