CA. Akhilesh Kumarcaakhilesh.in
Job Fraud Intelligence · methodology

How the job fraud checker decides — and what it cannot know

Risk model v1.0.0 · datasets sources 1.0.0 · companies 1.0.0 · patterns 1.0.0 · indicators 1.0.0 · reports 1.0.0 · effective 2026-09-15 · review after 2026-12-15

1. What is checked

Six checks, run in order, each producing signals with evidence, a source, a timestamp and a confidence:

  1. Evidence extraction. Email addresses and links are pulled from the pasted text so a reader who only pastes a message still gets the recruiter and job checks. Text from an offer-letter PDF is extracted in the browser and scanned like pasted text.
  2. Company. The name given, or a brand named in the text, is matched against companies.json (63 employers, each with official domains and a careers URL where one resolved on 2026-09-15). States: verified (in the dataset), mentioned (named in the text only), not in dataset, not supplied.
  3. Recruiter and domain. The address's domain is classed: official (the company's domain or a subdomain), free-mail (38 providers), lookalike (same label on another TLD; the company's label plus tokens such as -hr, -careers, -india; one or two edits away; the brand embedded in a longer label), government (gov.in, nic.in, bank.in and the other official suffixes), or corporate, not on file.
  4. Job listing. The link's host is classed the same way, with two extra classes: listed on a job portal or social network (a place, not a verification) and chat link (wa.me, t.me).
  5. Fraud patterns. 30 regular expressions over the text, line by line, in five categories. A same-line negation (“we never ask for any fee”) cancels payment matches on that line, so an employer's own warning does not score as a demand.
  6. Impersonation. A brand from the dataset contacted from a free or lookalike address; a job link that imitates a verified domain; a government job offered from a non-government domain (halved when no contact domain was given at all).

2. How the risk score is calculated

Deterministic and additive. Risk signals add their weight within their category; each category is capped: payment 45, communication 30, documents 20, job 35, impersonation 30, recruiter 35. Trust credits — recruiter on the official domain 25, job link on the official site 20, company in the dataset 5, corporate (non-free) recruiter domain 5 — are subtracted, and halved when any payment signal is present. The result is clamped to 0–100.

LevelRule
CRITICALscore ≥ 75, or a payment demand together with a free-mail recruiter, a lookalike domain or an impersonation signal
HIGHscore ≥ 55
MEDIUMscore ≥ 30
LOWscore < 30 and at least one signal (risk or trust) was found
INSUFFICIENT EVIDENCEno message or letter text of 40+ characters and fewer than two other evidence sources (recruiter address, job link, matched company); or text and sources present but no signal of either kind found. No score is shown.

The score is shown only when the coverage rule is met. With one field alone — a company name, a title — the page reports what it could not verify instead of a number. Any AI assistance a reader might add outside this page (to transcribe a screenshot, say) contributes text only; the score is computed here from that text by the same rules.

Every pattern, with its weight and source

idPatternCategoryWeightSourceConf.
fee-registrationRegistration or application feepayment35TCS — Recruitment Fraud Alert (India careers)0.9
fee-security-depositSecurity deposit or refundable depositpayment40Infosys — Recruitment Fraud Alert0.9
fee-trainingTraining, course or certification fee before joiningpayment30TCS — Recruitment Fraud Alert (India careers)0.85
fee-equipmentPayment for laptop, equipment or softwarepayment30TCS — Recruitment Fraud Alert (India careers)0.8
fee-background-checkBackground-check, verification or processing feepayment30Infosys — Recruitment Fraud Alert0.85
pay-cryptoCryptocurrency or USDT paymentpayment40MEA advisory — Indian nationals travelling to Cambodia and South-East Asia for jobs (reported by Akashvani News)0.8
pay-transferBank transfer, UPI or wallet payment requestedpayment25TCS — Recruitment Fraud Alert (India careers)0.8
pay-gift-cardGift card or voucher paymentpayment40National Cyber Crime Reporting Portal and helpline 19300.75
pay-genericMoney requested before joiningpayment20TCS — Recruitment Fraud Alert (India careers)0.8
task-investmentTask-based or investment job (pay to earn)payment35MEA advisory — Indian nationals travelling to Cambodia and South-East Asia for jobs (reported by Akashvani News)0.8
comm-whatsapp-onlyRecruitment conducted on WhatsAppcommunication18TCS — Recruitment Fraud Alert (India careers)0.7
comm-telegramRecruitment conducted on Telegramcommunication22TCS — Recruitment Fraud Alert (India careers)0.75
comm-im-interviewInterview or selection over chat, no call or meetingcommunication20Infosys — Recruitment Fraud Alert0.85
comm-urgencyUrgency or deadline pressurecommunication12TCS — Recruitment Fraud Alert (India careers)0.7
comm-threatThreat or penaltycommunication18National Cyber Crime Reporting Portal and helpline 19300.7
comm-secrecySecrecy demandedcommunication15National Cyber Crime Reporting Portal and helpline 19300.75
comm-unsolicitedUnsolicited selection without an applicationcommunication8TCS — Recruitment Fraud Alert (India careers)0.6
comm-personal-numberContact only through a personal mobile numbercommunication8TCS — Recruitment Fraud Alert (India careers)0.6
doc-aadhaar-pan-earlyAadhaar, PAN or passport requested before an offerdocuments18Infosys — Recruitment Fraud Alert0.7
doc-bank-detailsBank account, card, OTP or net-banking details requesteddocuments22Infosys — Recruitment Fraud Alert0.8
doc-photo-selfieSelfie, photo or video KYC requested by chatdocuments8Infosys — Recruitment Fraud Alert0.6
job-unrealistic-dailyUnrealistic pay for simple workjob22MEA advisory — Indian nationals travelling to Cambodia and South-East Asia for jobs (reported by Akashvani News)0.75
job-no-experience-high-payNo experience or qualification, high payjob15MEA advisory — Indian nationals travelling to Cambodia and South-East Asia for jobs (reported by Akashvani News)0.7
job-task-templateTemplate of a task-based 'job'job18TCS — Recruitment Fraud Alert (India careers)0.7
job-guaranteeGuaranteed job, 100% placement or direct joiningjob12TCS — Recruitment Fraud Alert (India careers)0.7
job-overseas-agentOverseas job through an agent, visa or ticket promisedjob15MEA advisory — Indian nationals travelling to Cambodia and South-East Asia for jobs (reported by Akashvani News)0.8
job-online-test-feeOnline test or admit card as the route to a jobjob12TCS — Recruitment Fraud Alert (India careers)0.6
imp-governmentGovernment or public-sector job claimedimpersonation20National Cyber Crime Reporting Portal and helpline 19300.7
imp-brand-referenceNamed company used as a referenceimpersonation10TCS — Recruitment Fraud Alert (India careers)0.65
imp-employee-idEmployee ID card or offer letter sent as proofimpersonation10TCS — Recruitment Fraud Alert (India careers)0.6

Structural signals outside this table: free-mail recruiter 20 (30 when a brand is named), lookalike recruiter domain 35, recruiter domain on a low-cost TLD 12, job link on a chat app 20, shortened job link 10, job link imitating a verified domain 30, job link not on the named company's site 15, job site on a low-cost TLD 10, brand named but address not its domain 30, recruiter domain not the named company's 20.

3. Evidence limitations

4. False positives and false negatives

False positives — a genuine offer scored MEDIUM or above: a small firm or consultant recruiting from Gmail; a genuine onboarding email listing Aadhaar, PAN and bank details for payroll; a job description that quotes a high daily rate for skilled contract work; a recruiter on a new corporate domain; a company fraud-alert page pasted in whole (its negations cancel same-line fee matches only). False negatives — a fraud scored LOW or INSUFFICIENT: a message that never mentions money until later; a fee demand phrased in a way the patterns do not cover; a lookalike domain of a company not in the dataset; a screenshot the browser could not read. This is why the level is a prompt to verify through the official channel, not a verdict.

5. “Unverified” is not “fraudulent”

Unverified means this page could not confirm something from its datasets. Not verified (✕) means the evidence contradicts the claim — the domain imitates a real one, the link opens a chat app. High-risk indicators detected means the message contains the specific patterns the employers and the government name as fraud. The page never says that a person or company is a fraudster: it shows the evidence and the arithmetic, names what it could not check, and tells you which official channel settles it.

6. Privacy

Nothing you paste, attach or type is transmitted, logged or stored. The engine, the datasets and the PDF reader are loaded with the page; the analysis runs in your tab; the site's Content Security Policy permits the page no connection to any other origin. Mobile numbers, Aadhaar numbers and PAN in your own text are masked in the result. No outcome logging is implemented in this version; if it is added it will be anonymised and limited to structured signals (which pattern ids fired, the level), never the text.

7. Datasets and sources

Each dataset records its source, source URL, publisher, collection date, effective date, confidence, methodology and version. Sources:

Reporting channels recorded: National Cyber Crime Reporting Portal · Helpline 1930 · Sanchar Saathi — Chakshu · eMigrate (MEA) · The company's own fraud-alert or careers contact. A dataset is never edited in place after publication: a change is a new version, the previous file is archived under fraud/historical/ and checksummed here.

Job Fraud Intelligence · Career Intelligence methodology · Career data catalogue