Is This Brand Collaboration Legit? Verify It Before You Reply
Do not click, pay, or share personal data yet. Find the brand’s real website yourself, compare the sender’s full domain, and confirm the person or agency through a contact channel you found independently. Treat requests for upfront fees, refunding an overpayment, passwords, verification codes, or unexpected downloads as stop signs. A matching domain, verified profile, SPF/DKIM pass, or clean link scan is only a signal—not proof. Continue only when the company confirms the outreach and the scope, pay, rights, and legal entity are clear in writing.
01 · THE DECISION PATH
The three checks that make an offer worth continuing
A polished message is not the thing you are trying to verify. You are trying to establish three separate facts, in order: Identity → Authority → Offer. A deal moves forward only when the evidence survives all three checks.
- 01
Identity: who sent this?
Inspect the actual address, full domain, reply path, message authentication, and destination of every link without using those signals as a verdict.
- 02
Authority: can they represent this campaign?
Ask the brand through a contact route you found independently to confirm the exact person or agency and the exact campaign.
- 03
Offer: does the commercial path make sense?
Match the confirmed party to the contracting and paying entity, then put scope, compensation, rights, payment, and data requests in writing.
02 · IDENTITY
1. Verify who sent the offer without using their links
Start outside the message. Type the brand name into your own browser or use a known bookmark, find its official website, and compare the sender’s complete domain character by character. Check the address after the final @, not just the display name. Expand the message details to see whether the visible From address and Reply-To address differ. A personal email address, lookalike spelling, extra word, or unfamiliar top-level domain deserves independent verification; none is a universal scam verdict by itself.
Do not call the phone number, reply to the address, scan the QR code, or open the “brief” from the incoming message while you are still identifying the sender. The FTC’s creator-specific warning describes fake offers that impersonate known brands and then ask creators for personal or financial information. Its phishing guidance recommends contacting a company through a number or website you know is real rather than using the message’s contact path.
FTC: Influencers, spot this job scamFTC: How to recognize and avoid phishing scamsGmail Help: Avoid and report phishing emails
Read authentication as a routing signal, not identity proof
In Gmail, message details can show whether a message is authenticated and which domains mailed and signed it. Passing SPF or DKIM can support the conclusion that the sending system was authorized for that domain. It does not tell you that the individual is assigned to the campaign, that an inbox has not been compromised, or that the offer is commercially sound. Failure or missing authentication is a reason to pause and investigate—not a substitute for asking the brand.
Gmail Help: Check if your Gmail message is authenticatedFBI: Business Email Compromise
Use domain and link checks to find conflicts
ICANN Lookup can expose registration data that is available for a domain, including dates. A newly registered lookalike domain is a useful reason to stop and verify. An older domain or a privacy-protected registrant does not prove who controls the mailbox. Likewise, Google Safe Browsing’s site-status check can surface a known warning at that moment; a clean result is not a safety certificate. HTTPS only says a connection is encrypted. It does not authenticate the business behind the page.
ICANN Lookup: Frequently asked questionsGoogle Transparency Report: Safe Browsing site status FAQ
04 · OFFER
3. Match the legal entity, payment path, and data request
Once authority is confirmed, compare the confirmation with the paperwork. The agreement should identify the contracting entity. The invoice instructions should identify the paying entity. If those names differ because an agency or payment processor is involved, ask the independently verified brand contact to explain the relationship in writing. Reconfirm any last-minute change to bank details or payment instructions through the same independent route.
| Offer field | What should be clear in writing | What needs another check |
|---|---|---|
| Parties | Contracting entity, paying entity, agency role | Names or countries that do not match confirmation |
| Work | Deliverables, platforms, dates, revisions, approvals | Vague work paired with urgent onboarding |
| Money | Fee, currency, payment trigger, method, due date | Upfront payment by you or an overpayment to refund |
| Rights | Usage, duration, territory, exclusivity, cancellation | Open-ended rights or terms changed outside the draft |
| Data | Requester, purpose, fields, and secure submission route | Credentials, one-time codes, full card details, or excess data |
Never pay a fee to release compensation, buy gift cards, or return part of an “overpayment.” The FTC warns that fake checks can appear in an account before a bank later determines they are fake; sending money back can leave you responsible for the loss. A screenshot, pending balance, or funds appearing is not final proof that payment has cleared.
FTC: How to spot, avoid, and report fake check scamsFBI: Business Email Compromise
Minimize data before verification; contextualize it after
Before identity, authority, payer, and purpose are confirmed, do not send a passport, tax identifier, bank login, password, one-time verification code, or full payment-card details. After confirmation, legitimate onboarding may require payment or tax information through a secure route. The right form depends on the parties, work, and jurisdiction. A Form W-9 is a specific U.S. tax context, not a universal sign that every collaboration is real. Ask a qualified adviser about your situation rather than using this screening guide as tax advice.
05 · DECISION TABLE
Sort the evidence into stop, pause, and supporting signals
Signals become dangerous when they are treated as a score. One convincing clue cannot cancel a direct contradiction. Use this table to choose the next action, not to calculate a legitimacy percentage.
| Decision | Evidence class | Examples | Next action |
|---|---|---|---|
| STOP | Hard stop | Brand independently denies the outreach; sender demands an upfront fee or overpayment refund; asks for passwords, full card details, or one-time codes; pushes an unknown login portal or unexpected download before confirmation | Stop contact, preserve evidence, and report |
| VERIFY | Pause and verify | Lookalike or new domain, personal email, unknown agency, Reply-To mismatch, pressure, or an off-platform-only invitation | Contact the brand through an independent route |
| VERIFY | Supporting only | Same-domain email, professional signature, logo, LinkedIn profile, verification badge, platform project, contract, authentication pass, clean scan, or apparent funds | Record it, but do not continue on this alone |
| CONTINUE | Proceed condition | Brand independently confirms the person or agency and campaign; contracting and paying entities align; scope, pay, rights, and payment path are clear in writing | Move to commercial and contract review |
CONTINUE does not mean “guaranteed.” It means the offer has enough verified coherence to justify the next review. You can still decline because the fee, rights, exclusivity, workload, safety, or contract terms are wrong for you.
06 · SAVE THE EVIDENCE
Build a Brand Offer Verification Record
Keep one record for the whole decision instead of relying on a clean-looking inbox thread. Save the original message and full headers before forwarding or reporting it. Record every contact route you found independently, the date you used it, who answered, and the exact scope of what they confirmed. Preserve contract versions and payment changes rather than overwriting them.
Technical checks belong in the record with their limits. Note the mailed-by and signed-by domains, any authentication result, the ICANN Lookup data you inspected, and the Safe Browsing status you saw. Then write “supporting signal only” beside them. That boundary prevents a later clean result from being mistaken for brand authorization.
DATE RECEIVED: CLAIMED BRAND / CAMPAIGN: SENDER NAME / FULL EMAIL / AGENCY: ORIGINAL EVIDENCE Message saved: Full headers saved: Links or files requested (do not open here): IDENTITY SIGNALS — SUPPORTING ONLY From / Reply-To / mailed-by / signed-by: Authentication result and limit: Domain registration data and limit: Safe Browsing result and limit: AUTHORITY CONFIRMATION Independent brand contact route: Date / person who answered: Exact person, agency, and campaign confirmed: OFFER ALIGNMENT Contracting entity / paying entity: Scope / fee / currency / due date: Usage rights / duration / territory / exclusivity: Data requested / purpose / secure route: DECISION: STOP / VERIFY / CONTINUE REASON AND TIMESTAMP:
Reopen the record whenever the sender, agency, legal entity, bank instructions, document host, or data request changes. The prior confirmation does not automatically cover a new party or path. A dated record is also more useful to your email provider, financial institution, platform, or law enforcement if you need to report what happened.
07 · LIMIT THE DAMAGE
If you already clicked, paid, or shared information
Stop using the original message as your navigation path. Save it and related receipts, screenshots, headers, phone numbers, domains, wallet addresses, and transaction identifiers. Then act through the real service, bank, card issuer, or platform you reach independently. Recovery steps depend on what you did; no single reset or report covers every exposure.
If you clicked or entered credentials
Close the page. If you downloaded or installed something, follow your device or organization’s trusted security guidance and run an appropriate scan. If you entered a password, go to the real service directly, change the affected password, review active sessions and recovery details, and enable stronger sign-in protection where available. Protect the email account that can reset your other accounts. If you supplied a one-time code, contact the affected service promptly. A password change is important, but it does not prove every session, forwarding rule, device, or connected account is safe.
FTC: How to recognize and avoid phishing scamsFTC: What to do if you were scammedGmail Help: Avoid and report phishing emails
If you paid or returned an overpayment
Contact the bank, card issuer, wire service, gift-card company, or payment app immediately. Say the transaction was connected to a suspected scam and ask what reversal or dispute options remain. Do not send more money to someone offering to recover the first payment. Report the incident through the FTC’s reporting path; business-email compromise and wire fraud can also be reported through the FBI’s channels. Speed can matter, but a report or reversal request does not guarantee recovery.
FTC: How to spot, avoid, and report fake check scamsFTC: What to do if you were scammedFBI: Business Email Compromise
If you shared identity, tax, or financial information
Use the FTC recovery guidance to match the response to the data exposed. Contact the relevant financial institution or agency through its real site, replace credentials where applicable, and monitor the affected accounts. For tax or identity documents, get advice appropriate to your country and facts. Keep the Brand Offer Verification Record with every report and case number so you can update institutions consistently.
08 · SOURCE LEDGER
Sources and method
Kabo checked the official sources below on September 1, 2026. FTC, FBI, Google, ICANN, YouTube, TikTok, and IRS material supports the specific fraud patterns, authentication limits, lookup functions, platform workflows, recovery steps, and tax context cited beside the relevant claims. Platform interfaces and guidance can change, so verify the current instructions on the linked official page before acting.
Identity → Authority → Offer, the STOP / VERIFY / CONTINUE decision table, the confirmation wording, and the Brand Offer Verification Record are Kabo editorial syntheses. They are not an official scam score, a certification that an offer is safe, a payment guarantee, or legal or tax advice. The method is intentionally conservative: resolve contradictions first, use technical and public-profile signals only as support, and rely on independent brand confirmation before commercial review.
- FTC: Influencers, spot this job scam
- FTC: How to recognize and avoid phishing scams
- FTC: How to spot, avoid, and report fake check scams
- FTC: What to do if you were scammed
- Gmail Help: Avoid and report phishing emails
- Gmail Help: Check if your Gmail message is authenticated
- FBI: Business Email Compromise
- ICANN Lookup: Frequently asked questions
- Google Transparency Report: Safe Browsing site status FAQ
- YouTube Help: Brand partner access
- TikTok for Business: Working with creators on TikTok One
- IRS: Forms and associated taxes for independent contractors