How it works

Before a single term is on the table, the sender pushes an NDA. Sometimes it is a real-looking PDF attachment, sometimes just a demand that you agree to keep the conversation confidential before they will reveal the campaign. Framed as professionalism, the NDA actually does two useful things for a scammer. It discourages you from doing the one check that would expose them, which is asking other creators whether they have seen the same sender or the same offer. And it can double as a delivery method, since the attachment you are told to open and sign is where malware or a credential-harvesting link hides. A confidentiality step is normal much later, once there is a real scope and a real contract, but not as the price of admission to hearing what the deal even is.

The tell-tale signals

What to do

Do not sign or open anything before you know who is writing and what they want. Reply and ask for the basic shape of the deal in plain email first: brand, deliverables, fee, and dates. Real partners share that freely, and an NDA, when it is warranted, comes with a named company and a real contract, not before them. Ask around in your creator circles and search the sender address, because scammers reuse the same script across dozens of channels, and one match is enough to confirm the risk. Treat any signed-document attachment from an unverified sender as unsafe.