RefolkCandidates
10 min read

Workday's May 2026 Bot Score: 4 Signals That Kill Applications

Workday, Greenhouse, and Ashby score applications for VPN, VoIP, and automation signals before a recruiter opens them. Here is how to apply clean.

You spent an hour tailoring a resume, clicked submit through a Workday portal with your VPN on, and never heard back. The silence is not the recruiter. Since May 2026, Workday's Fraudulent Application Detection has been scoring your submission for automation and IP signals before a human ever opens the tab, and Greenhouse and Ashby shipped equivalent modules in 2025.

What Workday, Greenhouse, and Ashby actually score

Every major ATS now runs a rules layer on your submission that flags four things: your IP geolocation, your device or user-agent fingerprint, your phone number type, and your email domain. None of these have anything to do with your resume, and all of them can silently drop your application into a "review later" bucket.

Here is the shipping timeline, taken from vendor announcements:

  • Workday, May 2026 agentic-AI release. Fraudulent Application Detection "surfaces signals like IP geolocation and automation likelihood scores so recruiters can more easily spot and filter out suspected bot or fraudulent applications."
  • Greenhouse Real Talent, June 3, 2025. A "tiered inbox based on application quality and the likelihood of fraudulent or spam activities." Greenhouse's docs are explicit: "This feature does not use AI or automated scoring. It applies rules based on objective signals."
  • Ashby Fraudulent Candidate Detection, September 16, 2025, rolled out to all Foundations, Plus, and Enterprise customers. Flags submissions "as they are submitted."

Ashby CEO Benjamin Encz framed the launch bluntly: "candidate fraud has quickly shifted from a rarity to a regular challenge." Read that as the vendor pitch. The consequence for real applicants is that VoIP numbers, mismatched geo-IPs, and disposable emails are now risk signals whether you meant them that way or not.

Why the India-to-US supply gap makes geo-IP the loudest flag

Geo-IP mismatch is the single loudest fraud signal for US roles because there are roughly 1.57 times more software engineers in India than in the US, and every US recruiter is drowning. This is a volume problem, not a bias problem.

In Refolk's index of professional profiles, queried August 2026, the raw counts look like this:

SegmentCount in Refolk's indexNote
Software Engineers, US346,233Baseline US SWE supply
Software Engineers, India544,2241.57x the US pool
US Recruiters89,274The gatekeeper layer
Apps per US recruiter if every Indian SWE applied once~6.1Illustrates the pressure driving detection

The mechanism is prior probability. When an Indian IP hits a US-only Workday req, the recruiter's fraud tool assigns a higher prior that this is offshore mass-applying than a real relocating candidate, because in aggregate it is. That prior punishes real applicants who happen to be traveling, on a corporate VPN, or in the wrong country during a layover.

1.57x
India-to-US software engineer supply ratio

544,224 Indian SWEs vs 346,233 US SWEs in Refolk's index. The math behind why geo-IP is the loudest fraud signal on US reqs.

Why your VPN is worse than a foreign IP

A US resident applying from a US VPN often scores worse than an overseas applicant on a residential IP, because Greenhouse and Ashby check both geolocation and known datacenter and proxy ranges. NordVPN, Mullvad, and corporate VPNs advertise datacenter IP blocks that fraud tools have flagged for years.

The practical result:

  • A San Francisco engineer applying through NordVPN from home: datacenter IP, region may or may not match resume, automation-likelihood score elevated.
  • A Bangalore engineer applying from home broadband: residential IP, clean fingerprint, single flag on geo mismatch.

The second candidate can survive a single-signal flag. Greenhouse's own TA team piloted the module on a Machine Learning role and reported that "candidates flagged only by weaker signals were more nuanced," meaning single-signal flags get manual review. Two or three simultaneous flags do not.

If you are in the US applying to US roles, turn the VPN off before you open the ATS tab. It is the cheapest fix on this list.

The four signals, and which two you can defeat mechanically

Greenhouse's rules-based approach is a gift to job seekers who read the docs, because deterministic rules can be defeated deterministically. Two of the four signal categories are fully within your control before you submit.

SignalWhat triggers itMechanical fix
IP geolocationVPN, datacenter IP, country mismatch with resumeApply from a residential connection in the country on your resume
Device fingerprintHeadless browsers, auto-clickers, unusual user agentsUse a normal desktop browser, log in normally
Phone numberVoIP (Google Voice, TextNow, Twilio numbers)Use a real carrier line, mobile or landline
Email domainDisposable domains, throwaway addressesUse a personal domain email or a reputable provider you actually check

Two of those, phone and email, you can fix in five minutes. A Google Voice number on your resume reads as VoIP to every fraud vendor on the market. A number from your actual mobile carrier does not. Same with email: a Fastmail address on your own domain is invisible to disposable-domain blocklists; a mailinator address is not.

Rules-based means defeatable. Two signals are yours to fix before you click submit.

The auto-apply tax: why LazyApply broke on Workday first

Auto-appliers are now the highest-risk way to submit, and Workday specifically breaks them. A 2026 hands-on test documented consistent auto-apply failures on Workday flows, and the reason is architectural: Workday requires multi-page account creation with device fingerprinting, and that same fingerprint is what feeds Fraudulent Application Detection later.

The category is also visibly deteriorating:

  • LazyApply: sits at roughly 2.4 out of 5 on Trustpilot in early 2026. A commonly cited outcome is 500 auto-applications for a single callback.
  • BulkApply: went unreachable by June 2026.
  • Simplify, Sonara, LoopCV: still shipping, but every one of them logs into LinkedIn or third-party ATSes in ways that trip user-agent checks.

LinkedIn's User Agreement §8.2 explicitly prohibits "bots or other unauthorized automated methods to access the Services." LinkedIn removed 200 million bots in 2024 alone, and reports bot activity increasing roughly 50% year over year. The enforcement risk is not theoretical.

The distinction that matters, and that the auto-apply category deliberately blurs: AI drafting is fine, AI submitting is not. A 2025 ResumeBuilder survey of more than 700 recruiters found 73% had no objection to AI-assisted applications if the content was accurate and personalized. What they object to is unattended blasting. The recruiter's complaint is not "you used AI," it is "you did not read the job description."

That is the exact seam Refolk sits in. Paste the posting, get your own resume back rewritten for that specific role, with a cover letter drafted from the same context, and then you press submit yourself, from your own browser, on your own residential IP. No headless automation, no user-agent flags, no VoIP number injected into a form field. The tailoring happens before the ATS ever sees you.

What Endorsed and Brainner add on top of Ashby

Third-party fraud vendors layer on top of Ashby via API and push the signal count from four categories to several hundred. If you are applying to a startup on Ashby, you may be scored by more than just Ashby.

  • Endorsed advertises evaluation against "400+ signals" and claims "1 in 3 remote applicants are fake." Take the second number with skepticism, but the 400-signal architecture is real.
  • Brainner claims applications are checked against "3.5 billion data points and 20+ fraud patterns," with a 95%+ accuracy claim on their model.
  • CLEAR, the airport identity-verification company, powers the selfie check inside MyGreenhouse for Greenhouse's identity flow.

The takeaway is not to panic about any single vendor's number. It is that the "objective signals" list keeps growing, and single-signal fixes matter more as the aggregate score gets denser. Clean phone plus clean email plus residential IP plus normal browser is a four-signal win against a system that only needs two flags to bucket you.

200M
Bots LinkedIn removed in 2024

Bot activity is up roughly 50% year over year, which is why every ATS shipped detection in 2025 and 2026.

How to apply clean in 2026: a pre-submit checklist

The mitigation is mechanical and takes under ten minutes per application. Run this before you click submit on any Workday, Greenhouse, or Ashby portal.

  1. Turn the VPN off. All of it. Corporate VPN, personal VPN, browser proxy.
  2. Use a residential connection in the country your resume claims. If you are traveling, wait.
  3. Put a real carrier phone number on the application, not Google Voice or TextNow.
  4. Use a personal-domain email or a mainstream provider you actually check. No disposable domains.
  5. Log in with a normal browser. Chrome, Firefox, Safari, on a real machine. No headless drivers, no auto-clickers.
  6. Draft with AI, submit by hand. Tailor the resume and cover letter before the ATS session starts, then complete the form yourself.
  7. Fill every field the ATS asks for. Skipped custom questions increasingly count as a weak-quality signal in Greenhouse's Real Talent tiering.

Tailoring one resume per posting by hand across 40 applications is genuinely unsustainable, which is why most candidates lose time on steps 6 and 7. Refolk writes your resume from your own history, tailors it to every posting you paste in, drafts the cover letter, and scores how well you actually fit the role before you spend fifteen minutes filling out the Workday form. The submission itself stays human, which is the only thing the fraud detector cares about.

What this changes about volume strategy

The old volume playbook, 500 applications a week through a Chrome extension, is now a negative-expected-value strategy. Fraud detection is priced into every large ATS, and the automation-likelihood score follows the account, not the application.

A better allocation, given the four-signal system:

  • 20 to 30 applications per week, all manually submitted, on tailored resumes, from a clean IP and clean identity signals.
  • Prioritize roles on ATSes where your fit is above the tier-1 quality threshold. Greenhouse Real Talent explicitly buckets by quality, so a partial application is worse than no application.
  • Skip roles where the geo mismatch is unfixable. If you are in India applying to a US-only Workday req with no relocation mentioned, the prior is against you regardless of how good the resume is.

Fewer, cleaner, better-tailored applications from a real browser on a real network. The auto-apply era is over, and the fraud-detection era rewards the same discipline good applicants have always had.

FAQ

Does using ChatGPT or Refolk to write my resume trigger ATS fraud detection?

No. Fraud detection scores the submission, not the document. The signals are IP, device fingerprint, phone type, and email domain, none of which know or care whether an AI helped draft the resume text. The 2025 ResumeBuilder survey of 700+ recruiters found 73% have no objection to AI-assisted applications when content is accurate and personalized. What gets flagged is the automation-at-submit layer: headless browsers, auto-clickers, and bulk-apply tools. Draft with whatever you want, then submit like a human.

Will a VPN always get my application flagged?

Not always, but often, and often worse than a foreign residential IP. Greenhouse and Ashby check both geolocation and known datacenter and proxy ranges. Consumer VPNs like NordVPN advertise datacenter IP blocks that have been flagged for years, so a US resident on a US VPN can score worse than an overseas applicant on home broadband. If you are applying from a country that matches your resume, turn the VPN off for the ten minutes it takes to fill out the form.

Are Google Voice numbers really a fraud signal?

Yes. VoIP numbers, including Google Voice, TextNow, and Twilio-provisioned lines, are treated as risk signals by Greenhouse's rules-based module and by Ashby's phone-signal category. This is one of the two signals you can defeat mechanically in five minutes: put your real mobile carrier number on the application. If privacy is your concern, keep the VoIP number for the resume PDF header and enter your carrier number in the ATS phone field.

How do I know if I have been silently flagged?

You mostly do not, which is the design. Greenhouse Real Talent tiers submissions into an inbox and Workday surfaces likelihood scores to the recruiter, so the flag is invisible to you. Two proxies you can use: response rates dropping sharply after you started using an auto-apply tool, or long silences on roles where your fit is genuinely strong. If both are true, audit your four signals (IP, device, phone, email) before you send another application. Fixing them is cheaper than sending another 500.

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Keep reading