Recruiter impersonation happens when scammers pose as a real company's recruiters, using its name, logo, and lookalike domains to defraud job seekers. It has become so common that nearly half of candidates now approach legitimate recruiter outreach with suspicion, forcing real hiring teams to prove they are not a scam before a conversation can even start. That means your reply rates are not falling because your outreach is bad. They are falling because a wary candidate cannot tell you apart from the fraud.

If you run sourcing or candidate comms and you are watching response rates slide while candidates reply asking you to "verify you are a real person," this is for you. Here is the data behind the trust collapse, why better copywriting cannot fix it, and the concrete trust signals a legitimate recruiter can actually deploy.

## Why candidates now assume your recruiter is fake

Skepticism toward unsolicited recruiter contact is no longer a fringe reaction. It is close to the median candidate posture. In a Monster survey of 884 workers conducted in early March 2026 (reported by HR Dive), **95% of job seekers said they had encountered suspicious job offers**, **more than half had been directly targeted by scammers**, and **nearly half now approach recruiter outreach with skepticism**.

Sit with that last number. Roughly one in two people you cold-message assumes, by default, that you might be running a con. They are not being paranoid. They are pattern-matching against an environment that has trained them to.

The damage is not just wasted time, though there is plenty of that. In the same Monster data, about **one-third of job seekers said they lost time investigating fake opportunities**, **nearly a quarter reported ongoing stress and anxiety**, and **nearly a quarter had shared personal information** like an email or phone number before realizing it was a scam. That final figure is the one that should worry every recruiter, because handing over contact details and clicking a link is exactly what a normal application asks a candidate to do. Scammers have taught people to treat your funnel's most basic step as a threat.

## How big is the job-scam problem, really?

The trust collapse is downstream of real, fast-growing financial harm. The strongest numbers come from the U.S. Federal Trade Commission's Consumer Sentinel data, and they climb steeply.

| Year | Reported losses to job scams |
|------|------------------------------|
| 2020 | $90 million |
| 2021 | $131 million |
| 2022 | $179 million |
| 2023 | $286 million |
| H1 2024 | topped $220 million |

That is more than threefold growth from 2020 to 2023, and the first half of 2024 alone nearly matched the entire 2022 total (FTC Data Spotlight, December 2024). The FTC also notes that most fraud goes unreported, so these figures understate the real harm.

Much of the recent surge came from **"task scams,"** gamified fake jobs that display illusory in-app earnings and then demand a deposit to unlock payouts. The FTC counted about **20,000 task-scam reports in the first half of 2024, up from roughly 5,000 in all of 2023**. Crypto has become the top payment method for these scams, with losses of about **$41 million in H1 2024 versus around $21 million in all of 2023** (FTC, December 2024). The machine is getting bigger and faster.

## Why scams poison trust in legitimate recruiters

Here is the mechanism that makes this your problem specifically. The dominant scam vectors are unexpected texts, WhatsApp messages, emails, and unsolicited "recruiter" outreach. Those are the exact same channels legitimate recruiters use to cold-message candidates.

So when consumer-protection agencies give advice, that advice works directly against you. The FTC's guidance is blunt: real employers will never contact you through generic unexpected texts or WhatsApp messages, never pay to get paid, and ignore unsolicited job texts. Every one of those warnings describes, from the outside, a normal piece of sourcing outreach.

The result is that legitimate cold outreach now starts underwater. Before a candidate reads your pitch, they are already running a fraud checklist, and your message trips half of it just by existing. Scammers compound this by spoofing real company names, copying logos, and registering lookalike domains, so a candidate genuinely cannot tell a real recruiter from an impostor by content alone.

## Both directions of the fraud: fake candidates and fake recruiters

Recruiter impersonation is only one half of a two-sided fraud wave, and understanding the other half explains why one-sided defenses fail.

The other direction is fraud aimed **at employers**. The FBI warned back in June 2022 that criminals were using **deepfakes and stolen personally identifiable information to apply for remote IT and software jobs**, with lip-sync mismatches during video interviews as a tell (FBI/IC3 PSA I-062822). Gartner has projected that **by 2028, one in four job candidate profiles globally may be fake** (Gartner, 2024, as reported by HR Dive; treat this as a projection, not a measurement). And North Korean nationals posing as remote IT workers to infiltrate U.S. companies is now a well-documented, ongoing pattern. Kit has covered that specific threat in [North Korean IT worker hiring fraud](/blog/north-korean-it-worker-hiring-fraud).

Recruiter impersonation is the mirror image: attacks on candidates that use the employer's identity. Both erode the same thing: the ability of either side to trust that the other is who they claim to be. A hiring stack that only hardens the employer side, screening for fake applicants while doing nothing to prove your own legitimacy to real ones, is defending exactly half the border.

## Why better outreach copy won't fix this

The instinct, when reply rates fall, is to rewrite the message. Warmer opener. Sharper hook. More personalization. None of it works here, and the reason is structural.

An attacker can copy your words perfectly. They can lift your logo, mirror your tone, clone your careers-page layout, and register a domain one character off from yours. Better copywriting does not help a candidate distinguish you from someone impersonating you, because the impersonator will simply copy your better copywriting too. You cannot out-write a forger.

Picture the everyday case. A candidate gets two messages the same week. One is a real recruiter from a 40-person startup. The other is a scammer spoofing a known brand's logo behind a lookalike domain. By content, the two are indistinguishable; the scammer may well have the tighter subject line. What actually separates them is whether the real message arrives DKIM-signed from a verified domain and links to a branded, company-owned portal with no password to enter. Everything a candidate can *read* is forgeable. Only the plumbing is not.

The only durable differentiators, then, are the things an attacker **cannot** forge cheaply. That is not language. It is infrastructure: a cryptographically authenticated email from your real domain, a destination on a domain you actually control, and a login flow with no phishable secret in it. These either exist in your hiring stack or they do not, and the candidate, or their mail client, can verify them without taking your word for anything.

<div class="blog-inline-cta">
  <p><strong>Your outreach isn't the problem. Your proof is.</strong> Kit signs every recruiter email from your own verified domain and sends candidates to a branded, company-owned portal, so legitimacy is something they can see, not something you have to argue.</p>
  <p><a href="/users/sign_up">Start your free trial</a></p>
</div>

## The trust signals a legitimate recruiter can actually deploy

Words won't separate you from a scammer, but a short list of verifiable signals will. Here is the checklist, in rough order of impact.

1. **Authenticated sender email.** Send from your company's own verified domain with valid SPF, DKIM, and DMARC. These are the industry-standard mechanisms precisely because they let the *receiver* cryptographically verify the sender. A free-mailbox address (a generic Gmail or Outlook account) or a spoofable domain cannot be verified, and increasingly mail clients say so out loud.
2. **A branded, company-owned destination.** Link candidates to your own domain and a branded career portal, not a generic ATS-vendor URL that looks interchangeable with a phishing link. A candidate who lands on `yourcompany.com` can read the address bar; one who lands on a random vendor subdomain cannot tell it from a lookalike.
3. **No credential collection.** Do not ask candidates to create a password. A passwordless, single-use magic-link login means there is no password to phish and no credential-stuffing surface. It also trains candidates to expect "we'll email you a secure link" instead of "create an account and enter a password," which is precisely the flow scam sites imitate.
4. **Consistent, checkable identity.** Same sender domain, same portal domain, same named recruiter across every touchpoint, with a real presence a candidate can independently confirm. Consistency is itself a signal; scams tend to shift channels and identities between messages.

Notice what is missing from this list: your prose. Every item is something a machine or a careful human can check independently. That is the whole point.

## How verified sender and passwordless auth became the recruiting baseline

Two of those signals deserve a plain-language explanation, because they used to be "nice to have" and the fraud era has quietly promoted them to table stakes.

**DKIM and DMARC are receiver-verified authentication, not a spam filter.** When you send DKIM-signed mail from a domain with a DMARC policy, you attach a cryptographic signature that the recipient's mail server checks against your published DNS records. If it validates, the receiver knows the message really came from your domain and was not altered in transit. An impersonator sending from a lookalike domain cannot produce that signature for *your* domain. This is not about landing in the inbox instead of spam; it is about the candidate's mail provider being able to confirm you are you.

**Magic links remove the phishable secret.** A single-use link emailed to the candidate lets them into your portal without ever creating a password. You cannot steal a password that was never created, and there is no credential-stuffing target sitting in a database waiting to leak. It is not that magic links are unbreakable in every scenario; it is that removing the stored secret removes an entire category of attack. Kit made this the default for candidate access, and the reasoning is spelled out in [Why we killed passwords for candidates](/blog/why-we-killed-passwords-for-candidates).

Frame both honestly with your security-minded colleagues. DKIM authenticates the sender; it does not guarantee deliverability. Passwordless removes the credential-theft surface; it does not make phishing impossible. But together they are two things an impostor cannot cheaply reproduce, and in a market where candidates assume fraud by default, "cannot be cheaply faked" is the only claim that matters.

## How Kit builds candidate trust in by default

Everything above is vendor-neutral advice; you can and should demand these signals from whatever stack you run. Kit's argument is simply that in the fraud era they should be defaults, not add-ons, so here is how Kit ships them.

- **Verified-sender email from your own domain.** Kit's outbound mail is DKIM-signed and sent as your verified company domain via a self-hosted mail server, so a candidate's mail client shows real authentication instead of a spoofable free-mailbox sender. The one thing a scammer cannot cheaply fake is a cryptographically authenticated email from your real domain, and Kit signs every message that way.
- **Passwordless magic-link candidate portal.** Candidates log in with secure, single-use links, so there is no password to phish and no credential-stuffing surface anywhere in the flow.
- **A branded, company-owned portal URL.** Candidates land on a company-branded, tenant-scoped destination rather than a generic vendor link they cannot distinguish from phishing. Legitimacy becomes something they can see in the address bar.
- **Human-reviewed, specific outreach.** Kit's outreach is built for real, specific messages sent under human review, the opposite of the blast-volume pattern that scams and spam recruiters rely on. If you care about outreach that lands honestly, see [personalized recruiter outreach and reply rates](/blog/personalized-recruiter-outreach-reply-rates).

If your candidate PII and security posture is the broader worry behind all this, [securing candidate data when your ATS becomes the breach](/blog/recruiting-platform-data-breach-candidate-pii-security) covers the storage side of the same problem.

The takeaway is narrow and durable. Candidate trust has become an infrastructure problem, not a messaging one. You will not write your way out of being mistaken for a scammer, because the scammer can copy anything you write. What they cannot copy is authenticated mail from your real domain, a portal on a domain you control, and a login with no secret to steal. Build those in, and legitimacy stops being something you assert and starts being something a wary candidate can simply verify.

Want to see what verified, passwordless candidate communication looks like out of the box? [Start a free trial](/users/sign_up) and send yourself a candidate email.