The fake job I nearly applied to had a documentation problem
It was late, I'd been looking at applications for a while, and the posting looked enticing. Technical writer, remote, part-time. Twenty hours a week at fifty to seventy dollars an hour. I was already mentally writing the cover letter after seeing the generous compensation. That should have been my first warning, but can you blame me for looking at a generous package and being interested?
So, I regret to say that I didn't catch the scam. My AI assistant did, and it caught it before I'd even started tailoring anything. And after the warning, I started looking more attentively at the job offer, the site, even the photos, and there was a big tell: the offer and the site had an editing problem.
The company couldn't keep its own name straight
The domain ended in .nl. The email address in the footer belonged to a company with a completely different name. The phone number's country code didn't match the country the company claimed to be in. No address anywhere.
Then the offer itself. Part-time, twenty hours, paid in dollars by a Dutch company, with equity, unlimited PTO, comprehensive medical and dental and vision, a two-thousand-dollar learning budget and a MacBook. On one hand, this was a pretty generous offer for a part-time job; on the other nobody hands a twenty-hour-a-week contractor American health insurance from Amsterdam.
None of that requires security expertise. It's the same read I'd do on any doc set: does this document agree with itself, and can I verify what it claims about the thing it describes? A footer that names two different companies is a broken cross-reference. Benefits copied from a template written for another jurisdiction is boilerplate nobody localised. This was a content problem wearing a job posting.
So I went and looked properly, which is where it stopped being subtle. The team photos were AI-generated. Once you've seen enough of them you don't need to squint. A search turned up threads of other people asking the same question about the same company, and a warning from a business with a similar name saying they knew people were trading on the resemblance to run exactly this.
I closed the tab. Total cost to me: about fifteen minutes and no CV sent to a stranger.
A file that doesn't get tired
I want to be clear that this wasn't me being super cautious and super experienced in catching scam job ads. What I have is a tool that searches for potential jobs, and when I find something that seems to fit, I pass the URL to a skill that runs it over my requirements. There is no scam detector in my setup. No blocklist, no fraud scoring, nothing trained on fake postings.
What I do have is a file where my hiring dealbreakers are written down. The things I won't work for. The signals that mean walk away. I wrote it months ago for a completely different reason, mostly so I'd stop wasting evenings on companies whose culture I already knew I'd hate. And because it's written down and gets read on every single application, it kept doing its job at eleven at night, when my brain was partially shut down for the day and had lowered its standards without me even realizing. It tripped on things that looked off, and when I went and looked closer, they had all the telltales of a scam.
That's the whole mechanism. Judgement I had once, in a good mood, on a clear afternoon, stored somewhere that doesn't get tired at the end of a long day.
And I think this is worth sitting with for a second, because tiredness is the actual attack surface here. There aren't many roles in my space right now. So the pile you're working through is longer and thinner at the same time, and a growing share of it isn't real, because people running these schemes go where the desperate people already are. That's just how it is this year. The part that's mine to manage is that I'm doing more applications than I used to, later than I should, with less left in the tank each time. Fatigue is a security problem and it doesn't feel like one from the inside. It feels like being efficient.
What I'd actually check
I don't think you need a comprehensive list, but you do need to be aware of a few details so that you can catch potential scams.
Does the company agree with itself? Read the footer, the contact block, the privacy policy. Mismatched names or a support address at some unrelated domain is the cheapest tell there is, and apparently it's the one scammers keep leaving in, probably because they're recycling a template.
Does the money make sense where the company says it lives? Currency, tax framing, benefits. American health insurance from a European company should stop you cold.
Do the people exist anywhere else? Reverse image search the team page. Check whether the employees they list have any history that predates the careers page. Real companies leave years of mess behind them on the internet. Fabricated ones are suspiciously clean and suspiciously recent.
Does the generosity match the commitment? Extravagant benefits attached to a small, vague, part-time role is somebody optimising for your reply, not for your employment. If the pay seems too good to be true, it probably is.
And finally, don't do this at midnight. If a posting excites you at 11pm, apply to it at 9am. Nothing worth having expires overnight.
Where this leaves me
I can't do anything about how few jobs there are. What I can control is how much of my attention this market gets to burn, and whether I'm the last line of defence when I'm least equipped to be. What I ended up with, without knowing it, was a skill that defends me from scams, because a couple of months ago I told it I have standards about company culture.
Funny where five years of technical writing lands you. I thought I was learning to make documentation clear. Turns out I was learning to notice when a document is lying, and it never occurred to me that the document might one day be a job offer with my name already half-filled in on it.