← All posts
Inclusive Hiring

The Reference Reply That Creates Defamation Risk

August 27, 2026 · 7 min read

A former team lead gets an email from a recruiter: “We are considering Sam for a client-facing role. Anything we should know?” The lead means well. Sam was talented but exhausting to manage, so the reply comes back in thirty seconds: “Strong technically. Between us, I would not rehire them, there were some attitude issues near the end.” Send.

That reply, written with no malice and probably some accuracy, is the kind of message that turns a routine favour into a defamation or misrepresentation claim. The candidate does not get the job. They ask why. Somewhere the phrase “attitude issues” surfaces, and now a manager and a company are explaining to a lawyer what “attitude” meant, whether they can prove it, and why they volunteered an opinion they were never asked to defend.

Why the casual line is the dangerous one

References sit in a specific legal position. In most jurisdictions an employer giving a reference is protected by qualified privilege: because there is a legitimate interest in sharing candid employment information, an honest, good-faith reference is shielded even if it turns out to be wrong. That protection is real, and it is also conditional. Qualified privilege is defeated by malice, by reckless disregard for the truth, or by statements the speaker did not honestly believe. The moment a reference drifts from documented fact into unverified characterisation, the shield gets thinner.

There is a second exposure that surprises managers. A reference does not have to be spiteful to be actionable. In Spring v Guardian Assurance plc [1994], the UK House of Lords held that an employer owes the subject of a reference a duty of care, so a negligently prepared reference that costs someone a job can support a claim in negligence, with no need to prove malice at all. Getting it carelessly wrong is enough. That is why a throwaway “attitude issues” is worse than a documented “received two written warnings for missed deadlines”: the first is a characterisation you may not be able to stand behind, the second is a fact you can.

The defence side of this is expensive when it goes wrong. Defamation exposure is not theoretical: a US cable-news network paid USD 787.5 million to settle a defamation claim after internal messages showed people privately doubting the very statements at issue. The mechanism is identical at a smaller scale in a reference. A written opinion that the speaker cannot support, especially one contradicted by the person’s own records, is the raw material of a claim.

This is exactly why so many organisations quietly moved to confirm-only references: job title, dates of employment, and sometimes whether the person is eligible for rehire, with everything else declined. In the United States, roughly 40 states passed reference-immunity statutes that protect employers who share good-faith, factual job-performance information, and even with that protection most large employers stayed confirm-only. The lesson they drew is simple: the downside of a candid paragraph outweighs the upside, so they stopped writing the paragraph.

The line between a fair reference and an actionable one

You do not have to go fully confirm-only to be safe. A fair reference and an actionable one differ on four tests. A statement is defensible when it is factual (an event, not a label), documented (you can point to a record), relevant (it concerns job performance, not personality or protected characteristics), and something you honestly believe. Fail any of those and you are in the risk zone.

Compare the two versions of the same reference:

  • Actionable: “I would not rehire them, there were attitude issues.” Opinion, undocumented, about character, volunteered.
  • Defensible: “They held the role of Account Manager from March 2023 to January 2025. Our policy is to confirm title and dates only.” Factual, documented, relevant, and honestly believed.

Decision guide for reference replies

Use this before sending any reference, spoken or written. If a statement does not clearly sit in the left column, move it right or drop it.

Safe to state Withhold or reframe Never state
Job title and dates of employment Reason for leaving (confirm only if factual and documented) Personal opinion on character (“attitude”, “difficult”, “not a team player”)
Documented duties and scope Performance ratings (only if from a formal, shared review) Speculation about health, family, or protected characteristics
Whether the person is eligible for rehire (yes or no, no narrative) Specific conduct (only if formally recorded and closed) Anything prefaced with “between us” or “off the record”
Facts already in a formal, signed record Comparisons to other employees A guess, a rumour, or a second-hand account

The “between us” line deserves its own row. There is no off-the-record in a reference. A recruiter can repeat it, a candidate can obtain it through disclosure, and the informal framing is often read as evidence that the speaker knew the statement was improper. Treat every reference reply as if it will be read aloud back to the candidate, because it might be.

A factual template line you can reuse

Give managers one sentence so they never have to improvise:

  • Confirm-only default: “I can confirm that [Name] was employed as [Title] from [start date] to [end date]. Our policy is to provide title and dates of employment only.”
  • If your policy permits eligibility: add “They are eligible for rehire” or “They are not eligible for rehire,” with nothing after it.

A one-line policy also protects the manager personally: it removes the pressure to be helpful by improvising, and it gives an honest, consistent answer to every requester. For the fuller version of what a defensible reference process looks like, see our guide to handling reference requests.

Where a pre-send check fits

Policies fail at the point of writing. The manager knows the confirm-only rule and still types “attitude issues” at 5pm because a helpful sentence feels harmless in the moment. That gap between the policy and the keystroke is where the exposure lives.

A pre-send check reads the draft in the composer, before it is sent, and flags the careless line. On the reference above, VerbaPulse flags “attitude issues” and “I would not rehire them” and suggests keeping the reply to confirmed title and dates. The suggestions are short and phrase-level, because the fix usually is: remove the characterisation, keep the fact.

Be clear about what this is. It is a front-end shield against accidental risk, the well-intentioned line a decent employee does not notice is a problem. It is not an adversarial control: it will not stop someone determined to defame a former colleague, and it is not a substitute for a written reference policy or legal review. It sits in front of your archiving and supervision tools (Smarsh, Proofpoint and similar), so fewer flagged messages reach those queues in the first place. The policy sets the rule, the pre-send check catches the moment the rule is about to be broken.

The takeaway

Set a confirm-only default in writing, give every manager the one-line template above, and route reference requests through HR or a named owner so individuals never improvise under pressure. When a manager does write more than title and dates, apply the four tests: factual, documented, relevant, honestly believed. A reference that passes all four is candid and safe. A reference that fails one is a favour that can cost you a claim.

This is general information on managing reference risk, not legal advice. Confirm your reference policy with qualified counsel in your jurisdiction.

See it on your own emails

VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.

Start a pilot

Up to 10 seats. EUR 120, credited to your plan if you continue.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← MNPI and market abuse: the everyday phrases that cross the line The new insider risk: what your team pastes into ChatGPT, Gemini, and Copilot →