What are red flags in a brand sponsorship email?
Updated July 29, 2026 · By Bryson Loughmiller
Short answer
The red flags that matter are structural, not cosmetic. Watch for anything that wants you to open an attachment or click through before deal terms exist, a sender domain that's almost right, invented urgency, payment in crypto or gift cards, and a brand that won't put deliverables in writing. Today's scam emails are well written. Judge the ask, not the grammar.
| Signal | Green flag | Red flag |
|---|---|---|
| Attachments / links | Brief pasted into the email body, or a link to a public page on the brand's own site | Password-protected .zip or .rar, a file you have to download before terms exist, or a shortened link to a host you don't recognize |
| Sender domain | Matches the brand exactly ([email protected]) | Almost matches — a swapped letter, an added hyphen, or a 'creators'/'media' suffix stapled onto the real name |
| Payment instrument | Invoice paid by ACH, wire, or a named invoicing platform | Crypto, gift cards, or an overpayment you're asked to partly refund |
| Compensation | Quoted budget range, or asks for your rate sheet | 'Exposure', free product only, or 'revenue share' with no floor |
| Deliverables | Specifies format, length, timing, and channels | Vague — 'a video about us' or 'a post' |
| Contract | Offers a written agreement before any work starts | Wants to start immediately on an email handshake |
| Urgency | Normal scheduling — campaigns get planned weeks to months out | 'Need this by Friday' or 'campaign launches Monday' |
| Access requested | Your public channel and a draft link | Channel access, login credentials, or a 'verification' sign-in page |
Why the old advice stopped working
I've spent about a decade in security engineering, which mostly means I've spent a decade being the guy at dinner explaining why that link is bad. Delightful at parties. Truly.
But the advice I'd have given a creator five years ago is useless now. Broken English, weird greetings, typos everywhere — that generation of scam email has retired. What shows up in your inbox today names a specific video, spells your name right, quotes a budget that sounds about right, and comes from a domain that looks fine if you don't stare at it. Some of these are better written than the real pitches.
So stop grading the writing. Grade the ask.
Real partnerships talk about terms first and swap files later. That order is boring and consistent and almost never violated. A phishing email has to get you to open something early, because the thing you open is the email. Everything else in it is set dressing.
What they're actually after
This is where most creator security advice goes sideways, and it's the part that changes what you should do about it.
They don't want your money. They want your channel.
A monetized channel with real history is worth vastly more than whatever someone could talk you into wiring, and it can be resold or pointed at your audience to run something much larger. Once you know that's the goal, the tradecraft stops looking random:
- The "brand brief" is the payload. It shows up as an archive or a document you have to download and run, instead of as words you could just read.
- The archive has a password for a reason, and the reason isn't politeness. The password is sitting right there in the email, which feels considerate and functions as evasion — mail gateways generally can't see inside an encrypted archive, so the file sails through unexamined.
- They're after your session, not your password. This is the part I wish more creators knew. Malware that grabs the authenticated session token your browser is already holding lets someone replay your logged-in state directly. No password required. Nothing ever prompts for a second factor, because as far as the system is concerned, you already passed it.
- The delivery rides on legitimate services. Real cloud storage, real file-transfer links. Good domain reputation is exactly why they're used.
Read the list below with that in mind. Nearly every flag on it is describing the same move: get you to run a file or type a password before any actual business has happened.
The red flags that matter most
Roughly ordered by how much weight I'd put on each.
- You're asked to open something before terms exist. The most important one, because it inverts how business conversations normally go. Terms first. Files later.
- A password-protected archive, or a file that has to run on your machine. A
.zipor.rarwith the password in the email body, a double extension, or a "brief" that turns out to be an executable or a shortcut. No real media brief has ever needed to arrive this way. - A domain that's almost right. Read it character by character.
[email protected]is not[email protected]. While you're in there, compare theReply-Toagainst theFrom— when those disagree, that's usually the whole answer. - A link that asks you to sign in. You're already signed in. A document you actually have access to just opens. An unexpected login page is the attack, not a hurdle on the way to the document.
- Urgency that appeared out of nowhere. "We need this by Friday." Campaigns get planned weeks to months out. Manufactured deadlines exist to walk you past the checks you'd otherwise run, and they work because they feel like enthusiasm.
- Crypto, gift cards, or an overpayment they want partly refunded. Real brands pay through systems that leave a trail. The overpayment version is old and still going strong.
- Anything asking for account access or credentials. A private draft link is normal. Handing over channel access, approving broad third-party app permissions, or typing your password into something the sender provided is not.
- Compensation that never gets specific. A real pitch names a range, asks for your rates, or at least opens the subject. "Exposure" and "future opportunities" are not compensation.
- Won't put deliverables in writing. Format, length, platform, date, usage rights. Brands need this documented internally anyway, so a real one will just write it down.
- Nothing proving they've seen your work. Weaker than it used to be, since naming your niche is trivially automated now. Still, an email with nothing specific in it is at best a mass mailing.
- A sender with no professional footprint. No LinkedIn, or one that doesn't list the brand. Thirty seconds, occasionally decisive.
- Payment only after publish, no upfront, no contract. More of a business problem than a security one, but it earns its spot: all the risk ends up on your side of the table.
I'm not going to hand you a scoring system. I know they're satisfying — count the flags, clear a threshold, feel like you did diligence. But one instance of number one or number two is already enough to stop, and a genuinely well-written email with none of the obvious tells can still be trying to take your channel. Counting works better on last decade's scams.
The verification routine
Five minutes, and none of it involves opening the thing:
- Go around the sender, not through them. Type the brand's address into your browser, find their contact form, ask whether this campaign and this person are real. Never use contact details the suspicious email handed you — if the email is hostile, so is its phone number.
- Check that the human exists. Name, role, and employer on LinkedIn should line up with the signature.
- Actually read the headers.
FromversusReply-To, and the domain one character at a time. - Ask for the brief as text. "Could you paste the details into the email?" is a completely ordinary request that costs a real partnership manager nothing, and it takes the attachment out of the conversation entirely. If they push back on that, you've learned something.
If you want a real baseline rather than a checklist: put phishing-resistant sign-in on the Google account attached to your channel — passkeys or a hardware key, not SMS codes — and look through your connected third-party apps once in a while. Those two hold up on the day you're tired and click something you shouldn't have. Which will happen eventually. It happens to people who do this for a living.
That last point cuts both ways, incidentally. Auditing your connected apps means auditing us too, and I'd rather you did. What BEGL asks for and what it keeps is written out on our security page.
What real outreach looks like
Real brand outreach is usually shorter than the fake kind. It names the brand and the campaign, says what it wants and roughly when, and either quotes a budget or asks what you charge. It's low-pressure and perfectly willing to sit in your inbox for a few days while you look into it.
An email that's working hard to get you past your own process is telling you what it is. The expensive mistakes are almost always the ones that talked their way around a check you already knew to run.
Related questions
- What's the safest way to verify a sender?
- Verify out-of-band — through a channel the sender doesn't control. Open the brand's website by typing the address yourself and use the contact form there to ask whether the campaign and the person are real. Don't reply to the suspect email, and don't call a number it gave you. Then cross-check the sender's name, role, and employer on LinkedIn, and read the full sender domain character by character, including any Reply-To that doesn't match the From. None of this requires opening the attachment, which is the point.
- Should I scan the attachment with an online scanner first?
- Scanning is a weak control and it has a real downside. A scanner only recognizes what it already knows, so a clean result isn't evidence the file is safe — attackers test against the public scanners before they send anything. Worse, files you upload to those services are generally shared with their security-partner networks. So uploading a contract to check it can leak the contract. Don't upload anything you'd consider confidential. Better move: don't open the file at all. Ask for the content pasted into the email.
- Why would anyone bother scamming a creator?
- Your channel is the asset. Creator-targeted phishing is usually about taking over the account, not about talking you into a wire transfer. That changes the whole calculation: the attacker doesn't need your password, and two-factor authentication isn't automatic protection. It's why the useful advice here is about access rather than about spotting bad grammar.
- I have 2FA turned on. Am I safe from this?
- Safer. Not safe. Two-factor authentication doesn't close this path by itself, because a common technique steals the session token your browser is already holding after you've logged in. Replaying a live session skips the login screen entirely, so nothing ever asks for your second factor. What actually helps: not running the file, moving to phishing-resistant sign-in like passkeys or a hardware key instead of SMS codes, and occasionally checking which third-party apps still have access to your account.
- Is a Gmail sender always a scam?
- No, and assuming it is will cost you real deals. Plenty of small brands, founders, and freelance marketers email from Gmail because that's what they have. Treat it as a reason to verify, not a verdict — ask for a confirming note from a brand-domain address, which takes a real partnership manager about ten seconds. And don't over-trust the reverse: a brand-domain sender proves very little, since lookalike domains cost a few dollars.
- The email asks me to download a brand brief from a Google Drive link. Is that safe?
- Cloud storage gets abused precisely because the link looks fine and the domain has a good reputation. Two separate risks live here: a malicious file sitting on legitimate infrastructure, and a fake sign-in page harvesting your Google credentials. Useful rule — if a link asks you to sign in to Google, close it. You're already signed in to Google. A real Drive document just opens. When in doubt, ask for the brief in the email body; a real brand won't argue.
- What do I do if I think I already clicked something?
- Assume the session is compromised and move quickly. Sign out of all sessions, change the password from a different device you trust, then hunt for the things an attacker sets up to keep access: mail forwarding rules, filters, account delegation, changed recovery email or phone, and connected third-party apps. Then check your channel for anything you didn't do. Google's official walkthrough is Secure a hacked or compromised Google Account, and it covers the Gmail-settings and YouTube checks in a sane order.
- They sent me a contract right away. Is that good or bad?
- Good sign, but read it before you sign it. The things to look for are inside the contract, not in the fact that one exists: unlimited content rights, perpetual exclusivity, uncapped indemnification, and 'work for hire' language that hands over ownership of your video. A real brand expects to negotiate. A scam contract is take-it-or-leave-it.