Field Notes — the Docurensic blog

Field Notes

Document fraud, forensics, and verification workflows — practical writing from the team building the engine.

AllInternationalApostilleLegalizationVerificationComplianceEvidenceChain Of CustodyForensicsGuidesFraud EconomyTemplatesGeneratorsTrendsTrade
How-to guideAug 12, 20268 min

Verify It at the Source: A Directory of Official Registries

Issuer confirmation outranks every form of analysis, including ours. A directory of the free official registries — companies, sanctions, licences, education, travel documents — and the rule that stops a fake verification

ArticleAug 09, 20267 min

Tender Fraud: When the Winning Bid Is a Forgery

A tender is decided almost entirely on paperwork — certificates, accounts, references, insurance. Most of it is scored once, by someone with forty other submissions to read, and never checked again.

How-to guideAug 08, 20267 min

Wire Fraud: What to Do in the First 72 Hours

Almost everything that works on a fraudulent transfer works in the first day. Almost nothing works after the third. Here is the order to work in when it has already happened.

ArticleAug 07, 20267 min

Fake Portfolio Statements: Wealth That Only Renders

A portfolio statement is a claim about money you cannot see, issued by an institution you may not be able to contact, in a format nobody standardised. That is a lot of room to work in.

ArticleAug 05, 20268 min

The Job Offer That Wants Your Bank Details

A recruitment scam is a document operation. There is no job, so everything the victim receives is paper — and paper produced under time pressure by someone impersonating a company they have never worked for.

How-to guideAug 02, 20267 min

Reading Email Headers: The Trail a Message Can't Fake

Everything a sender types can be forged. Everything the relay servers stamped on the way through cannot be rewritten after the fact — which is why the headers are where the answer lives.

ArticleJul 31, 20267 min

One Character Off: How Lookalike Domains Get Paid

The most effective domain in payment fraud is not a hacked one. It is a real domain, correctly configured, that differs from your supplier's by a single character nobody reads.