Identity fraud arrives by email. Verify it there.
Nobody steals a load by walking into your office. They email you — from a domain one character off a real carrier's, quoting under a hijacked authority, sounding exactly like the hundred legitimate carriers in the same inbox. Keelway runs identity checks on every inbound carrier email, at the moment it lands, before anyone can book the wrong "carrier."
How the fraud actually works
Freight fraud coverage in the trade press — FreightWaves, CCJ, Overdrive — keeps describing the same entry point. The spoofed domain: a fraudster registers something one character off a real carrier's domain and quotes on loads under that carrier's good name. The hijacked identity: contact records or credentials on a legitimate authority get taken over, sometimes around an ownership change, and loads booked against it disappear or get re-brokered. The chameleon: a revoked operator opens a fresh authority and starts clean on paper. Congress and FMCSA have both turned attention to registration fraud for exactly this reason.
Notice what every variant has in common: the first contact with the victim is an email that looks routine. The load board posting was real. The rate discussion reads normally. The tells are in metadata a busy coordinator never checks — domain registration age, contact-record mismatches, the gap between the authority quoted and the identity claimed.
What Keelway checks on every inbound carrier email
Does the email match the registration?
Does the authority match the claim?
Is this authority what it says it is?
One number, reasons attached
What to do on a red flag
- Don't reply to the flagged thread. A fraudster who knows they're caught rotates domains and tries again.
- Verify out-of-band. Call the phone number on the FMCSA registration — never the one in the email signature — and ask if they quoted your load.
- Check the artifact. Read the domain character by character. Our carrier email red flags tool lists the patterns worth memorizing.
- Log the decision. In Keelway, override with a note or decline with a reason — either way it lands on the carrier's permanent record, so the next coordinator sees the history.
Layered defense: identity, vetting, monitoring
Keelway is an AI platform that automates carrier email triage for freight brokers — turning 40+ carrier replies per posted load into a ranked, vetted shortlist in under a second. Identity verification is one of three layers in that pipeline. Vetting covers fitness — authority, insurance on file, safety history, detailed on the carrier onboarding page. Monitoring covers change — re-checks at acceptance and pickup, covered under continuous carrier monitoring. For the deeper fraud layer, Fraud Shield ($199/mo flat, in beta) adds phishing-pattern checks and rate-con interception alerts on top.
If you're also evaluating network-layer identity products like Highway, read our honest Highway comparison — the layers are complementary, and the inbox layer is the one that sees the actual fraudulent email. For the fraud pattern this all defends against, start with what double brokering is.
Frequently asked questions
What is carrier identity verification?+
How does carrier identity fraud actually work?+
Why is the inbox the right place to verify identity?+
What identity signals does Keelway check?+
What should I do when an identity flag fires?+
Is identity verification enough by itself?+
Verify every carrier at the moment they email you.
Related
The deeper fraud layer — chameleon patterns, phishing checks, rate-con interception.
The email-layer tells of carrier impersonation, listed.
Every risk rule CarrierVet runs on an FMCSA record, explained.
The fraud pattern identity verification exists to stop.
When to work with fresh authorities — and how to tell honest new carriers from chameleons.