# The 7 patterns in fake sponsor emails

If you post regularly, sponsorship emails show up whether you asked for them or not. A brand deal lands in your inbox, the number looks good, and for a second you forget to read closely. That second is exactly what the sender is counting on.

Most inbound offers come from real businesses doing outreach. A slice of them do not. The fake ones are not random or creative. They reuse the same handful of moves because those moves work on busy people who are excited to get paid. Once you can name the pattern, the email stops looking like money and starts looking like what it is.

Here are the seven patterns that keep showing up, what each one looks like in your inbox, the tell that gives it away, and what to do instead of clicking.

1. The password-protected attachment

What it looks like. The message is warm and specific. It names your channel, offers a flat rate, and attaches "the brief" or "the contract" as a .zip or .rar file. The body hands you the password to open it. Something like: "Full campaign details and rate card are in the attached file. Password: Brand2026."

The tell. A password sitting right next to the file it unlocks. Encrypting an attachment stops Gmail and your antivirus from scanning what is inside, which is the whole reason it is there. Real brands send briefs as a Google Doc, a PDF link, or a shared page. They do not ship you a locked archive with the key written two lines below it.

What to do. Do not download it, and do not open it on your phone assuming phones are safe, because they are not immune. Reply and ask for the brief as a shared document or a plain link. A genuine partner will send one without a fuss. A scammer will keep pushing the attachment.

2. The lookalike domain

What it looks like. The sender name is a brand you recognize, and the address looks almost right. Nvidia becomes nvidia-partners.com. Notion becomes notion-team.co. Sometimes a single letter is swapped so your eye slides past it, like an uppercase I standing in for a lowercase l, or rn posing as m so canva reads as cariva.

The tell. The domain is close but not the real one. The gap is usually an extra word, a hyphen, a different ending like .co or .info instead of .com, or one letter that does not belong.

What to do. Open the actual sender address, not the display name your client shows you. Then type the brand's real website into your browser yourself and find their partnerships or press contact. Compare the two. If a company reaches out from a domain that is not its main site, treat that as a strong signal to slow down.

3. A free-mail account claiming a big brand

What it looks like. "Hi, I'm the influencer marketing manager at [huge company]." The signature is polished, the logo is pasted in, and the reply-to address is something like brand.partners@gmail.com or marketing.samsung2026@outlook.com.

The tell. A company large enough to have an influencer budget also has its own email domain. A real brand manager writes from an address ending in the company's website, not Gmail, Outlook, Proton, or Yahoo. A famous name paired with free mail is a mismatch worth flagging.

What to do. Ask them to email you from their company address before you share anything. If the whole relationship has to run through a personal inbox, that is your answer. You can also look up the company's actual partnerships contact and ask them directly whether this person works there.

4. Cover the shipping fee

What it looks like. A gifting offer. They love your content and want to send you a product to feature, free of charge. There is just a small shipping or customs fee to release the package, and they need your card details to cover it. "The item is fully complimentary, we only ask you to handle the 4.95 delivery charge."

The tell. You are being asked to pay in order to receive a gift, and to hand over card numbers to do it. The fee is tiny on purpose, small enough to feel harmless. The goal is not the few dollars. It is your payment details and the habit of entering them on their page.

What to do. Never pay to receive a sponsorship. Real gifting costs the creator nothing. Do not enter card details on any link from a cold email. If the product is real and they want you to have it, they cover the shipping, because that is the cost of doing outreach.

5. Crypto payout and a move to Telegram

What it looks like. Strong pay for a short promo, often for an exchange, wallet, or token. Early in the thread they want to continue on Telegram or WhatsApp, and the payment is in USDT or another coin. At some point you are asked to connect a wallet or verify your account first.

The tell. Two signals stacked together: getting pulled off email onto an encrypted chat app before any real terms exist, and payment in crypto that cannot be reversed once it leaves. The wallet connection or verification step is where the actual theft happens.

What to do. Keep the conversation on email until terms and identity are clear. Do not connect a wallet, sign a transaction, or verify anything to get paid. Legitimate sponsors pay you through normal channels after the work runs, and they do not need access to your wallet to send money.

6. The offer that is too big for you

What it looks like. A number far above your usual rate, with almost no conditions attached. A channel doing a few thousand views per video gets offered several thousand dollars for one integration, sometimes more than a mid-size channel would command.

The tell. The pay ignores your actual reach. Real brands price against your views, your niche, and your audience, and they negotiate. An amount that does not match your size is not a lucky break. It is bait designed to switch off your caution, usually paired with one of the other patterns on this list once you reply.

What to do. Compare the offer to what your channel realistically earns. When a number feels too generous, read the rest of the email harder, not softer. Ask specific questions about deliverables and timeline. Vague answers and pressure to commit fast tell you what you need to know.

7. The fake copyright strike or account warning

What it looks like. This one does not pose as a sponsor. It arrives dressed as YouTube. "Your video has received a copyright claim. Your channel will be removed within 48 hours unless you appeal. Verify your account here." The link goes to a login page that looks like Studio.

The tell. Urgency, a threat to your channel, a countdown, and a link asking you to sign in. The sender domain is not a Google address, and the login page is not on youtube.com. Real enforcement never depends on you clicking a link in an email to save your account.

What to do. Do not click the link. Open YouTube Studio yourself by typing the address, and check your notifications and copyright tab there. Genuine claims and strikes appear inside Studio, not only in your inbox. Turn on two-step verification, and if you can, add a passkey or security key so a stolen password alone cannot get in.

Before you reply

Every pattern here comes down to the same habit: read the sender, the domain, the attachment, and the ask before you read the dollar figure. The scammers are betting you will do it the other way around.

If an offer has you second-guessing, you can run it through the LegitSponsor free checker before you respond. It reads the same signals covered here and gives you a quick risk assessment based on the evidence in the email. It is not a verdict, it is a second opinion, and it takes less time than opening that attachment would have.