Help Center for
TopicsGuidesWebinarsContact

Recognizing Phishing Scams

Scammers may pose as Indeed to trick you into sharing personal information. This could be your password or a two-factor authentication (2FA) code. They use this information to access your account and sensitive data. This tactic is called phishing.

Recognizing phishing tactics is the best way to protect yourself and your account. In this article, we'll share a few common scams. We'll also explain how to keep your account safe, and what to do if you suspect a phishing scam.

Common phishing tactics

Copied logos and design

  • Scammers copy Indeed's logo, colors, and email format to make their messages seem real.
  • A recognizable Indeed logo doesn't always mean the email came from Indeed.

Urgent or threatening messages

  • Scammers create pressure by demanding immediate action.
  • They may threaten to suspend your account or delete your data if you don't respond fast.
    • Example: "We'll disable your account in 24 hours unless you verify your information now."

Suspicious links

  • Phishing emails often include links that lead to fake websites or mobile app stores.
  • They're designed to steal your sign-in information or install malware on your device.

How to check a link

  • Hover over the link without clicking to see where it leads.
  • Check for misspelled domains like "Lndeed.com" or "ind33d.com" instead of "indeed.com.”
  • Don't click if the link doesn't go to an indeed.com domain.
Some fake sites may redirect you to the real site after you enter your credentials. This makes the scam harder to detect.

Fake email addresses

Scammers use email addresses that look like Indeed's official domains with slight variations.

Official Indeed domains

  • @indeed.com
  • @indeedemail.com

Fake domains

  • @ihdeedemployer.com
  • @Indeed.com (with a lowercase "L")
  • Any other variation
If you're unsure about an email, sign in to indeed.com instead of clicking links in the message.

Requests for personal information

Scammers may ask for your information through:

  • Web forms or surveys
  • Email replies
  • Text messages (also called "smishing")

What Indeed will never ask for

  • Your password outside of the official sign-in page on indeed.com
  • Your 2FA code
  • Downloads of software to access your account

Protecting your account

Enable two-factor authentication (2FA)

Use strong, unique passwords

Create a password that:

  • Is at least 8 characters long
  • Includes a mix of letters, numbers, and symbols
  • Is different from the passwords you use on other sites

Review your account often

Check your account activity for any suspicious behavior, such as:

  • Jobs you didn't post
  • Messages you didn't send
  • Applications you didn't submit
  • Changes to your profile you didn't make

What to do if you suspect phishing

If you receive a suspicious email or text

  1. Don't click any links or download any attachments.
  2. Don't reply to the message.
  3. Mark it as spam.
  4. Delete it immediately.

If you think your account was compromised

  1. Change your password immediately by signing in to your Indeed account.
  2. Enable 2FA if you haven't already.
  3. Contact our support team right away.

Learn more in our article Think You Were Hacked? Here's What to Do.

Report suspicious activity

Help protect the Indeed community by reporting phishing attempts and suspicious activity. Contact our support team if you:

  • Notice unauthorized activity on your account
  • Encounter a fake Indeed website or job posting
  • Have questions about whether a communication is legitimate
Was this article helpful?

More in this topic

Using Two-Factor Authentication (2FA) on IndeedSigning In to Your Indeed Employer AccountFAQs: Opening an Indeed AccountUpdating Business Contact DetailsChange Account Owner
Still need help?Send us a message and our team will follow up.
Submit a request
Recognizing Phishing Scams