Methodology
About the technology
CareerSteer does not guess, and it does not rate employers by reputation or opinion. Every assessment is assembled from records that exist independently of the message you received and independently of us. This page documents exactly which records we read, what each one can and cannot prove, and how they combine into a single risk index.
1. Registration data (RDAP)
Every internet domain is recorded by the registry that operates its extension. We query those registries directly through RDAP, the successor to WHOIS, and read the registration date, the expiry date, the sponsoring registrar and the ownership status.
Registration age is the single most useful objective signal in employment fraud. Criminal infrastructure is disposable: a domain used to impersonate an employer is typically weeks or a few months old, because older domains are reported and suspended. A genuine employer has normally held its domain for many years. Where ownership details are withheld behind a privacy service — lawful and extremely common — we state that the owner could not be identified rather than treating it as guilt.
2. Mail authentication and transport records
We resolve the domain's published DNS records over an encrypted DNS-over-HTTPS channel and examine three things: whether mail exchangers (MX) exist at all, whether an SPF policy declares which servers may send on the domain's behalf, and whether a DMARC policy tells receiving servers what to do with mail that fails those checks.
A hiring domain with no mail exchanger cannot receive company email. A domain with no SPF or DMARC policy is trivially easy to forge, which is the mechanism behind recruiter impersonation. These are structural facts about the domain, not inferences about intent.
3. Transport security
We attempt a TLS handshake with the domain's web host. A handshake that completes proves a valid certificate chain is presented for that exact name. A handshake that fails tells you there is no secured website behind an address that is being used to recruit.
4. Public corporate registry cross-reference
Where the message names a company, we search the SEC EDGAR filer register — the public record of entities that file with the United States Securities and Exchange Commission — and report any match together with its Central Index Key.
We are explicit about the limits of this check: the overwhelming majority of legitimate employers are private and do not appear in EDGAR. An absent match is therefore not evidence of fraud. It means only that the name could not be confirmed against a public register, and that confirmation must come from another independent source, such as a national company register or the employer's own published switchboard.
5. Textual behavioral analytics
The text itself is evaluated against documented fraud scripts: advance-fee requests, counterfeit-check and equipment-reimbursement schemes, untraceable payment rails, requests for identity or banking data before a signed offer, recruitment conducted exclusively in a consumer chat application, manufactured urgency, and secrecy instructions.
Each matched pattern is reported with the reason it matters, so you can judge the evidence yourself rather than accepting a score on trust.
6. How the index is produced, and what it is not
Each confirmed marker contributes a fixed weight to a 0–100 index. Below 22 the assessment reads Verified / Low Risk, up to 55 it reads Unverified / Proceed with Caution, and above that it reads High Risk / Confirmed Flags. The thresholds are deliberately conservative: we would rather ask you to verify an honest employer than reassure you about a fraudulent one.
An CareerSteer report is an evidence summary, not an adjudication. It cannot read a private employer's internal records, and it cannot confirm that a named individual works where they claim. Final verification must always be made through official, independently sourced channels — which is exactly what the safe verification guide walks you through.