Help Center for
TopicsGuidesWebinarsContact

Recognising Phishing Scams

Scammers may pose as Indeed to trick you into sharing Personal Data. This could be your password or a two-factor authentication (2FA) code. They use this information to access your account and sensitive data. This tactic is called phishing.

Recognising phishing tactics is the best way to protect yourself and your account. In this article, we will share a few common scams. We will also explain how to keep your account safe and what to do if you suspect a phishing scam.

Common phishing tactics

Copied logos and design

  • Scammers copy Indeed's logo, colours and email format to make their messages seem real.
  • A recognisable Indeed logo does not always mean the email came from Indeed.

Urgent or threatening messages

  • Scammers create pressure by demanding immediate action.
  • They may threaten to suspend your account or delete your data if you do not respond fast.
    • Example: "We will disable your account in 24 hours unless you verify your information now."

Suspicious links

  • Phishing emails often include links that lead to fake websites or mobile app stores.
  • They are designed to steal your sign-in information or install malware on your device.

How to check a link

  • Hover over the link without clicking to see where it leads.
  • Check for misspelt domains like "Lndeed.com" or "ind33d.com" instead of "indeed.com."
  • Do not click if the link does not go to an indeed.com domain.
Some fake sites may redirect you to the real site after you enter your credentials. This makes the scam harder to detect.

Fake email addresses

Scammers use email addresses that look like Indeed's official domains with slight variations.

Official Indeed domains

  • @indeed.com
  • @indeedemail.com

Fake domains

  • @ihdeedemployer.com
  • @Indeed.com (with a lowercase "L")
  • Any other variation
If you are unsure about an email, sign in to indeed.com instead of clicking links in the message.

Requests for Personal Data

Scammers may ask for your information through:

  • Web forms or surveys
  • Email replies
  • Text messages (also called "smishing")

What Indeed will never ask for

  • Your password outside of the official sign-in page on indeed.com
  • Your 2FA code
  • Downloads of software to access your account

Protecting your account

Enable two-factor authentication (2FA)

Use strong, unique passwords

Create a password that:

  • Is at least 8 characters long
  • Includes a mix of letters, numbers and symbols
  • Is different from the passwords you use on other sites

Review your account often

Check your account activity for any suspicious behaviour, such as:

  • Jobs you did not post
  • Messages you did not send
  • Applications you did not submit
  • Changes to your profile you did not make

What to do if you suspect phishing

If you receive a suspicious email or text

  1. Do not click any links or download any attachments.
  2. Do not reply to the message.
  3. Mark it as spam.
  4. Delete it immediately.

If you think your account was compromised

  1. Change your password immediately by signing in to your Indeed account.
  2. Enable 2FA if you have not already.
  3. Contact our support team right away.

Learn more in our article Think You Were Hacked? Here's What to Do.

Report suspicious activity

Help protect the Indeed community by reporting phishing attempts and suspicious activity. Contact our support team if you:

  • Notice unauthorised activity on your account
  • Encounter a fake Indeed website or job posting
  • Have questions about whether a communication is legitimate
Was this article helpful?

More in this topic

About Indeed Employer Single Sign-On (SSO)Change Account OwnerFAQs: Opening an Indeed AccountManaging Indeed Browser NotificationsTroubleshooting 2FA Issues
Still need help?Send us a message and our team will follow up.
Submit a request
Recognising Phishing Scams