Inspiration

“Call the number in this email to verify your internship offer.” If the email is forged, that number may belong to the same scammer. OfferCheck turns that trap into a practical question: which contacts came from the offer, and how can you check elsewhere?

What it does

Paste a job, internship, or scholarship offer, name the organization it claims to represent, and optionally add the sender address. OfferCheck extracts emails, domains, links, phone numbers, chat handles, and payment requests. It compares domains with the claimed organization and labels channels Official, Lookalike, Unrelated, or Unverifiable. These are heuristic relationships, not proof that a sender controls a domain or that an offer is legitimate. Evidence-backed scam signals produce an explainable Low / Caution / High / Stop band. The app then guides an independent check that avoids the offer's own phone numbers, links, and reply addresses. A Low score is not a certification.

Two built-in synthetic examples show a fake recruiter reaching Stop and a plausible legitimate offer staying Low. The app runs entirely in the browser, so pasted offer text is not uploaded.

How we built it

React, TypeScript, and Vite power a static app. A deterministic pipeline extracts and normalizes channels, compares domains, matches scam patterns, scores the evidence, and builds the verification steps. There is no backend, storage, or runtime AI API. A Content Security Policy blocks outbound connections after load. The public repository includes more than 50 automated tests covering scam and legitimate examples, domain lookalikes, affiliated university domains, and inert rendering of extracted contacts.

Challenges and lessons

Defanged links such as hxxp and [.] should be recognized without becoming clickable. Similar-looking domains and real institutional subdomains create opposite failure risks: missing a scam or falsely accusing a legitimate offer. We added adversarial and legitimate controls, including a university-domain affiliation case, while retaining a clear warning that domain matching is not authentication. The lesson is that the safest verification step must come from outside the offer itself.

What's next

Broader, curated institutional-domain coverage; multilingual scam-signal rules; and an optional on-device explainer limited to the deterministic findings.

Originality and AI use

OfferCheck was created in September 2026 for this event and is not entered elsewhere. Devin (Cognition) assisted with concept research, implementation, tests, documentation, and media. The running app does not use a generative model, external API, or third-party dataset. All example offers are synthetic. Source · Live app.

75-second judge demo

Watch the voiced OfferCheck walkthrough. Narration is synthesized text-to-speech; all offers shown are synthetic. The video demonstrates a scam, a plausible legitimate message, the evidence behind warnings, and the independent verification path.

Built With

Share this project:

Updates

Submission history