Checks whether a job listing appears on the employer's own careers page, using public sources.
It's a command-line tool and a library. Every result is plain data, so the same checks can sit behind a desktop app, a website or anything else.
Python 3.9 or later, standard library only. certifi is used when installed. The domain-age check
calls whois.
# a posting on Greenhouse, Lever, Ashby or Workable
python3 -m reqcheck https://job-boards.greenhouse.io/example/jobs/123
# any other posting: give the employer's domain and the exact title
python3 -m reqcheck --domain example.com --title "Security Analyst"
# add counts read by hand from the company's LinkedIn page
python3 -m reqcheck --domain example.com --title "Security Analyst" --followers 1200 --employees 40
# the full result as JSON
python3 -m reqcheck https://job-boards.greenhouse.io/example/jobs/123 --json
# keep a copy, with your own note, in your home folder
python3 -m reqcheck https://job-boards.greenhouse.io/example/jobs/123 --save --note "applied"
python3 -m reqcheck historypip install . adds a reqcheck command that does the same.
| field | what it reports |
|---|---|
posting |
For Greenhouse, Lever, Ashby and Workable links: whether the posting is still on its board and its title, from the board's public API, and whether that board is the one the employer's site links to |
careers_listing |
Whether the title is on the employer's own careers page. Follows the landing page one level to its job list, and reads any Greenhouse, Lever, Ashby or Workable board the site links to |
bot_protection |
How many requests to the employer's site were refused |
automated_evaluation |
Automated-evaluation vendors named in the careers page source, or self-described automated screening |
domain_age |
Registration date, from whois |
contact_details |
Phone area codes, email addresses and virtual-office provider names published on the site |
follower_employee_ratio |
Computed from the counts you supply |
| status | meaning |
|---|---|
measured |
the check ran and produced a value |
absent |
the check ran and the thing is not there |
blocked |
the site refused the request |
unavailable |
the method failed, such as a list that loads by script or an API that could not be read |
not_checked |
the check ran, but what it read cannot support a conclusion |
not_supplied |
needs a value that was not given |
Only measured and absent describe the employer. The others describe what the tool could not see.
A role is reported absent only when the list read was complete: a hosted board read in full and linked from the employer's own site, or a page that shows a job list with no sign of pagination. No score is produced.
Nothing is kept unless you pass --save. Saved checks, and any note you add, go to
~/.reqcheck/checks.jsonl, readable only by you. REQCHECK_HOME can move that folder, but only to
somewhere inside your home folder. reqcheck never writes inside the project and never sends your
checks anywhere.
from reqcheck import check_listing
result = check_listing(url="https://job-boards.greenhouse.io/example/jobs/123")
print(result["summary"])
print(result["fields"]["careers_listing"]["status"])check_listing() returns the same data --json prints. Nothing in the core prints, stores or
scores anything, so it can go behind any front end, split into services, or be ported to another
language. Whatever form a build takes, keep these:
- Users' records stay on their own devices. An app writes to the user's home folder. A website keeps history in the visitor's browser. A server keeps nothing about its users or what they checked.
- Keep the private-address block. It stops a hosted build from being used to reach the network it runs on. A hosted build should also rate-limit and block internal address ranges at the network level, as a second layer.
- Keep
measuredandabsentapart from everything else, and add no score. - Don't automate the platforms under Not read.
The tests run offline against a made-up employer:
python3 -m unittest discover -s testsLinkedIn, Indeed, Glassdoor, ZipRecruiter, Built In and Dice, including their country sites, LinkedIn's lnkd.in links, and any link that redirects to them. Automated access breaches their terms or is blocked. For listings there, pass the domain and title by hand.
- HTTPS only, with certificate verification. A plain
http://address is read over HTTPS instead, and a site that only serves plain HTTP is reported as unavailable. - Nothing is fetched from a private, loopback or link-local address. The check runs on each connection, against the DNS lookup that connection uses, so redirects and DNS answers that change between lookups can't get around it. Proxy settings are ignored for the same reason.
- Responses are read up to 8 MB. Anything larger is reported as unreadable.
- Board names and posting IDs taken from pages are validated and escaped before use, and the API hosts are fixed.
- Everything the command line prints has control and format characters removed, so text from a
page or an API can't rewrite the terminal or disguise a domain.
--jsonoutput is plain ASCII, with every other character escaped. - A domain read from a posting page is used only if it's a valid hostname.
whoisreceives a validated hostname and is never run through a shell.- Saved checks are owner-only files inside the home folder, never written through a symlink.
- do-not-ghost-me (AGPL-3.0) collects anonymous reports from applicants who were ghosted, at donotghostme.com. Every reqcheck result links to its company search, which you open in your own browser. Its public API refuses automated clients, so reqcheck doesn't call it.
- didtheyghostme (MIT) tracks what happened after people applied, the side of the question reqcheck doesn't cover.
No code from either project is included.
reqcheck is available under either of two licenses. Pick the one that fits what you're building:
- AGPL-3.0-or-later for any use, commercial included. If you share a build, or let others use a modified build over a network, you must offer its full source under the same license.
- PolyForm Noncommercial 1.0.0 for noncommercial use. Your build can stay private, but it can't be used to make money.
Together they mean no build of reqcheck goes private for profit.
Required Notice: Copyright (c) 2026 The reqcheck authors