In this article:
- Why a convincing freight email may not identify its true sender
- How to verify load and payment changes out of band
- Which checks belong to a public review and which require authorized access
A familiar email address is not identity proof
A message can look like a normal part of a shipment: a rate confirmation, carrier packet, appointment change, invoice, or request to update an account. The writing style and conversation history may look right, but email alone does not establish who is operating the account.
A lookalike domain can differ by one character or an added word. A legitimate freight broker, carrier, or vendor account can also be compromised, allowing an attacker to continue a real thread from a real mailbox. A clean-looking message therefore still needs independent verification when it changes where freight, money, or access will go.
Changes that deserve a separate check
Pause before acting on an unexpected change to a pickup or delivery location, driver or equipment, load details, rate, factoring relationship, bank account, payment instructions, portal password, or multi-factor authentication method.
For example, an email that appears to come from an established carrier asks a dispatcher to send a load to a new address. Treat the example as a request, not a confirmed instruction. Call the established contact using a number already stored in your system or obtained from a trusted record. Do not use the phone number or link supplied only in the new message.
Use a callback process people can follow
Write down who may approve a sensitive change and which independent contact path staff should use. The process should work when the email account or normal collaboration tool is unavailable.
Confirm the legal name, USDOT or MC number where relevant, shipment details, and payment destination. Compare the request with the existing rate confirmation, bill of lading, carrier records, and prior business relationship. Escalate conflicts before a truck moves or money is sent.
- Call a previously verified number, not a number introduced by the suspicious request.
- Require a second person to review bank, factoring, destination, or access changes.
- Preserve the original message, headers, attachments, and call notes.
- Report the request through your established IT, fraud, insurer, and law-enforcement procedures when appropriate.
Authentication helps, but it has limits
Use multi-factor authentication for email, load boards, TMS accounts, payment services, and government portals when supported. Give each worker an individual account, remove former-user access promptly, and review recovery methods and mailbox forwarding rules.
SPF, DKIM, and DMARC can make some forms of domain spoofing harder and provide useful email-authentication signals. They do not prove that every message is legitimate, stop a compromised legitimate mailbox, or replace a callback process. MFA reduces the chance that a stolen password is enough, but it does not make account compromise impossible.
Review public exposure and internal safeguards separately
A public exposure review can examine observable domain, email-authentication, website, certificate, and internet-facing service signals. It cannot inspect private mailboxes, confirm who approved a load, validate a carrier identity, or determine whether an account has been compromised.
An authorized assessment can review internal account configuration and available evidence when those checks are included in scope. Securing Your Business's $1,995 Business Security Baseline is responsible for that internal safeguard verification for businesses with up to 25 employees. Remediation is handled by your IT provider or separately scoped improvement work.
A short pre-change checklist
Before acting on a sensitive email, ask:
- Was this change expected, and does it fit the existing business relationship?
- Did we verify the sender through a known contact path?
- Did a second person review the load, payment, or access change?
- Are the domain, account, phone number, and destination consistent with trusted records?
- Did we preserve the message and report anything suspicious through company procedures?
Keep verification close to the operation
Freight teams work under time pressure, so the safest process is one that is short, documented, and practiced. Test it with a clearly labeled hypothetical exercise rather than waiting for a real payment or destination change.
These checks reduce avoidable confusion, but they do not guarantee prevention of cargo theft or freight fraud. Combine them with physical cargo controls, contract procedures, and advice from your IT and operations providers.
Need an evidence-backed starting point?
The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.
