WFH.teamOpen app
Job Scam RadarMethodology / version 1.0

An evidence review, not an accusation engine.

The radar combines deterministic language rules, employer and job records, domain infrastructure, and thresholded community reports. It explains every scored signal and treats unavailable evidence as unknown.

01

Inputs and retention

Users may submit a job URL, recruiter email or domain, job description, or message. Raw descriptions, messages, recruiter addresses, email local parts, and URL query strings are not stored. We retain the canonical URL, analyzed base domain, derived score and reasons, and keyed one-way fingerprints used to detect repeated descriptions.

02

Scored signals

Rules cover fake checks, applicant-funded equipment, payment and cryptocurrency requests, identity or banking requests, task jobs, reshipping, informal chat-only recruiting, urgency, unrealistic compensation, employer-domain mismatches, lookalike domains, young domains, repeat patterns, and community reports.

03

Verification checks

The checker compares canonical URLs with active WFH.team job inventory, published employer domains and careers links, and public RDAP registration data. Domain age is cached for seven days. Page-fetch redirects are revalidated to prevent access to private network addresses.

About ICANN RDAP
04

Score bands

  • 0–24 Low: no strong pattern detected.
  • 25–54 Caution: details require independent verification.
  • 55–79 High: significant warning signs.
  • 80–100 Critical: multiple or severe scam mechanics.

A critical language pattern creates a minimum score of 70. Scores are capped at 100. A low score never guarantees legitimacy.

05

Community publication

Reports collect categories only, keyed by a one-way browser/network fingerprint to reduce repeat submissions. Domains remain private while pending and enter the public ledger only after independent WFH.team review or at least three reports. Community-flagged entries are explicitly labeled as not independently verified.

06

Weekly trends

Weekly totals and breakdowns publish only after at least 10 checks. Community report totals below three are suppressed. The historical dataset contains aggregate counts and reason codes, never submitted messages, email addresses, identity documents, or banking details.

Open versioned trend dataset
07

Limitations

Domains can be compromised, legitimate companies can use third-party recruiting systems, career listings can move, RDAP records can be incomplete, and language varies. Automated checks cannot establish criminal intent, validate a person’s identity, or replace law enforcement, legal advice, or direct employer verification.

08

What to do next

Contact the employer using details you found independently. Do not pay for a job or deposit a check and forward money. If money or identity information was sent, contact the payment provider or financial institution immediately and report the incident.

FTC job-scam guidance ReportFraud.ftc.gov

Revision history: Version 1.0, August 11, 2026 — initial public methodology.