Email red flags in job applications
An email address is the cheapest part of a fake identity. Anyone can make a hundred in an afternoon, so an address on its own rarely proves anything. But addresses made in bulk have shapes, and the shapes are easy to see once you know them. This page lists the ones worth checking in an applicant export, what each means, and how ApplySift scores them. The weights below are the ones on the signals page; a row reaches Review at two points and Likely fraud at five.
1. A throwaway domain
Mailinator, Guerrilla Mail, 10 Minute Mail, YOPmail and their relatives hand out inboxes that expire in minutes and need no sign-up. They exist for one-off verifications, not for an inbox you expect an interview invitation to land in. Nobody who wants the job applies from one.
How ApplySift scores it: email-disposable, three points. The list is deliberately short, around twenty domains, because the long public lists of disposable providers carry false positives; it is matched on the domain and any parent domain, so a subdomain of a listed provider counts too. Three points puts the row in Review by itself. With almost anything else on the row it is Likely fraud.
2. A fresh-account provider
A new outlook.com, hotmail.com, live.com or msn.com account takes about a minute and asks for nothing. Millions of real people use these addresses, so a Hotmail address is not a red flag; it is a faint one. What makes it worth a point is the company it keeps. In the one real applicant pool the weights were set on, nine in ten Outlook addresses also carried a VOIP wholesaler phone number, against six in ten of the pool overall (the figures are on the signals page).
How ApplySift scores it: email-provider, one point, for exactly those four domains. Gmail and Yahoo are not on the list, and neither are regional variants such as outlook.co.uk. It will never move a row on its own.
3. Digits in the local part
Real handles have a few digits at most: a birth year, a lucky number, the 2 that Gmail suggested. Addresses generated to stay unique carry more, because the generator appends a counter or a random run: michael.carter48213@, j.nguyen2048173@. Sort the email column and the pattern jumps out, dozens of names each followed by five, six or seven digits.
How ApplySift scores it: email-digits, one point at five or more digits in the local part, two points at seven or more. All digits are counted, not just the trailing run, so jsmith1987 (four) passes and j12smith345 (five) does not.
4. No trace of the applicant's name
Most people's address contains some piece of their name. A generated address often does not, because the name and the address were produced separately: the application says Priya Raman and the address is bluewind7742@. Plenty of real people have a handle unrelated to their name, which is why this is a weak signal, but it compounds with the others.
How ApplySift scores it: email-no-name, one point, when the local part contains neither the first four letters nor the last four letters of the applicant's first or last name (letters only, case ignored; a name shorter than four letters has to appear whole). It only runs when the file has a name column.
5. One mailbox behind several applicants
Gmail ignores dots in the local part and anything after a plus sign, so j.smith@gmail.com, jsmith@gmail.com and jsmith+acme@gmail.com are one inbox. An export shows three applicants; there is one. The shared phone number guide covers how to find these in a spreadsheet.
How ApplySift scores it: email-shared, three points for every row in the cluster, after dots and plus tags are stripped on Gmail and plus tags on every domain. The scored file's shared_with column lists the other rows.
6. One name under several addresses
The reverse pattern: the same first and last name applying from two or three different mailboxes. Sometimes it is a real person who applied twice and used a different address the second time. Often it is one identity being reused with a fresh address per application.
How ApplySift scores it: name-multi-email, two points, when the same first and last name appears with more than one distinct mailbox in the file.
What these add up to
| Address on the application | Reasons | Tier |
|---|---|---|
priya.raman@gmail.com, name Priya Raman | none | Clear |
bluewind7742@hotmail.com, name Priya Raman | email-provider, email-no-name | Review (2) |
michael.carter48213@outlook.com, name Michael Carter | email-provider, email-digits | Review (2) |
k2048173@mailinator.com, name Kevin Lee | email-disposable, email-digits (7), email-no-name | Likely fraud (6) |
Notice that none of the email signals except a throwaway domain or a shared mailbox gets a row past Review by itself. That is deliberate. Email shapes are cheap tells, and the phone number is the expensive one: a wholesaler block is three points, so an address that looks generated plus a phone that is provisioned by API is where the Likely fraud pile comes from.
What ApplySift does not check
- Whether the mailbox exists. No verification email, no SMTP probe. ApplySift never contacts an applicant.
- The domain's age or reputation beyond the short disposable list. A fresh custom domain reads as an ordinary domain.
- Résumé or cover-letter text. A mismatch between the name on the résumé and the name on the application is a real signal, but it needs files the export does not carry.
Checking a file yourself
In a spreadsheet: split the email column at the @, sort by domain and skim for throwaway providers; add a column that counts digits in the local part (=LEN(A2)-LEN(REGEXREPLACE(A2,"[0-9]","")) in Google Sheets) and filter for five and up; normalise Gmail addresses and COUNTIF for duplicates. It takes twenty minutes on a few hundred rows and most of an afternoon on a few thousand. Or upload the export and read the summary, which is free and counts every one of these signals before you decide whether the scored file is worth paying for.