← All articles A person checking a suspicious email on a laptop

By Joyce Eva Nolla · 8 min read

One Friday, an email landed in my inbox. Sender name: Amazon, with the logo and the verified badge. A senior marketing role, "matching my background". Every security signal was green: SPF, DKIM and DMARC all passed, sent from a real amazon.com subdomain. And yet it was entirely fake. This story is not a one-off: it shows the new generation of job scams, written and refined with artificial intelligence, built to slip past the very filters we are told to trust. Here is how these traps work, and above all how to defeat them.

Let's dissect the specimen

Take this "Amazon" email and open it up, layer by layer. Each part has a precise job inside the trap.

1. The skin. What you see first is built to reassure: the name "Amazon", the verified badge, the logo, and a hook, "a role that matches your background". The surface is flawless, and that is exactly the point.

2. The technical skeleton. Under the skin, the envelope is genuine: SPF, DKIM and DMARC all show "pass", and the email comes from a real subdomain, email.health.amazon.com. Except that subdomain is the newsletter system of the health division: the pipe is authenticated, but hijacked from its intended use.

3. The nervous system. Then come the psychological levers: personalized flattery clearly pulled from your LinkedIn profile, the authority of a big brand, a sense of urgency, and a step-by-step progression that draws you in a little more with each exchange.

4. The hidden machinery. The heart of the setup is a "Submit your details" button that does not lead to Amazon's site, but to a tracking redirector whose destination is masked. That is the trapdoor: one click, and your data goes elsewhere.

5. The AI's DNA. In the message's code, the fraudster forgot to clean out raw tags from the ChatGPT interface (data-turn="assistant", conversation-turn-140) and signed off "in collaboration with Gemini", a competitor's AI. These are the fingerprints of manufacture: the message was written with an AI, then pasted without proofreading.

6. The predation. The real goal is not to hire you. It is to get your information first, then draw you further in: a fake interview, a request for money or a paid service. Everything else is set dressing.

Once you have seen the inside, you spot the same skeleton in almost all of these scams. Here is how to detect it every time.

What changed: recruitment fraud goes AI

Fake job offers are nothing new, but their volume and credibility have crossed a line. According to the US Federal Trade Commission, reported losses to job scams more than tripled between 2020 and 2023, and already topped 220 million US dollars in the first half of 2024 alone. In Canada, the Canadian Anti-Fraud Centre reports that more than 2,300 victims lost over 49 million dollars to these scams in 2024, and only 5 to 10% of frauds are ever reported: the real numbers are far higher.

Artificial intelligence speeds everything up. Fraudsters use language models to read your LinkedIn profile and write a message that mirrors your background, tone and career path. The result looks personal and professional, without the spelling mistake that used to give the scam away, and the volume is exploding.

The core lesson: a verified badge and green security checks authenticate the pipe, not the person behind the message. In 2026, "it looks legit" is no longer a security strategy.

Recognize the red flags

Before any technical check, some behaviours should raise your guard:

  • Unsolicited contact on the wrong channel. A real recruiter does not pitch a senior role by text, WhatsApp or Telegram.
  • Big money, few details. High pay, a vague description, no mention of a real process.
  • Urgency and flattery. You are rushed, told your profile is "exceptional", pressured to decide fast.
  • Personal information requested too early. Social insurance or security number, banking details, ID copy, before any real interview.
  • An offer with no serious interview. A job offered after a simple chat exchange, without ever seeing a face, is almost always fake.
  • You are asked to pay. Equipment, training, software: no honest employer makes you pay to be hired.
  • You are steered toward a paid service or "specialist". A real recruiter never charges you and does not refer you to a paid resume-writing service. This is often an advance-fee scam, where the fake recruiter earns a commission.
  • You are told not to contact the company directly. This instruction is meant to isolate you and stop you from verifying the offer at the source.

Real recruiter vs fake recruiter

 Real recruiterFake recruiter (scam)
First contactPosted role, professional channelSurprise message, often by text or chat app
Email addressOfficial company domainGeneric domain, odd subdomain, or tracking link
ProcessInterviews, exchanges, normal timelinesNear-instant offer, pressure, everything in writing
Information askedAfter hiring, via a secure HR portalBank, ID or SIN from the start
MoneyThe company pays youYou are asked to pay or to cash a cheque
VerifiableThe role exists on the official careers siteFound nowhere but the email

Verify, from the simplest to the most complex

Here is the verification ladder, from the fastest move to the most technical analysis. The first three steps expose the vast majority of scams in under two minutes.

  1. The quoted Google search. Copy the exact job title in quotation marks, followed by the company name, for example "Senior Digital Customer Strategy Manager" Amazon. If the query returns no results, that is your first warning: a real role almost always leaves a public trace.
  2. The reputation search. Search the company or recruiter name followed by words like "scam", "fraud" or "complaint". Previous victims have often already documented the scheme.
  3. The official careers site check. Go straight to the company site (for example amazon.jobs) and search for the role. If it is not listed, it does not exist. Golden rule: never apply through a link received by email, always go to the official site yourself.
  4. The sender address analysis. Look at the real address, not just the display name. Be wary of generic domains (gmail.com, outlook.com) for corporate recruiting, and of inconsistent subdomains. In the Amazon case, the email came from email.health.amazon.com, the newsletter system of the health division: a pharmacy does not recruit senior marketing managers.
  5. Hovering over links, without clicking. Hover over each button or link to reveal the real URL. A "Submit your details" link pointing to an unknown tracking redirector rather than to the company site is a trap. When in doubt, copy the link without clicking it (right-click, then "Copy link address") and paste it into a recognized URL checker, which analyzes the real destination without you having to visit it:
    • VirusTotal (virustotal.com)
    • Google Safe Browsing site status (transparencyreport.google.com/safe-browsing/search)
    • urlscan.io
    • Cloudflare Radar URL Scanner (radar.cloudflare.com/scan)
    • Norton Safe Web (safeweb.norton.com)

    One important note: a "safe" verdict is not a 100% guarantee. A brand-new scam page that has not been reported yet can slip through. So cross-check two tools, and if either one flags any danger, do not click.

  6. The recruiter identity check, in depth. Look up their LinkedIn profile, but remember that existing is not the same as being authentic: fraudsters steal a real professional's photo, and sometimes even their job title, to build a credible identity. Go further: the email address should match the profile (a consistent company domain, not a Gmail); message the person through their official LinkedIn profile to confirm they really contacted you; run a reverse image search on their photo (if it appears under other names, it is stolen); check the account's age, activity, recommendations and current employer, then cross-check with the agency's official site and an official phone number.
  7. Reading the headers. In Gmail: the three dots, then "Show original". You will see the real sending route and the SPF, DKIM and DMARC verdicts in plain text. Be careful though: these checks authenticate the sending domain, not the person. A fraudster abusing a legitimate subdomain or a compromised account can show three "pass" verdicts while being 100% malicious.
  8. AI-assisted analysis. Copy those headers and paste them into an assistant (ChatGPT, Claude, Gemini, Copilot, Perplexity or Le Chat) with the question: "Is this email legitimate? Analyze the headers." AI spots alignment inconsistencies and suspicious relays faster than the human eye.
  9. Spotting AI and copy-paste traces. Rushed fraudsters leave clues. In the Amazon case, the email's HTML contained raw ChatGPT interface tags (data-turn="assistant", conversation-turn-140): proof the message had been refined over 140 exchanges with an AI, then pasted without cleanup. A signature reading "in collaboration with Gemini" (a competitor's AI) is another telling absurdity.

Careful: AI can be fooled too

Pasting the headers into an AI assistant (step 8) is useful, but it is not an infallible verdict. When this email was tested, an AI assistant first caught the scam, then changed its mind and called it "legitimate". That is exactly the reasoning error this kind of fraud feeds on. Here are the most common traps, so you know when not to trust an AI's answer:

  • Confusing "authenticated" with "honest". Green SPF, DKIM and DMARC only prove the email really passed through a server authorized for that domain. It is like recognizing the mail carrier, not checking what is inside the envelope. If the sending account is hacked or abused, everything it sends is "technically perfect" and still fraudulent.
  • Inventing an explanation for every anomaly. To justify what looks wrong, an AI can make up unverifiable stories: "maybe Amazon recruits through its health division", "Gemini is probably an internal code name", "the person exists, they are just not indexed". When every red flag needs its own special, custom explanation, the simplest answer is the right one: it is a scam.
  • Treating absence of proof as proof. "I can't find anything on this recruiter, so nothing says they are fake" is circular reasoning. Not being able to verify that someone exists is a negative signal, not a reassuring one.
  • Declaring a link "safe" without following it. An AI cannot see where a masked tracking link actually leads. So it cannot guarantee the link is harmless.
  • Citing off-topic sources or inventing details. An AI can state things with confidence, lean on a source that is about something else, or describe a header that does not even exist in your email. This is called a hallucination.
  • Ignoring the most obvious clue. Here, the email's code contained raw tags from the ChatGPT interface. An analysis that concludes "100% legitimate" without explaining that anomaly simply did not analyze the message.
  • Flip-flopping with the wording, and pushing you to act. Rephrase the question and an AI can reverse its verdict. Some even end up offering to "prepare you for the interview", which is exactly the trap the fraudster was hoping for.

How to use AI without getting caught: treat it as a second pair of eyes, never as the final judge. Give it the full information (the headers AND the email's source code), always cross-check with independent verification (the official careers site, the reputation search), and be suspicious if it changes its mind or invents explanations. The rule that never fails is still the simplest one: if the role is not on the company's official careers site, it does not exist. For a thoughtful everyday use of AI, I share elsewhere how I built my own multi-AI stack.

Financial traps to spot

Many job scams do not only want your data: they want to turn you into a middleman, sometimes without your knowledge. Here are the four most common setups and the reflex that protects you.

The trapHow it worksThe right reflex
Fake cheque and overpaymentYou get a cheque "for your equipment", send part of it back, then the cheque bounces weeks later and the bank claws back the full amountNever cash a cheque to send part of it back
Money muleYou receive money then forward it elsewhere for a commission: it is criminal money you are launderingNever lend out your bank account
Parcel mule (reshipping)You are "hired" to receive and reship parcels bought with stolen cardsRefuse any job that involves reshipping parcels
Task scamsSmall early payouts, then a deposit demanded to "unlock" earnings that do not existNever pay to get paid

These setups can expose you to prosecution, even if you did not know what they were. The FTC notes that task scams made up nearly 39% of job scam reports in the first half of 2024, with cryptocurrency as the preferred payment method. The rule that sums it all up: never pay to get paid, never cash a cheque to send part of it back, never lend out your bank account.

Protect your data

What you should never give an unverified recruiter: social insurance or security number, banking details, passport or licence copy, passwords. Turn on two-factor authentication on your accounts, consider a separate email address for applications, and if you think you have been exposed, place a fraud alert on your credit file. These steps limit the damage even if a fraudster gets some of your information.

If you are a victim: what to do, step by step

  1. Cut contact and send nothing more.
  2. Notify your financial institution immediately if money or a cheque is involved; it can sometimes block or reverse a transaction.
  3. Change your passwords and enable two-factor authentication.
  4. Report it (see the help lines below).
  5. Monitor your credit with Equifax Canada and TransUnion Canada, and request a fraud alert.
  6. If your SIN is compromised, contact Service Canada.

Help lines and reporting

In Canada

  • Canadian Anti-Fraud Centre (CAFC). Report online at reportcyberandfraud.canada.ca, or by phone at 1-888-495-8501 (Monday to Friday, 10 a.m. to 4:45 p.m. Eastern time).
  • Your local police. Police investigate; report any theft of money or identity to them.
  • Competition Bureau Canada (deceptive marketing practices): 1-800-348-5358.
  • Service Canada (compromised social insurance number): 1-866-274-2267.
  • Credit bureaus: Equifax Canada and TransUnion Canada, for a fraud alert.

On the platforms

  • Gmail: open the message, the three dots, then "Report phishing".
  • LinkedIn: the "..." menu on the message or profile, then "Report".
  • The impersonated company's fraud team (for example recruiting-fraud@amazon.com), with the technical evidence.

Internationally

  • United States: ReportFraud.ftc.gov, IdentityTheft.gov, and the FBI at ic3.gov.
  • Phishing: forward the email to reportphishing@apwg.org.

Learn more: reliable resources on scams

A few free, trustworthy resources to recognize fraud and stay current:


Frequently asked questions

What are SPF, DKIM and DMARC, in plain terms?

They are three technical checks that verify where an email comes from. SPF lists which servers are allowed to send messages for a domain. DKIM adds a signature that proves the message was not altered in transit and really came from a server holding the domain's key. DMARC checks that the domain shown in the "From" field matches the ones validated by SPF and DKIM. Together they authenticate the sending channel, not the honesty of the person writing.

Is an email that passes SPF, DKIM and DMARC necessarily safe?

No. Those checks authenticate the domain and the sending channel, not the sender's intent. A fraudster abusing a legitimate subdomain or a compromised sending account can show three green verdicts while being malicious. Always confirm the role actually exists on the official careers site.

What is the fastest way to verify a job offer?

Copy the exact job title in quotation marks, followed by the company name, into Google. A query with no results at all is a first warning. Then confirm by searching for the role directly on the company's official careers site: if it is not there, it does not exist.

Can I ask an AI to check an email for me?

Yes for a first opinion, no as a final verdict. An AI can analyze the headers and flag inconsistencies, but it also gets things wrong: it can confuse "authenticated" with "honest", invent reassuring explanations, or call a link "safe" without following it. Use it as a second pair of eyes, and always cross-check with the official careers site.

How can I tell if a message was written by an AI?

Be wary of overly smooth personalization, a generic corporate tone, unusual length and, sometimes, leftover code or inconsistencies (names, pronouns, odd signatures). Careful though: the absence of typos no longer proves anything. Today most of these scams are impeccably written, precisely because of AI.

I already shared information or money. What should I do first?

Contact your financial institution immediately if money or a cheque is involved, change your passwords, then report to the Canadian Anti-Fraud Centre (1-888-495-8501 or reportcyberandfraud.canada.ca) and your local police. Request a fraud alert from Equifax and TransUnion, and notify Service Canada if your social insurance number is involved.

I'm sharing this article simply because these scams affect everyone, and a few reflexes are often enough to avoid them. If it helped you, please share it: it could help more than one person. I'm Joyce Eva Nolla, a bilingual (FR/EN) marketing and communications strategist and the founder of PichPich Marketing.

Did this help? Share it, and browse the blog for more clear, practical guides.

See the blog