How it works
Before a single term is on the table, the sender pushes an NDA. Sometimes it is a real-looking PDF attachment, sometimes just a demand that you agree to keep the conversation confidential before they will reveal the campaign. Framed as professionalism, the NDA actually does two useful things for a scammer. It discourages you from doing the one check that would expose them, which is asking other creators whether they have seen the same sender or the same offer. And it can double as a delivery method, since the attachment you are told to open and sign is where malware or a credential-harvesting link hides. A confidentiality step is normal much later, once there is a real scope and a real contract, but not as the price of admission to hearing what the deal even is.
The tell-tale signals
- An NDA is required before any terms, budget, or deliverables are shared. The order is backwards, since secrecy comes before there is anything to keep secret.
- You are quietly or openly discouraged from discussing the offer with other creators.
- The NDA arrives as an attachment you are urged to open and sign quickly, especially a document or archive, or anything you have to enable content to read.
- The sender is a free mailbox or a lookalike domain rather than the brand's real address.
What to do
Do not sign or open anything before you know who is writing and what they want. Reply and ask for the basic shape of the deal in plain email first: brand, deliverables, fee, and dates. Real partners share that freely, and an NDA, when it is warranted, comes with a named company and a real contract, not before them. Ask around in your creator circles and search the sender address, because scammers reuse the same script across dozens of channels, and one match is enough to confirm the risk. Treat any signed-document attachment from an unverified sender as unsafe.