Real vendors use company domains; scammers use Gmail and lookalike addresses
The fastest filter: check the email domain. A recruiter claiming to represent Accenture will send from @accenture.com, not @accenture-hiring.com or @gmail.com. Scammers register domains one character off (replacing "l" with "1", swapping "o" for "0") or use free email providers to appear as third-party recruiters.
Verify the domain by visiting the vendor's official careers page. Copy the email address format from their site, then compare it character-by-character with the one in your inbox. One typo in the domain name is the tell.
Real vendors ask for your resume and experience; scammers ask for payment upfront
Legitimate C2C placements never charge applicants. If an email asks you to pay a fee—registration, processing, background check, credential verification—it's a scam. Vendors make money from their clients, not from contractors.
Red flag phrases: "processing fee," "deposit required," "one-time credential charge," "visa sponsorship fee." None of these exist in the real C2C market. A real email asks for your resume, your rate, your availability, and your tech stack. That's it.
Real vendors reference specific skills or use your name; scammers mass-blast templates
Personalized emails mention something about your background—a project, a technology, a job title you posted. They use your actual name. Scammers send identical messages to hundreds of addresses with placeholder text like "[Your Name]" or generic greetings like "Hi there."
Check the email header. Look for "BCC" recipients. If you see dozens of addresses in the copy line, it's a mass blast. Real recruiters send individual emails or use a proper email platform with suppressed recipient lists.
Real vendors include contract terms; scammers hide the deal structure
Legitimate C2C emails mention the bill rate (or ask for your expected rate), contract length, and client location—even if vague. They reference whether it's remote, hybrid, or onsite. C2C contracts require clarity on structure from the start.
Scams avoid specifics entirely. They say things like "unlimited earning potential," "high-paying remote work," or "we'll send you details after you apply." Real vendors know that C2C contractors ask hard questions about rates, markup, and terms upfront.
Real vendors can be verified through LinkedIn; scammers disappear
Search the recruiter's name on LinkedIn. A real vendor has a profile with a work history, endorsements, and recommendations. Check if they work for the company they claim to represent. If the profile was created last month or has no connections, it's suspicious.
Better yet: reach out directly to the vendor company through their official site. Call their main recruiting line or visit their careers page. Ask if they have a recruiter with that name actively placing C2C contractors. If they say no, you have your answer.
Real vendors follow up after radio silence; scammers vanish after you ask questions
Email the "recruiter" back with specific questions: "What's the bill rate?" "Who is the end client?" "How long is the contract?" "What are the payment terms?" Real recruiters respond within hours. Scammers either ghost or send you to a suspicious link.
If they reply with a link to "complete your application" or a request to download software, don't click. Real application processes use job boards or established recruiting platforms—not random URLs or file downloads.
One more layer: use an AI recruiter that moves faster than the scammers
The C2C market moves at the speed of application velocity. The longer you spend verifying whether an email is real, the longer other contractors are applying to legitimate roles. GiraffyReach detects fresh C2C postings the moment they hit vendor boards and auto-applies before the spam and scams have time to surface in your inbox.
For roles you find on your own, keep this checklist bookmarked. It takes 30 seconds to spot a scam if you know the pattern. Save those 30 seconds, and you save yourself from credential theft and financial loss.