Half of it never touches the load board.
The rate confirmation for a load nobody booked. The FMCSA notice that didn’t come from FMCSA. The “view your paperwork” link that points at a program instead of a document. LaneScout’s optional mail layer reads the email you have open, in your browser, and names the facts that don’t line up — before you click.
The mail layer is part of Pro — $15/mo. The extension itself is free and so are the badges on every load-board row; this half is not. You install free, sign in, and turn it on from the popup once you’re on Pro. What’s in each plan.
Add to Chrome — free Back to homeWhat it looks like
A banner above the message, listing what fired. Nothing is hidden, nothing is blocked, nothing is moved to spam. You read the line and decide.
Your rate confirmation for PO# 4471‑B has been successfully accepted
Dispatch <dispatch@rate-confirm-docs.example> · to me
Carrier E‑Rate Confirmation. Your carrier rate confirmation is ready.
Illustrative mock. The sender and the PO number are fabricated, the domain is
.example — a reserved suffix that cannot resolve — and no company is named, because a
picture of the banner does not need one. Note the tier: two ordinary facts, neither of them an
accusation, add up to worth verifying, not to a red alert. The pattern is not
invented: a document delivered as .exe, .msi or .scr is the
standard freight malware drop, which is why the check exists — and why .zip,
.pdf and .doc are deliberately not flagged. Real rate
cons travel as those, and a false alarm on every one of them would make the layer worthless.
You don’t need a load board for this part
The badge half of LaneScout needs a DAT One session to have anything to read. The mail layer does not. If you find your freight somewhere else, if you’re a brand-new authority still waiting on a board subscription, or if you’re the person in the office who opens the paperwork rather than the one who scans the board — the mail layer is the half that works for you without a board seat. It is the one half that costs something: Pro, $15/mo.
It also covers a different moment. The badge speaks before the call. The mail layer speaks after — at the rate con, the setup packet, the “update your carrier profile” notice. Those arrive whether or not you ever opened a load board that day.
What it checks
| Signal | What it means |
|---|---|
| Government impersonation | The message references FMCSA or DOT but was sent from a domain that isn’t a
.gov address. |
| Official link goes offsite | A “sign in / portal / verify” link in a message invoking FMCSA leads somewhere that
isn’t an official .gov site. |
| Look-alike broker domain | The sender’s domain is within a couple of characters of a registered broker’s FMCSA email domain, but is not the same domain. Checked against our mirror of the FMCSA broker file — roughly 30,000 records. |
| Executable link | A link points straight at a program file rather than a document. |
| Reported contact | The sender domain or a link host was reported to LaneScout in connection with impersonation and confirmed by a moderator. |
| New sender domain | The domain the mail came from was registered within the last 90 days. Suppressed when the domain is a registered broker’s own domain on the FMCSA record. |
| New link domain | The sender looks ordinary — an established address, sometimes a genuinely compromised one — but the destination behind the link is days old. |
| Display-name mismatch | The name on the message says one thing (“USDOT Compliance”); the address behind it is something else. |
| Account-action wording | Urgency plus a sign-in link. Supporting only — it never raises a banner on its own, because urgent wording with nothing else behind it is not evidence of anything. |
Each line on the banner is a checkable fact about the email in front of you. None of them is a statement about a company, and none of them is a verdict.
What leaves your machine
Read on your machine, and only there
The subject and the body are scanned locally, in the browser. That text is never transmitted,
never stored, and never seen by us. Neither is the link path — the .exe filename in
the example above is matched entirely on your side.
What we do receive
The sender’s domain and the hostnames the links point at — up to ten per message. That is what the denylist and the domain-age check need. Not addresses, not names, not content.
Off until you turn it on
Gmail access is an optional permission. Nothing is registered, requested or read until you switch the layer on in the extension popup, and Chrome shows its own permission prompt when you do.
Off means off
Switch the toggle back and the extension releases the permission and unregisters itself from Gmail. Not paused — released. The board badges keep working either way.
The full detail is in the privacy policy.
Turning it on
- Install the extension, then click the LaneScout icon in the Chrome toolbar.
- Sign in and upgrade to Pro from that popup — the mail layer is the Pro half. The toggle below it stays inert until then, and says so rather than switching on and doing nothing.
- Switch on Gmail impersonation protection. Chrome asks for permission for
mail.google.com; that prompt is Chrome’s, not ours. - Open a message. If nothing fires, nothing appears — which is the intended state for almost every email you will ever open.
If a Pro subscription lapses, the layer stops on its own: the extension unregisters itself from Gmail and releases the permission, the same as switching the toggle off. Nothing keeps reading your mail on a plan that no longer includes it.
What it does not do
Worth being plain about, because a tool that is vague about its limits gets trusted for things it can’t do:
- It doesn’t block, delete, or move anything. It adds a banner. Every message stays exactly where it was and stays fully readable.
- It doesn’t open attachments. It reads the message you have open — sender, subject, body text, link destinations. Files attached to it are not examined at all.
- It doesn’t scan your mailbox. Nothing runs on a list view; there is no crawl, no backfill, no history.
- Gmail on the web only —
mail.google.com. Not Outlook, not the mobile app, not a desktop mail client. - A quiet banner is not an all-clear. Nothing fired on the checks we run. That is a smaller claim than “this email is safe,” and we won’t make the bigger one.
Where the rest of it lives
The mail layer is one of three surfaces. The other two read the DAT One load board: a Clear / Caution / High Risk / Unverified badge on every broker row from the public FMCSA record, and a panel showing the actual lines behind it. See how the board side works, or read why pre-call vetting is the part that matters.
Add to Chrome — free Back to home