An email offers you a remote role you never applied for — easy hours, generous pay, start whenever. It just needs you to chat on Telegram and accept an “equipment package.” That is the shape of a job scam, and the payday is yours to lose. Here’s how it works, the tells, and how to check an offer safely.
Published 4 August 2026 · ~7 min read · By the Phixo team
Job scams have exploded alongside remote work, and they’re effective for a simple reason: they arrive when people want them to be real. A flexible, well-paid role landing unprompted in your inbox is easy to rationalise — maybe a recruiter found your CV, maybe you got lucky. Scammers count on that hope to switch off the scrutiny you’d apply to a “your account is locked” email.
But the fake job offer follows a script as predictable as any phishing message. Strip away the friendly tone and it’s always heading toward one of two payouts: your money (through a fake check or an equipment “fee”) or your identity (through the personal and banking details you hand over during “onboarding”). Recognise the pattern once and you’ll spot every variant.
Treat a job offer as a scam if you never applied, the pay is high for little work, there’s no real interview, and it pushes you to WhatsApp or Telegram to continue. Real employers hire from a company email domain, interview you properly, and never ask you to pay for equipment, deposit a check and wire part of it back, or hand over bank details before you’ve signed anything. Verify by checking the sender’s domain against the company’s real website, and by finding the role on the company’s own careers page yourself.
The email is the opener. Once you reply or message the “hiring manager,” the scam moves toward one of these ends:
The golden rule: in a real job, money flows to you and only to you. The instant an “employer” needs you to pay for something, buy something specific, or move money on their behalf, the offer is a scam — no matter how professional the email looked.
An offer — not even an interview invite, an offer — for a role you never sought is the first red flag. Legitimate hiring doesn’t skip the part where you apply.
“$35/hour, 3–4 hours a day, no experience required” for a role no one could describe. Scammers dangle the reward and stay fuzzy on the work, because there is no work.
Click the sender name and read the part after the @. A real recruiter at a company writes from that company’s domain.
A free Gmail address, or a lookalike domain registered last week, doing the hiring for a “company” is the tell. Check the domain against the firm’s real website.
“Message our hiring manager on Telegram to continue.” This is the single most reliable sign. Those apps have no employer verification, leave no email trail, and let the scammer vanish. Real hiring happens over company email and scheduled interviews.
A quick text chat, or a “screening” that’s really just onboarding forms, stands in for a proper conversation. No serious employer offers a job without talking to you meaningfully first.
Bank details for “payroll,” a fee for “equipment,” a check to deposit — anything financial before you’ve signed a real contract is the scam arriving. Stop there.
Take the email out of the loop and verify at the source:
Impersonation is common. Scammers borrow the names of real, reputable companies and copy real job titles to look legitimate. A recognisable company name proves nothing on its own — the email domain and the hiring process are what tell you the truth.
Most phishing plays on fear — a locked account, a failed payment, a package on hold. The job scam is unusual because it plays on hope, which lowers your guard in a different way: you want it to be real, so you look for reasons to believe rather than reasons to doubt. That’s the same emotional lever behind other “good news” scams, and the antidote is identical to the one in our guide to spotting a phishing email — verify at the source instead of trusting the message. And like the fake invoice email, the fake job offer is aimed squarely at freelancers and job-seekers, who see real recruiter mail often enough that one more doesn’t stand out.
How far it went determines what to do — work down this list:
Look for the pattern: an unexpected offer for a job you never applied to, high pay for little work, no real interview, and a push to WhatsApp or Telegram. Real employers hire from a company domain, interview you, and never ask you to pay for equipment or deposit a check and send part back. Check the sender’s domain against the company’s real site.
Those apps have no employer verification, no email trail, and let them delete messages and disappear — and they get you away from your inbox’s spam filters. Genuine recruiting happens over company email and scheduled interviews.
Not necessarily. Scammers impersonate real companies and copy real job titles to borrow credibility. Verify on the company’s official careers page and contact them through their real site — never through the email or chat you were handed.
Yes, that’s the fake-check scam. The check bounces after you’ve spent real money on “equipment,” and you’re left liable. No legitimate employer sends money before day one or makes you buy your own equipment through them.
Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language that flags patterns like unsolicited offers and off-platform chat pushes. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.