How to spot a fake
Freight Passport email.
We send you emails about trucks arriving at your dock, and those emails have links in them. Criminals know that. Freight fraud is, overwhelmingly, someone impersonating a party you already trust. So here is exactly how to tell our email from a forgery — in ninety seconds, and for good.
Every anti-phishing tip you have ever been handed — check the URL carefully, look for typos, does it feel urgent? — is a judgment call. At 6am, on a phone, with a truck at the gate, you will get some of them wrong. Everyone does. The three rules below require no judgment at all. They are not warning signs. They are facts about how this system is built, and they cannot become untrue.
If any one of these is broken, the email is fake.
Not suspicious. Not probably. Fake. You do not need to check anything else.
We never ask you for a password.
Because there is no password. Freight Passport does not have one — not for you, not for your broker, not for anyone. There is no password of yours for a criminal to steal, and no login page of ours for one to copy. Anyone claiming to be us and asking you to sign in with a password is fake. No exceptions, ever.
We never send a link that logs you in.
Every link in a Freight Passport email opens a load — one shipment, at one facility, on one day. That is all any of them do. None of them will ever sign you into an account. If a link that looks like it came from us drops you into a signed-in session, or into a dashboard, or into anything that greets you by name and asks you to continue — it is fake.
We never mention payment.
Not invoices. Not banking details. Not remittance, wire instructions, updated ACH information, or a past-due balance. Not ever, in any email, to anyone. Freight fraud is very often payment redirection — a real load, a real carrier, and one changed bank account. An email from us about money is fake, without exception, no matter how correct the load details in it look.
Trust the domain. Nothing else.
A logo can be copied in ten seconds. So can our layout, our wording, our colours, and the name that shows at the top of the message. The domain an email is sent from cannot be copied — we publish an internet-wide policy that tells every mail server on earth to reject anything claiming to be our domain that isn’t. So we teach you exactly one thing, and you never have to learn another.
Read everything after the @ — that is the part that matters.
We are .ai — never .com.
Our domain ends in .ai. There is a freightpassport.com and it is not us — we have never owned it and we have never sent a single email from it.
This is the one place people slip, because .com is what everyone assumes. An email from freightpassport.com is fake, always, without exception — no matter how right the rest of it looks. Read the end of the address, not the beginning.
This will not change. We are not moving to a different domain later, and we monitor the public certificate logs continuously for lookalikes — including that .com.
Do not trust the name you see.
In your inbox, our email shows up as something like this:
That string proves nothing. A display name is just text that anyone can type. A phisher can put those exact words — that exact spelling, that exact “via” — on an email sent from a domain they registered this morning, and your inbox will show it to you the same way it shows ours. The display name is decoration. The domain is the fact. Open the message, look at the actual sender address, and read what comes after the @.
One real header. Two forgeries.
The display name is identical in all three. Only the domain gives them away.
<loads@notify.freightpassport.ai>
<loads@notify.freightpassport-alerts.com>
<loads@freightpassport.notify-loads.com>
Read a domain right-to-left. Always.
This is the only technique on the page, and it takes two seconds. A domain is read backwards from the end. Whoever owns the last two parts owns the email — everything to the left of that, they made up.
So: find the last dot, take the one word to its left, and ask “is that word exactly freightpassport, followed by .ai?” If there is a hyphen in it, an extra word in it, a different spelling — or if it ends in .com — it is not us, and nothing else in the email can change that.
If you think you got a fake.
Three steps. In this order. It takes under a minute and it may save a truckload.
Don't click.
Not the link, not the attachment, not the unsubscribe. Don’t reply either — a reply tells them the mailbox is live and a human reads it.
Forward it to us.
Send it to phishing@freightpassport.ai. Forward the whole message if you can — the headers are what we need. No detail, no apology, no explanation required.
Call your broker.
Use a number you already have — one from your own records, a past invoice, your phone. Never a number printed in the email you are suspicious of. That is the oldest trick there is.
Why we’re asking you to click links at all.
We are aware of what we are doing. We send freight emails with links in them, to people at docks, and we are asking them to click. That is the exact habit fraudsters exploit — and we are, in a small way, training it.
We could pretend that isn’t true. We would rather tell you, because it is the reason you should believe anything else on this page. If we are going to train a dangerous habit, we have to own the pattern before someone else uses it against you with our name on it. So here is what we did about it — not policies, but properties. Things the system cannot do:
Every one of those is a fact about the machine, not a promise about our behaviour. Promises can be broken quietly. These would take a rewrite — and you would be able to tell.
We send from exactly one address, always: loads@notify.freightpassport.ai
We never ask for a password · No link of ours logs you in · We never discuss payment
Suspicious message? phishing@freightpassport.ai · This page lives at freightpassport.ai/verify and is linked from the footer of every email we send.