Understanding Red Flags for Fake Applicants

Understanding Red Flags: A Guide for Recruiters


🚨What red flags are (and what they aren't)🚨

Red flags in Brainner are signals designed to give recruiters more information about a candidate, not automatic verdicts. A flag on its own rarely tells the full story. Its purpose is to help you look at the candidate as a whole (resume content, experience, contact details, and these signals combined) so you can identify fake applicants and cut down the noise in your pipeline.

The best way to use flags is as an extra layer of context on top of your normal screening. A single flag can be a light signal worth noting. Several flags on the same candidate, or a flag combined with inconsistencies in the resume, build a much stronger case for a closer review.

For phone, email, and LinkedIn checks, Brainner uses third-party data sources that specialize in fraud detection and identity enrichment. This gives you access to signals that would be impossible to build or maintain in-house.

Below is a breakdown of every flag, grouped by category.

πŸ“ž Phone flags

Powered by third-party data sources.

VOIP or non-personal phone number detected

The phone number belongs to a VOIP provider (such as Google Voice or TextNow) or is a non-personal line (virtual, shared, or business). Based on our analysis with clients across real cases, this is one of the strongest indicators of fake applicants, since fraudsters rely heavily on these numbers because they are easy to create and dispose of.

That said, there are legitimate scenarios where candidates use virtual lines, either for certain types of roles or in specific regions. When hiring for those cases, the recruiter should factor in that context before treating the flag as decisive.

Phone number associated with fraud activity

The phone number appears in fraud databases maintained by our data providers. This is a strong signal and worth close review, especially if the candidate is progressing to later stages.

πŸ“© Email flags

Powered by third-party data sources.

Email shows signals of fraud or abuse

The email address has been linked to fraudulent or abusive behavior by our data providers. Treat this as a high-priority signal.

Email address was created recently

The vendor identified the email as recently created. There is an important nuance here: our vendor's database is extremely large, and it is possible the vendor only indexed the email recently even though the account itself is older. On its own, this should be treated as a lighter flag. When it appears together with other flags, it gains much more weight and becomes a meaningful signal.

Email address cannot reliably receive emails

The email failed deliverability checks. It could be a typo, a disposable address, or a mailbox that no longer exists. Regardless of qualifications, if you cannot reach the candidate the process cannot move forward.

Disposable or system-generated email detected

The email address comes from a disposable email service (such as Mailinator, Guerrilla Mail, or similar temporary inbox providers) or shows patterns typical of system-generated addresses. Legitimate candidates almost never use these to apply for a role, since they need a reliable way to receive updates from the recruiter. This is a strong signal that typically points to a candidate who does not intend to be reachable or is trying to hide their real identity.

🌐 LinkedIn flags

Powered by third-party data sources.

LinkedIn profile URL not provided

The candidate did not include a LinkedIn URL in their CV or in the pre application questions. Most legitimate candidates in today's market have a LinkedIn presence and share it openly, so an absent URL is worth noting.

LinkedIn profile is private or URL is invalid

This flag covers two different situations, and the right response depends on which one you are looking at:

The candidate's LinkedIn profile may be set to private, which means it can only be accessed when logged into LinkedIn. In this case, we recommend the recruiter open the profile directly. If the profile loads and you can review the information, treat the flag as informational and analyze the content yourself.

If the URL is broken or leads nowhere, treat the flag as high. There is no profile to verify against, which removes one of the main ways to validate the candidate's identity and background.

LinkedIn connection count is low

Candidates with unusually few connections may have recently created or fake profiles. Real professionals typically accumulate connections over years of activity, so a very low count is worth noting alongside other signals.

LinkedIn profile was created recently

A newly created profile is not proof of fraud by itself, but combined with other signals it can indicate a profile made specifically to support a fake application.

Professional history differs between LinkedIn and resume

The work history (companies, roles, titles, or dates) shown on the candidate's LinkedIn does not match what appears on the resume. This is a meaningful signal, since fake applicants often invent or inflate experience on the resume that is not backed by their actual LinkedIn presence.

There are legitimate cases too: a candidate may not have kept their LinkedIn fully up to date, or may have chosen to omit certain roles. Small discrepancies (a missing side project, a slightly different job title) are usually not a concern on their own. Large discrepancies (entire roles or companies that do not appear on LinkedIn, or dates that do not line up) are worth investigating.


πŸ“‚ File metadata

Resume shows signs of automated generation

The resume file contains metadata suggesting it was produced by an automated tool rather than written manually. Fraudsters and low-effort applicants often use AI or template generators to create resumes at scale. When you see this flag, look for coherence between the resume content and the candidate's stated background, and pay attention to overly generic language or claims that do not match the depth of the described experience.


How to use flags in practice

  1. Do not reject on a single flag. Flags are inputs to your judgment, not decisions on their own.
  2. Look for clusters. Multiple flags across different categories (for example, email + phone + LinkedIn) build a much stronger case than any single flag in isolation.
  3. When in doubt, verify. A quick Linkedin message or a short screening call is usually enough to clear up ambiguity for borderline cases.

The goal is not to filter out every risky candidate automatically. The goal is to give you the signals you need to spend your time on real applicants and quickly identify the ones designed to waste it.


Frequently Asked Questions

FAQs

1. Does a red flag mean the candidate should be automatically rejected?

No. Red flags are inputs to your judgment, not decisions on their own. A single flag can be a light signal worth noting, while several flags across different categories on the same candidate build a much stronger case for closer review. The goal is to give you the context you need to make a better-informed decision..

2. What categories of red flags does Brainner detect?

Brainner analyzes four areas: phone number signals (such as VOIP or numbers linked to fraud activity), email signals (such as deliverability issues, recent creation, or fraud associations), LinkedIn signals (such as low connection count, recently created profiles, or missing or broken URLs), and resume file metadata (such as signs of automated or AI-generated content).

3. Where does Brainner get the data behind the flags?

For phone, email, and LinkedIn checks, Brainner uses third-party data sources that specialize in fraud detection and identity enrichment. This gives you access to signals that would be difficult or impossible to build and maintain in-house.

4. What should I do if a candidate has a private LinkedIn profile?

If the LinkedIn profile is set to private, Brainner will flag it, but we recommend opening the profile directly while logged into LinkedIn. If the profile loads and the information is visible, treat the flag as informational and review the content yourself. If the URL is broken or leads nowhere, treat the flag as high priority, since there is no profile to verify the candidate's identity and background against.

5. How should I interpret the "email created recently" flag?

This is one of the lighter flags on its own. Our data provider's database is extremely large, and it is possible the vendor only indexed the email recently even though the account itself is older. Treat it as a soft signal in isolation, but pay closer attention if it appears alongside other flags such as a VOIP phone number or a recently created LinkedIn profile.

Still have questions?

Book a demo or .