Freight fraud · 7 min read
Jakub Wujec
Last reviewed: 16 June 2026
Fake carrier emails and suspicious domains to review before pickup
Fake carrier email threads often use freemail, disposable domains, invisible characters in the address, or a domain that does not match the company name in KRS or CEIDG. Compare the booking email to registry data and RDAP/WHOIS on the same day you approve the load. A suspicious carrier domain is a risk signal that requires review, not proof of fraud by itself.
Key checks before you assign the load
- Read the full email address, including dots, hyphens, and non-Latin characters.
- Check whether the domain is freemail, disposable, or recently registered.
- Compare domain core tokens with the legal name from the company register.
- Open the carrier website and check if it matches register address and phone.
- Use an independently found or previously confirmed contact channel: public contact from CEIDG or the transport register, the company website, a CRM contact, or a number confirmed on earlier loads. Do not rely only on the number in the suspicious email.
- Run the same contact pass when a known carrier switches to a new domain.
Quick triage before you reply with pickup details
Do this pass on the booking thread itself, before you send an address or cargo value.
Step 1: Read the full email address character by character
Zoom in on dots, hyphens, and any character that could be an invisible or homoglyph substitute for a letter you expect.
Step 2: Match the email domain to the register website
Compare the domain against the legal name and any listed website in KRS, CEIDG, ANAF, or ARES. A mismatch is a review item.
Step 3: Check domain creation date via RDAP against register age
Prefer RDAP or the registry when a creation date is published. When it is unavailable, use historical signals: passive DNS first seen, MX history, Certificate Transparency, first website versions, or earlier domain activity. A domain weeks old on a company that claims a decade of history is a stronger signal than a young company with a young domain.
Step 4: Use an independently confirmed contact channel, not the email
Use an independently found or previously confirmed contact channel: public contact from CEIDG or the transport register, the company website, a CRM contact, or a number confirmed on earlier loads. Do not rely only on the number in the suspicious email.
If the load is already moving
- Contact the carrier only through an independently found or previously confirmed channel, not the booking thread.
- Request the driver photo an ID and licence at pickup and compare it with the register entity.
- Ask for a GPS or tracking link straight from the vehicle.
- Freeze payment until the domain and register mismatch is explained.
- File a police report if you believe the load or payment has already been diverted.
What not to rely on
- Display name in Outlook or Gmail showing a known carrier brand.
- A PDF letterhead that matches the email signature.
- Previous loads with the same display name but a different domain.
- Owner privacy in RDAP or WHOIS alone, without checking creation date when published or historical signals: passive DNS, MX history, Certificate Transparency, first website versions.
- A website that copied logos but uses a different invoice entity.
- Assuming IT will catch spoofing after you already shared pickup info.
Why this risk signal matters and what it does not prove
Carrier email spoofing targets operations teams, not IT. The inbox is where pickup addresses and cargo values leak first.
- A suspicious carrier domain plus clean register data may still mean impersonation of a real haulier.
- Freemail on a small sole trader can be normal; on a sp. z o.o. with ten trucks it is a stronger signal.
- Email alone never proves fraud. Combine with licence, VAT, and insurance checks.
- Clearing a domain mismatch through an independently confirmed contact channel is faster than recovering cargo after pickup.
Red flags and common mistakes
Invisible or homoglyph characters in the email
May indicate spoofing aimed at looking like a trusted domain. Requires review before you reply with cargo details.
Disposable domain or unusual TLD
TLD choice alone carries very low weight. Focus on domain age, website content, and match to the register entity, not the ending by itself.
IDN punycode domain close to a real carrier brand
Lookalike domains are a common impersonation path. Compare with the legal name in the register.
Freemail on a fleet operator story
Gmail or similar on a company with dozens of trucks may indicate a broker or fake identity. Not proof alone, but worth an independently confirmed callback.
Email domain country mismatch with carrier VAT country
Domain country versus VAT country is a very weak signal. Often normal for international groups. Still confirm contact through an independent channel when pickup is imminent.
When you want contact and domain checks in one place
Every verification run includes contact and domain analysis alongside VIES and national registers.
- Booking email compared with register company data.
- Domain and website checked against register address and legal name.
- VAT and licence checked on the VAT ID you enter, not the display name in email.
Certica
Don't want to do this on every booking?
Certica pulls data from the same registers, checks it, and shows a clear result: what is OK, and what needs clarifying before loading.
Signals worth reviewing together
Across supported registers, checks that most often need human review before load assignment are email and domain mismatches, domains registered recently compared with company age, management or ownership changes in the company register, and transport licence scope that does not fit the booked lane.
These are risk signals, not proof of fraud. Clear them before you assign the load.
Official sources
FAQ
What makes a carrier email suspicious?
Freemail on a fleet operator, disposable domain, invisible characters, lookalike spelling, or a domain registered last week while KRS shows a ten-year-old company. Each is a risk signal, not automatic fraud.
How do I check a suspicious carrier domain quickly?
Check the creation date via RDAP or the registry when published. When unavailable, use historical signals: passive DNS first seen, MX history, Certificate Transparency, first website versions, or earlier domain activity. Compare with the company register extract on booking day alongside VAT and licence data.
Is Gmail always a fake carrier email?
No. Sole traders sometimes use freemail. The signal is stronger when register data shows a limited company, community licence, and multiple vehicles.
What should I do after a domain warning?
Use an independently found or previously confirmed contact channel: public contact from CEIDG or the transport register, the company website, a CRM contact, or a number confirmed on earlier loads. Do not rely only on the number in the suspicious email. Hold pickup details until the mismatch is explained or cleared.