freightpassport.ai/verify

How to spot a fake
Freight Passport email.

We send you emails about trucks arriving at your dock, and those emails have links in them. Criminals know that. Freight fraud is, overwhelmingly, someone impersonating a party you already trust. So here is exactly how to tell our email from a forgery — in ninety seconds, and for good.

Every anti-phishing tip you have ever been handed — check the URL carefully, look for typos, does it feel urgent? — is a judgment call. At 6am, on a phone, with a truck at the gate, you will get some of them wrong. Everyone does. The three rules below require no judgment at all. They are not warning signs. They are facts about how this system is built, and they cannot become untrue.

The three rules

If any one of these is broken, the email is fake.

Not suspicious. Not probably. Fake. You do not need to check anything else.

01

We never ask you for a password.

Because there is no password. Freight Passport does not have one — not for you, not for your broker, not for anyone. There is no password of yours for a criminal to steal, and no login page of ours for one to copy. Anyone claiming to be us and asking you to sign in with a password is fake. No exceptions, ever.

Asks for a password → fake.
Why this is airtightThis is not a rule we follow. It is a thing the system does not contain. Accounts are optional here, and when someone does want one, they get a six-digit code sent to their inbox. We could not ask you for a password even if we wanted to — there is no field to type it into.
02

We never send a link that logs you in.

Every link in a Freight Passport email opens a load — one shipment, at one facility, on one day. That is all any of them do. None of them will ever sign you into an account. If a link that looks like it came from us drops you into a signed-in session, or into a dashboard, or into anything that greets you by name and asks you to continue — it is fake.

Signs you in → fake.
Why this is airtightWe never put anything in an email that can grant a session. This is the sharpest rule we own, and it cuts both ways: your mail scanner can fetch a link, but it cannot type a code into a form. So the only way into an account here is a code we send to an inbox you already control — never a link you clicked.
03

We never mention payment.

Not invoices. Not banking details. Not remittance, wire instructions, updated ACH information, or a past-due balance. Not ever, in any email, to anyone. Freight fraud is very often payment redirection — a real load, a real carrier, and one changed bank account. An email from us about money is fake, without exception, no matter how correct the load details in it look.

Mentions money → fake.
Why this is airtightFreight Passport does not handle payments. It has no invoicing, no remittance, no banking fields — none of that data exists anywhere in the product. We are not declining to email you about money. We have nothing to email you about.
The one field that cannot be faked

Trust the domain. Nothing else.

A logo can be copied in ten seconds. So can our layout, our wording, our colours, and the name that shows at the top of the message. The domain an email is sent from cannot be copied — we publish an internet-wide policy that tells every mail server on earth to reject anything claiming to be our domain that isn’t. So we teach you exactly one thing, and you never have to learn another.

Every Freight Passport email comes from
loads@notify.freightpassport.ai
Always. Nothing else is us.
One address. It has never changed and it is not going to.
Read everything after the @ — that is the part that matters.

We are .ai — never .com.

Our domain ends in .ai. There is a freightpassport.com and it is not us — we have never owned it and we have never sent a single email from it.

This is the one place people slip, because .com is what everyone assumes. An email from freightpassport.com is fake, always, without exception — no matter how right the rest of it looks. Read the end of the address, not the beginning.

This will not change. We are not moving to a different domain later, and we monitor the public certificate logs continuously for lookalikes — including that .com.

Do not trust the name you see.

In your inbox, our email shows up as something like this:

Arrowpoint Freight via Freight Passport

That string proves nothing. A display name is just text that anyone can type. A phisher can put those exact words — that exact spelling, that exact “via” — on an email sent from a domain they registered this morning, and your inbox will show it to you the same way it shows ours. The display name is decoration. The domain is the fact. Open the message, look at the actual sender address, and read what comes after the @.

Worked example

One real header. Two forgeries.

The display name is identical in all three. Only the domain gives them away.

Real
Arrowpoint Freight via Freight Passport
<loads@notify.freightpassport.ai>
Read it right-to-left: .aifreightpassport → and only then notify. The real, registered name is freightpassport.ai. notify is just a room inside our house.
Forgery Fake
Arrowpoint Freight via Freight Passport
<loads@notify.freightpassport-alerts.com>
The registered domain here is freightpassport-alerts.com — a completely different company, which anyone can buy for a few dollars. Our name being inside it means nothing. The hyphen is the tell, and it is the whole tell.
Forgery Fake
Arrowpoint Freight via Freight Passport
<loads@freightpassport.notify-loads.com>
Nastier, because it opens with our exact name. But read right-to-left and the registered domain is notify-loads.com. “freightpassport” here is just a room inside somebody else’s house — and they chose the name of the room to fool you.

Read a domain right-to-left. Always.

This is the only technique on the page, and it takes two seconds. A domain is read backwards from the end. Whoever owns the last two parts owns the email — everything to the left of that, they made up.

loads@notify.freightpassport.ai
← ← ← read this way
freightpassport.aiThe registered domain. The only part anyone had to prove they owned. This is the fact.
notify.A subdomain — a room inside that house. Whoever owns the house names the rooms, and can name one anything at all.
loads@A mailbox. Means nothing on its own.

So: find the last dot, take the one word to its left, and ask “is that word exactly freightpassport, followed by .ai?” If there is a hyphen in it, an extra word in it, a different spelling — or if it ends in .comit is not us, and nothing else in the email can change that.

If you think you got a fake.

Three steps. In this order. It takes under a minute and it may save a truckload.

01

Don't click.

Not the link, not the attachment, not the unsubscribe. Don’t reply either — a reply tells them the mailbox is live and a human reads it.

02

Forward it to us.

Send it to phishing@freightpassport.ai. Forward the whole message if you can — the headers are what we need. No detail, no apology, no explanation required.

03

Call your broker.

Use a number you already have — one from your own records, a past invoice, your phone. Never a number printed in the email you are suspicious of. That is the oldest trick there is.

The part nobody else will say out loud

Why we’re asking you to click links at all.

We are aware of what we are doing. We send freight emails with links in them, to people at docks, and we are asking them to click. That is the exact habit fraudsters exploit — and we are, in a small way, training it.

We could pretend that isn’t true. We would rather tell you, because it is the reason you should believe anything else on this page. If we are going to train a dangerous habit, we have to own the pattern before someone else uses it against you with our name on it. So here is what we did about it — not policies, but properties. Things the system cannot do:

One domain, forever
Every email we will ever send comes from notify.freightpassport.ai. Not your broker’s domain, not a campaign domain, not a new one next quarter. One string for you to learn, once.
DMARC at p=reject
We instruct every receiving mail server in the world to reject — not flag, reject — any message that forges our domain. That is why the domain is the one thing on this page worth memorising.
No passwords anywhere
Not for you, not for brokers, not for staff. There is no credential in this system to phish.
No link grants a session
Nothing we mail you can log anyone in. A stolen link exposes one load, which the thief already knew about — never an account.
No payment content, ever
The product holds no banking data and sends no invoices, so the highest-value fraud in freight has nothing here to redirect.
Opening is never acting
Merely fetching one of our links changes nothing — not a confirmation, not a flag, not a record. Corporate mail scanners open every link in every email before you see it, and we built for that. Acting on a load is always a deliberate, separate step you take on the page, with your eyes open.
A verified sender mark
Planned, not live. It will put our logo in the inbox next to the message, backed by a certificate — we are working through the trademark it requires. Until you see it here described as live, do not treat a logo as evidence of anything.

Every one of those is a fact about the machine, not a promise about our behaviour. Promises can be broken quietly. These would take a rewrite — and you would be able to tell.

Freight Passport · Logixtecs Solutions LLC
We send from exactly one address, always: loads@notify.freightpassport.ai
We never ask for a password · No link of ours logs you in · We never discuss payment
Suspicious message? phishing@freightpassport.ai · This page lives at freightpassport.ai/verify and is linked from the footer of every email we send.