Industry Brief — Logistics & Supply Chain

A truckload can be stolen with a domain name

Freight brokers, carriers, 3PLs, terminals and customs agents exchange binding documents with counterparties they have never met, on timelines measured in hours. Screening every domain in that exchange against a continuously verified list of live phishing infrastructure is the cheapest control in the chain.

390,000+Active phishing domains tracked
<50msTypical lookup response time
24hFull database rebuild cycle
100Domains per batch request
The structural problem

Freight runs on documents from strangers

Every load is a chain of one-off relationships held together by PDFs and email, and each link is an opportunity to insert a lookalike domain.

A single shipment from a factory gate to a retail distribution centre passes through more independent organisations than almost any other commercial process. A shipper tenders the load to a broker. The broker posts it to a load board and awards it to a carrier that may have been onboarded that morning. The carrier assigns a driver, possibly an owner-operator subcontracted through a second carrier. A warehouse receives it, a customs agent clears it if it crosses a border, a terminal schedules a gate appointment for it, and a consignee signs for it. Most of those parties have no trading history with each other and no shared identity system, yet within a few hours they must exchange rate confirmations, carrier packets, bills of lading, delivery notes and invoices, and act on each one as if it were authentic.

The documents themselves are unremarkable. A rate confirmation is a PDF. A carrier packet is a bundle of a signed authority letter, a certificate of insurance, a W-9 or VAT registration, and a set of bank details for settlement. A bill of lading is a form. None of these artefacts carries a cryptographic signature that a receiving clerk can check, and almost all of them arrive by email from an address that the recipient has never seen before because the counterparty is new. The only identity signal available at the moment of decision is the sending domain, and that signal is trivially cheap to forge. A domain that differs from a legitimate carrier's by one character, or that appends a plausible word such as "logistics", "dispatch" or "freight" to a known name, costs a few dollars and can be registered, given a mailbox and put to work in under an hour.

This is what makes carrier impersonation the most economically attractive fraud in the sector. In double-brokering, a fraudster poses as an established carrier, wins a tendered load from a broker using copied authority documents and a lookalike domain, then re-brokers that load to a genuine carrier who actually hauls it. The fraudster collects payment from the original broker and never pays the hauler, or, in the more damaging variant, the fraudster takes the load itself. Strategic cargo theft of this kind does not require a lockpick or a fence at the gate. It requires an email domain that a dispatcher glances at for two seconds, a copied operating authority number, and a bank account that will be closed by the weekend. The value at risk is the full replacement cost of the freight, and for pharmaceuticals, consumer electronics or high-value food commodities a single trailer can carry six figures of goods.

The industry's operating tempo is precisely what makes verification hard. Detention charges accrue by the hour. A missed appointment window at a distribution centre can push a delivery days to the right. Load boards reward the broker who covers freight fastest, and a carrier compliance officer who takes an extra day to call back an unfamiliar counterparty on a number found independently is a carrier compliance officer whose lanes go uncovered. So the checks compress. The packet is reviewed for completeness rather than authenticity. The insurance certificate is filed rather than confirmed with the issuing agent. The domain is read but not examined. Speed is not carelessness here, it is the commercial requirement of the job, which is why the control that survives has to be one that costs milliseconds rather than a phone call.

The same structural weakness runs downstream to the consignee and the consumer. Delivery notification emails and text messages are the one category of unsolicited message that almost everyone is expecting to receive, because almost everyone is waiting for a parcel. That expectation is what fraudsters monetise with fake redelivery-fee and customs-duty pages, and the reputational cost lands on the carrier and the retailer whose brand is on the message. An e-commerce and retail operation and its logistics provider are effectively defending the same inbox from opposite ends. The domain-level answer is the same in both directions: know, at the moment a document or a link is handled, whether the domain involved is currently resolving as part of live phishing infrastructure.

Threat landscape

Six fraud patterns in freight and supply chain

Each one begins with a domain that looks close enough to a known counterparty to survive a two-second glance.

These six patterns account for most of the domain-borne fraud that transport managers, carrier compliance officers and accounts payable supervisors actually encounter. They differ in who is targeted and what is stolen, but they share a mechanism: a registered domain, resolving at the moment of the attack, that impersonates a party in the chain. Some of that infrastructure is bespoke and short-lived. A great deal of it is recycled across campaigns and appears in threat-intelligence collection days before it reaches a specific dispatcher.

That overlap is the operational opening. A lookup against a continuously refreshed set of DNS-verified phishing domains will not catch a domain registered twenty minutes ago for a single target, and no honest control claims otherwise. What it does catch is the substantial share of activity that runs on infrastructure already observed elsewhere, and it does so without asking anyone in the chain to slow down. The check is a lookup, not an investigation.

Carrier and broker impersonation

A fraudster registers a near-copy of an established carrier's domain, replies to a load board posting, and receives a rate confirmation for freight it never intends to deliver. The dispatcher sees a familiar company name and a plausible email address; the trailer is gone by the time anyone calls the real carrier.

Double-brokering with forged authority

Copied operating authority letters, altered insurance certificates and a lookalike sender domain get a fake carrier through onboarding. The load is re-brokered to a genuine hauler who delivers it and is never paid, leaving the original broker facing a duplicate claim and a chargeback dispute.

Delivery and customs-fee smishing

Consignees and consumers receive tracking updates demanding a small redelivery or customs charge on a page hosted at something like parcel-duty-clearance.example.com. The card details harvested there are secondary; the reputational damage attaches to the carrier and the retailer named in the message.

Supplier invoice redirection

An accounts payable team receives a routine invoice from a haulier or a packaging supplier, sent from a domain one character off the real one, with new bank details and a note about a corporate restructure. Payment terms in freight are short, so the money often moves before the genuine supplier chases the overdue balance.

Terminal appointment credential theft

Drayage operators and hauliers are phished for their logins to a port community system or terminal appointment portal. Stolen credentials let an attacker book slots, view container release information and, in the worst outcome, arrange collection of a container by a truck that has no business at the gate.

Booking platform account takeover

Shipping line portals and forwarder booking platforms hold rate agreements, container bookings and release instructions. A credential-harvesting page cloned from the real login screen gives an attacker the ability to amend a booking, redirect a consignment or quietly read a company's entire forward shipping plan.

Where the control lands

The document journey, and where a check fits

One load produces a predictable sequence of documents, and every one of them carries domains worth screening.

Follow a single truckload and the paperwork sequence is almost always the same. The shipper sends a load tender, which in EDI terms is the 204 transaction set, the message that offers a shipment to a carrier with its stops, weights and appointment windows. The carrier accepts and a rate confirmation goes back, fixing the linehaul rate and accessorials. If the carrier is new, a carrier packet arrives alongside it. On pickup a bill of lading is issued, status messages flow back through the 214 transaction set as the shipment moves, a proof of delivery is signed at the consignee, and finally the carrier invoices, which in EDI is the 210. Between the structured EDI messages sit dozens of unstructured emails, because in practice exceptions, appointment changes and document corrections are negotiated in free text.

The screening point that produces the most value per lookup is carrier onboarding, because that is where a fraudulent counterparty is admitted to the chain and where every subsequent document inherits its assumed legitimacy. A carrier packet is a rich source of domains: the sender address, the domain in the letterhead, the URL on the insurance certificate, the address used for remittance queries and the website listed on the authority letter. Extract them, deduplicate them and screen them together. A packet in which the remittance contact sits on a different domain from the operating authority, and that domain is already known phishing infrastructure, is not an edge case requiring judgement. It is a stop.

The second screening point is outbound. Before a tracking notification, appointment reminder or document-request link goes out to a consignee, screen the domains it contains. Notification templates are frequently assembled from partner-supplied tracking URLs, forwarder portals and short links, and a compromised partner can put a hostile domain into a message that carries your brand. Screening outbound content protects the recipient and protects the sender's ability to say, credibly, that its own notifications were checked. Both points use the same endpoint, and the batch endpoint accepts up to 100 domains per request, which comfortably covers a packet or a notification batch in one call.

One load, six documents, two checkpoints

The green nodes mark where a domain extraction and screening step fits without adding a manual review stage.

Load tender (204)
Rate confirmation
Carrier packet
Bill of lading
POD & notifications
Invoice (210)

The checks are placed where a new domain first enters the process and where domains leave it toward a customer, not on every hop in between.

Screening the domains in a carrier onboarding packet
curl -X POST https://phishingdetectionapi.com/api/v1/batch \
  -H "Content-Type: application/json" \
  -d '{
    "apikey": "YOUR_API_KEY",
    "domains": [
      "midlands-haulage-group.example.com",
      "midlands-haulage-remittance.example.net",
      "certs.insurance-broker.example.org",
      "dispatch-midlandshaulage.example.io"
    ]
  }'

# Response
{
  "results": [
    {"domain":"midlands-haulage-group.example.com","is_phishing":false,"category":null,
     "dns_status":null,"confidence":0.0},
    {"domain":"midlands-haulage-remittance.example.net","is_phishing":true,
     "category":"phishing/malware","dns_status":"resolves","confidence":0.98},
    {"domain":"certs.insurance-broker.example.org","is_phishing":false,"category":null,
     "dns_status":null,"confidence":0.0},
    {"domain":"dispatch-midlandshaulage.example.io","is_phishing":true,
     "category":"phishing/malware","dns_status":"resolves","confidence":0.98}
  ],
  "checked": 4,
  "phishing_found": 2,
  "credits_used": 4
}
Screening links in tracking notifications before they reach consignees
import re, requests
from urllib.parse import urlparse

API = "https://phishingdetectionapi.com/api/v1/batch"
KEY = "YOUR_API_KEY"

def unsafe_domains(message_bodies):
    """Return domains in outbound shipment notifications that are
    currently listed as active phishing infrastructure."""
    found = set()
    for body in message_bodies:
        for url in re.findall(r'https?://[^\s"\'<>]+', body):
            host = urlparse(url).netloc.split(':')[0].lower()
            if host:
                found.add(host)

    flagged = []
    domains = sorted(found)
    for i in range(0, len(domains), 100):        # batch limit is 100
        r = requests.post(API, json={"apikey": KEY,
                                     "domains": domains[i:i + 100]}, timeout=10)
        r.raise_for_status()
        flagged += [x["domain"] for x in r.json()["results"] if x["is_phishing"]]
    return flagged

# hold the batch, alert the notification owner, do not send
blocked = unsafe_domains(pending_shipment_emails)
if blocked:
    quarantine_batch(reason="phishing domain in tracking link", domains=blocked)
Integration surface

Six systems where the lookup belongs

A domain check is worth little as a standalone tool and a great deal as a field inside the system where the decision is already being made.

Transport management system

Screen the domains attached to every carrier and customer record in the TMS, on creation and on any change to contact or remittance details. A flagged result becomes a hold on the record rather than an email nobody reads.

Load board integrations

Carriers reached through load board postings are the least-known counterparties in the business. Screen the responding domain at the moment of first contact, before a rate confirmation is generated and while declining still costs nothing.

Carrier onboarding and vetting

Add the lookup to the vetting workflow alongside authority, insurance and safety-score checks. The carrier compliance officer gets a recorded result on every domain in the packet instead of a subjective judgement about whether an address looks right.

Accounts payable workflow

Screen the sender and remittance domains on invoice intake and on any bank-detail change request. The result is stamped on the payment record, which is what an auditor or an insurer will want to see after a disputed transfer.

Customer notification platform

Every tracking update, appointment reminder and document-request message carries links. Screening them before dispatch keeps partner-supplied or template-injected domains from going out under your brand to thousands of consignees.

Yard and terminal appointment portal

Terminal operating systems and appointment portals are credential targets. A terminal operations manager can screen the domains in inbound haulier correspondence and in any link sent to portal users, protecting the gate schedule and container release process.

Finance operations

What changes in accounts payable

Freight settlement is high-volume, low-margin and fast, which is exactly the profile invoice fraud is built for.

A mid-sized 3PL settles thousands of carrier invoices a month against rate confirmations, and each one is a small transaction reviewed quickly. Nobody scrutinises a four-figure haulage invoice the way they would scrutinise a capital purchase, and the fraudsters know it. The productive attack is not a fabricated invoice for an implausible amount, it is a genuine-looking invoice for an ordinary amount from a supplier that really exists, sent from a domain that differs from the real one by a transposed letter or an added hyphen, with a request to update the remittance account. The accounts payable supervisor is not being careless when this succeeds. They are processing at the rate the business requires.

Adding a domain lookup to invoice intake changes the shape of the review rather than its speed. Instead of asking a clerk to eyeball a sender address, the system compares the sender and remittance domains against the vendor master and screens both against the phishing database. Most invoices pass in under fifty milliseconds and are never seen by a human differently than before. The small number that produce a mismatch or a hit are routed to a hold queue with a specific reason attached, which is a far better prompt for a callback than a general instruction to stay vigilant. A callback to a number taken from the vendor master rather than from the invoice remains the definitive control, and the lookup is what tells you which of a thousand invoices deserves one.

The second place this matters is the change request itself. Bank-detail changes, new remittance addresses and vendor master updates should be treated as a distinct category of transaction with their own evidence requirements, because they are what the fraud is actually trying to achieve. A screening result recorded against the change request, showing the domain checked, the verdict and the timestamp, converts a soft procedural expectation into an artefact. That artefact is what supports a claim, satisfies an auditor, and gives a finance director something concrete to show a customer whose payment was misdirected. Teams in banking and financial services have run controls of this kind for years; freight settlement is only now catching up.

Invoice intake

Extract the sender domain and any domains in the remittance block, screen them in one batch call, and attach the verdict to the invoice record before it enters the approval queue. Clean invoices continue untouched; hits stop at a hold queue with a named reason.

Bank-detail change requests

Treat every request to change payment details as its own transaction type. Screen the requesting domain, compare it against the domain of record, and require an independent callback whenever either the comparison or the lookup raises a question.

Vendor master updates

New carriers, forwarders and warehouse partners enter the vendor master constantly. Screening the domain at creation, and re-screening periodically from the daily feed, keeps a record that was clean at onboarding from ageing quietly into a liability.

The audit trail a documented check creates

The value of a recorded lookup outlives the individual payment it protects. When a load is lost or a payment is misdirected, the questions that follow come from insurers, from a customer's legal team, from an internal auditor and sometimes from a regulator, and they are all versions of the same question: what did you check, and when. A stored verdict with a domain, a timestamp and a result answers it directly, where a policy document only describes an intention. Because the database is rebuilt every 24 hours and each retained domain has been confirmed to resolve, the record also says something a static blocklist cannot: that the domain was live infrastructure at the moment it was screened. That is the difference between a control you can evidence and a control you merely assert. Full pricing for lookup volume is on the pricing page, and the continuously updated export is described on the daily feed page.

Anatomy of an attack

How a double-brokering attempt unfolds

Five stages from a registered domain to a trailer that never arrives, and the points where a domain check interrupts the sequence.

1

The domain is registered and dressed

An attacker selects a carrier with a solid safety record and registers something adjacent to its real domain, for example midlandshaulage-dispatch.example.com. Mailboxes are created, a one-page website copies the carrier's public information, and the domain begins resolving. Where that domain has already been used against another target, it is likely to have been collected, verified as resolving and loaded into the database before the first email is sent.

2

The packet is submitted to onboarding

A carrier packet arrives with a copied authority letter, an altered certificate of insurance and bank details that belong to a mule account. It is complete, well-formatted and internally consistent, because it was built from a real carrier's genuine documents. The only thing that does not match is the domain, and a manual reviewer comparing it to a name they half-remember will usually let it through.

Interruption point: screen every domain in the packet
3

A load is awarded and confirmed

The fraudulent carrier bids on a posting, wins the freight and receives a rate confirmation. From this moment the attacker holds the pickup number, the shipper's address, the appointment window and a description of the goods, which is enough to arrive at the origin facility looking exactly like the carrier that was booked. High-value commodities are selected deliberately at this stage.

Interruption point: screen the responding domain at first contact
4

The load is collected or re-brokered

Either a driver working for the attacker collects the freight directly, or the load is re-posted and awarded to a genuine carrier who is told to deliver to an address that is not the real consignee. In the second case an innocent hauler performs the theft in good faith, which makes recovery and prosecution considerably harder and stretches the timeline before anyone notices.

5

The trail goes cold

The delivery window passes, the consignee reports a no-show, and the broker calls the real carrier, who has never heard of the load. By then the mailbox is abandoned, the bank account is emptied and the domain may already have stopped resolving, which is why a database that prunes dead domains and rebuilds daily reflects live infrastructure rather than a historical list. The claim, the customer conversation and the insurance process follow, and all of them turn on what was checked at stage two.

Evidence point: the stored verdict and timestamp
Operational economics

What the control costs against what a load is worth

The arithmetic is unusually simple, because the unit of loss in this sector is large and the unit of prevention is very small.

04:30
UTC daily feed export
50
Concurrent DNS threads
10s
DNS resolution timeout
12 mo
Credit validity window

Lookups are sold as credit packs, one credit per domain checked, and the rate falls with volume. The Starter pack is $59 for 10,000 lookups, which is $0.0059 each; Professional is $249 for 100,000 at $0.0025; Business is $499 for 250,000 at $0.0020; and the largest pack, Scale, is $3,999 for 5,000,000 lookups at $0.0008 each. Credits stay valid for twelve months. Set that against the value of one trailer of consumer electronics, one misdirected settlement run, or the cost of covering a lane again at spot rates after a load disappears, and the comparison does not need modelling. A broker screening every domain in every carrier packet, at perhaps eight domains per packet, gets through a great many onboardings before the cost approaches a single incident. A 14-day refund policy applies to unused credits where under 10% have been consumed.

Organisations that would rather hold the data than call an endpoint can subscribe to the daily threat feed from $499 per month, with annual plans available. The feed is a full CSV or JSON export of the database, delivered as domain,category,dns_status, and it is the right shape for a 3PL that wants to run its own DNS filtering across depots, driver tablets and terminal offices rather than integrating a lookup into each application. The export runs at 04:30 UTC once the day's rebuild is complete, and every domain in it has been resolved through rotating proxies using 50 concurrent threads with a 10 second timeout, so what lands in your resolver is infrastructure that was answering DNS that morning. Teams weighing the feed against per-lookup calls will find the wider partner-vetting picture in the supply chain use case, and those wiring the lookup into mail flow should start with email security. Registration for an API key is at the registration page.

Obligations

Regulatory and contractual context

Transport sits inside a widening set of security expectations, and the sharpest of them arrive through customer contracts rather than statute.

In the European Union, NIS2 names transport among the sectors it covers, alongside energy, health, digital infrastructure, public administration and postal services. For operators that fall in scope, the directive raises expectations around cybersecurity risk management and introduces incident-reporting duties to national authorities, together with accountability at management level for the adequacy of those measures. The practical consequence for a logistics operator is that security is no longer purely an IT budget line defended internally. Whether a specific carrier, forwarder or terminal operator is in scope depends on national transposition and on size and criticality thresholds, so the sensible step is a scoping assessment with counsel rather than an assumption in either direction. What is clear is the direction of travel, and that being able to describe a documented, mechanical control over inbound and outbound domains is easier than describing a training programme.

Customs and trusted-trader programmes add a second layer. Authorised Economic Operator status in the European Union and C-TPAT membership in the United States both grant tangible benefits, such as fewer inspections and faster clearance, in exchange for meeting supply-chain security criteria. Those criteria are broader than physical security. In general terms they cover the vetting of business partners, the integrity of the information used to make customs declarations, and the protection of the systems in which that information is held. A control that screens the domains of new partners and of the correspondence carrying declaration data sits comfortably inside that expectation. Programme requirements differ between jurisdictions and are periodically revised, so treat this as an area to confirm against the current published criteria and your customs broker's guidance rather than a checklist to be inferred from a web page.

Where consignee personal data is processed, GDPR applies in the ordinary way. Delivery notifications necessarily involve names, addresses, phone numbers and sometimes access instructions, and Article 32 requires security measures appropriate to the risk. Screening the domains in outbound notification traffic is a defensible measure under that heading, because the risk being managed is the misuse of a communication channel that the recipient trusts precisely because the carrier's brand is on it. If personal data is compromised, Articles 33 and 34 govern notification, with the well-known 72 hour window for informing the supervisory authority. Carriers running large notification volumes should be able to describe what happens to a batch that contains a flagged link, and who owns that decision.

The most immediate pressure, though, is contractual. Large shippers and retailers now write security clauses into 3PL and carrier agreements that flow their own obligations down the chain, and those clauses have grown considerably more specific over the last few years. They commonly require the provider to maintain an information security programme, to notify the customer of incidents within a defined period, to vet subcontractors, to complete security questionnaires, and to accept audit rights. Where a customer is itself subject to NIS2, DORA or sector regulation, or is a public company subject to US cybersecurity disclosure rules, its incentive to push those requirements outward is strong. A 3PL account director will meet these clauses in commercial negotiation long before a regulator ever appears.

None of this makes a domain-reputation lookup a compliance product, and it should not be sold internally as one. It is a lookup: a fast, evidenced answer to whether a domain is currently resolving as part of known phishing infrastructure. What it contributes to a framework such as ISO/IEC 27001, SOC 2 or the NIST Cybersecurity Framework is a documented technical control with a machine-generated record, applied at the two points where an outside party enters and leaves the process. That is a genuinely useful thing to have in a questionnaire response, and it is far more persuasive than a policy statement. Related sector views are available for energy and utilities and for manufacturing, both of which share the partner-vetting problem in a different form.

Keep reading

Related material

Deeper treatments of the same control applied to neighbouring parts of the chain.

Put a check between a stranger's document and your freight

Screen carrier packets, supplier invoices and outbound tracking links against hundreds of thousands of DNS-verified active phishing domains, rebuilt every 24 hours and answered in under 50 milliseconds.