Skip to guide
BRAND OFFER VERIFICATION
12 primary sources

Is This Brand Collaboration Legit? Verify It Before You Reply

Do not click, pay, or share personal data yet. Find the brand’s real website yourself, compare the sender’s full domain, and confirm the person or agency through a contact channel you found independently. Treat requests for upfront fees, refunding an overpayment, passwords, verification codes, or unexpected downloads as stop signs. A matching domain, verified profile, SPF/DKIM pass, or clean link scan is only a signal—not proof. Continue only when the company confirms the outreach and the scope, pay, rights, and legal entity are clear in writing.

01 · THE DECISION PATH

The three checks that make an offer worth continuing

A polished message is not the thing you are trying to verify. You are trying to establish three separate facts, in order: Identity → Authority → Offer. A deal moves forward only when the evidence survives all three checks.

  1. 01

    Identity: who sent this?

    Inspect the actual address, full domain, reply path, message authentication, and destination of every link without using those signals as a verdict.

  2. 02

    Authority: can they represent this campaign?

    Ask the brand through a contact route you found independently to confirm the exact person or agency and the exact campaign.

  3. 03

    Offer: does the commercial path make sense?

    Match the confirmed party to the contracting and paying entity, then put scope, compensation, rights, payment, and data requests in writing.

02 · IDENTITY

1. Verify who sent the offer without using their links

Start outside the message. Type the brand name into your own browser or use a known bookmark, find its official website, and compare the sender’s complete domain character by character. Check the address after the final @, not just the display name. Expand the message details to see whether the visible From address and Reply-To address differ. A personal email address, lookalike spelling, extra word, or unfamiliar top-level domain deserves independent verification; none is a universal scam verdict by itself.

Do not call the phone number, reply to the address, scan the QR code, or open the “brief” from the incoming message while you are still identifying the sender. The FTC’s creator-specific warning describes fake offers that impersonate known brands and then ask creators for personal or financial information. Its phishing guidance recommends contacting a company through a number or website you know is real rather than using the message’s contact path.

FTC: Influencers, spot this job scamFTC: How to recognize and avoid phishing scamsGmail Help: Avoid and report phishing emails

Read authentication as a routing signal, not identity proof

In Gmail, message details can show whether a message is authenticated and which domains mailed and signed it. Passing SPF or DKIM can support the conclusion that the sending system was authorized for that domain. It does not tell you that the individual is assigned to the campaign, that an inbox has not been compromised, or that the offer is commercially sound. Failure or missing authentication is a reason to pause and investigate—not a substitute for asking the brand.

Gmail Help: Check if your Gmail message is authenticatedFBI: Business Email Compromise

Use domain and link checks to find conflicts

ICANN Lookup can expose registration data that is available for a domain, including dates. A newly registered lookalike domain is a useful reason to stop and verify. An older domain or a privacy-protected registrant does not prove who controls the mailbox. Likewise, Google Safe Browsing’s site-status check can surface a known warning at that moment; a clean result is not a safety certificate. HTTPS only says a connection is encrypted. It does not authenticate the business behind the page.

ICANN Lookup: Frequently asked questionsGoogle Transparency Report: Safe Browsing site status FAQ

03 · AUTHORITY

2. Confirm that the person or agency is authorized

Identity and authority are different. A real agency may not represent this brand. A real employee may not own this campaign. A LinkedIn profile, verified social account, professional signature, logo, or matching company email is useful context, but none answers the decisive question: did the brand authorize this person or agency for this outreach?

Find a press, partnerships, creator, support, or general contact route on the brand’s official website or verified account. Send a short confirmation without forwarding sensitive documents. Name the person, their full email address, and the campaign. If the brand confirms through that independently found route, save the response. If it denies the outreach, stop communicating with the sender. If it cannot confirm, keep the decision at VERIFY rather than filling the gap with social proof.

STATIC CONFIRMATION TEMPLATEAsk through a channel you found independently
I received an offer from [name/email] about [campaign]. Before I open documents or share onboarding information, could you confirm whether this person or agency is authorized to represent your brand on this campaign?

A campaign visible in a platform workflow can add corroboration. YouTube documents brand partner access requests, and TikTok documents creator invitations and campaign work inside TikTok One. These records support only the activity the platform shows. Their presence does not guarantee an off-platform contract or payment, and their absence does not by itself make an email campaign fake.

YouTube Help: Brand partner accessTikTok for Business: Working with creators on TikTok One

04 · OFFER

3. Match the legal entity, payment path, and data request

Once authority is confirmed, compare the confirmation with the paperwork. The agreement should identify the contracting entity. The invoice instructions should identify the paying entity. If those names differ because an agency or payment processor is involved, ask the independently verified brand contact to explain the relationship in writing. Reconfirm any last-minute change to bank details or payment instructions through the same independent route.

Match each part of the offer before accepting or onboarding
Offer fieldWhat should be clear in writingWhat needs another check
PartiesContracting entity, paying entity, agency roleNames or countries that do not match confirmation
WorkDeliverables, platforms, dates, revisions, approvalsVague work paired with urgent onboarding
MoneyFee, currency, payment trigger, method, due dateUpfront payment by you or an overpayment to refund
RightsUsage, duration, territory, exclusivity, cancellationOpen-ended rights or terms changed outside the draft
DataRequester, purpose, fields, and secure submission routeCredentials, one-time codes, full card details, or excess data

Never pay a fee to release compensation, buy gift cards, or return part of an “overpayment.” The FTC warns that fake checks can appear in an account before a bank later determines they are fake; sending money back can leave you responsible for the loss. A screenshot, pending balance, or funds appearing is not final proof that payment has cleared.

FTC: How to spot, avoid, and report fake check scamsFBI: Business Email Compromise

Minimize data before verification; contextualize it after

Before identity, authority, payer, and purpose are confirmed, do not send a passport, tax identifier, bank login, password, one-time verification code, or full payment-card details. After confirmation, legitimate onboarding may require payment or tax information through a secure route. The right form depends on the parties, work, and jurisdiction. A Form W-9 is a specific U.S. tax context, not a universal sign that every collaboration is real. Ask a qualified adviser about your situation rather than using this screening guide as tax advice.

IRS: Forms and associated taxes for independent contractors

05 · DECISION TABLE

Sort the evidence into stop, pause, and supporting signals

Signals become dangerous when they are treated as a score. One convincing clue cannot cancel a direct contradiction. Use this table to choose the next action, not to calculate a legitimacy percentage.

The strongest verified evidence determines the next action
DecisionEvidence classExamplesNext action
STOPHard stopBrand independently denies the outreach; sender demands an upfront fee or overpayment refund; asks for passwords, full card details, or one-time codes; pushes an unknown login portal or unexpected download before confirmationStop contact, preserve evidence, and report
VERIFYPause and verifyLookalike or new domain, personal email, unknown agency, Reply-To mismatch, pressure, or an off-platform-only invitationContact the brand through an independent route
VERIFYSupporting onlySame-domain email, professional signature, logo, LinkedIn profile, verification badge, platform project, contract, authentication pass, clean scan, or apparent fundsRecord it, but do not continue on this alone
CONTINUEProceed conditionBrand independently confirms the person or agency and campaign; contracting and paying entities align; scope, pay, rights, and payment path are clear in writingMove to commercial and contract review

CONTINUE does not mean “guaranteed.” It means the offer has enough verified coherence to justify the next review. You can still decline because the fee, rights, exclusivity, workload, safety, or contract terms are wrong for you.

06 · SAVE THE EVIDENCE

Build a Brand Offer Verification Record

Keep one record for the whole decision instead of relying on a clean-looking inbox thread. Save the original message and full headers before forwarding or reporting it. Record every contact route you found independently, the date you used it, who answered, and the exact scope of what they confirmed. Preserve contract versions and payment changes rather than overwriting them.

Technical checks belong in the record with their limits. Note the mailed-by and signed-by domains, any authentication result, the ICANN Lookup data you inspected, and the Safe Browsing status you saw. Then write “supporting signal only” beside them. That boundary prevents a later clean result from being mistaken for brand authorization.

SELECTABLE RECORDBrand Offer Verification Record
DATE RECEIVED:
CLAIMED BRAND / CAMPAIGN:
SENDER NAME / FULL EMAIL / AGENCY:

ORIGINAL EVIDENCE
Message saved:
Full headers saved:
Links or files requested (do not open here):

IDENTITY SIGNALS — SUPPORTING ONLY
From / Reply-To / mailed-by / signed-by:
Authentication result and limit:
Domain registration data and limit:
Safe Browsing result and limit:

AUTHORITY CONFIRMATION
Independent brand contact route:
Date / person who answered:
Exact person, agency, and campaign confirmed:

OFFER ALIGNMENT
Contracting entity / paying entity:
Scope / fee / currency / due date:
Usage rights / duration / territory / exclusivity:
Data requested / purpose / secure route:

DECISION: STOP / VERIFY / CONTINUE
REASON AND TIMESTAMP:

Reopen the record whenever the sender, agency, legal entity, bank instructions, document host, or data request changes. The prior confirmation does not automatically cover a new party or path. A dated record is also more useful to your email provider, financial institution, platform, or law enforcement if you need to report what happened.

07 · LIMIT THE DAMAGE

If you already clicked, paid, or shared information

Stop using the original message as your navigation path. Save it and related receipts, screenshots, headers, phone numbers, domains, wallet addresses, and transaction identifiers. Then act through the real service, bank, card issuer, or platform you reach independently. Recovery steps depend on what you did; no single reset or report covers every exposure.

If you clicked or entered credentials

Close the page. If you downloaded or installed something, follow your device or organization’s trusted security guidance and run an appropriate scan. If you entered a password, go to the real service directly, change the affected password, review active sessions and recovery details, and enable stronger sign-in protection where available. Protect the email account that can reset your other accounts. If you supplied a one-time code, contact the affected service promptly. A password change is important, but it does not prove every session, forwarding rule, device, or connected account is safe.

FTC: How to recognize and avoid phishing scamsFTC: What to do if you were scammedGmail Help: Avoid and report phishing emails

If you paid or returned an overpayment

Contact the bank, card issuer, wire service, gift-card company, or payment app immediately. Say the transaction was connected to a suspected scam and ask what reversal or dispute options remain. Do not send more money to someone offering to recover the first payment. Report the incident through the FTC’s reporting path; business-email compromise and wire fraud can also be reported through the FBI’s channels. Speed can matter, but a report or reversal request does not guarantee recovery.

FTC: How to spot, avoid, and report fake check scamsFTC: What to do if you were scammedFBI: Business Email Compromise

If you shared identity, tax, or financial information

Use the FTC recovery guidance to match the response to the data exposed. Contact the relevant financial institution or agency through its real site, replace credentials where applicable, and monitor the affected accounts. For tax or identity documents, get advice appropriate to your country and facts. Keep the Brand Offer Verification Record with every report and case number so you can update institutions consistently.

08 · SOURCE LEDGER

Sources and method

Kabo checked the official sources below on September 1, 2026. FTC, FBI, Google, ICANN, YouTube, TikTok, and IRS material supports the specific fraud patterns, authentication limits, lookup functions, platform workflows, recovery steps, and tax context cited beside the relevant claims. Platform interfaces and guidance can change, so verify the current instructions on the linked official page before acting.

Identity → Authority → Offer, the STOP / VERIFY / CONTINUE decision table, the confirmation wording, and the Brand Offer Verification Record are Kabo editorial syntheses. They are not an official scam score, a certification that an offer is safe, a payment guarantee, or legal or tax advice. The method is intentionally conservative: resolve contradictions first, use technical and public-profile signals only as support, and rely on independent brand confirmation before commercial review.