LaneScout

Half of it never touches the load board.

The rate confirmation for a load nobody booked. The FMCSA notice that didn’t come from FMCSA. The “view your paperwork” link that points at a program instead of a document. LaneScout’s optional mail layer reads the email you have open, in your browser, and names the facts that don’t line up — before you click.

The mail layer is part of Pro — $15/mo. The extension itself is free and so are the badges on every load-board row; this half is not. You install free, sign in, and turn it on from the popup once you’re on Pro. What’s in each plan.

Add to Chrome — free Back to home

What it looks like

A banner above the message, listing what fired. Nothing is hidden, nothing is blocked, nothing is moved to spam. You read the line and decide.

Your rate confirmation for PO# 4471‑B has been successfully accepted

LaneScout: worth verifying
• A link in this email points directly to an executable file (Rate_Confirmation_PO_4471B.exe) — freight documents are never sent as programs
• The sender’s domain (rate-confirm-docs.example) was registered 6 days ago
Factual signals, not a verdict. FMCSA never asks you to sign in from an email link — go to fmcsa.dot.gov directly.

Dispatch <dispatch@rate-confirm-docs.example>  ·  to me

Carrier E‑Rate Confirmation. Your carrier rate confirmation is ready.

Click here to view your rate confirmation

Illustrative mock. The sender and the PO number are fabricated, the domain is .example — a reserved suffix that cannot resolve — and no company is named, because a picture of the banner does not need one. Note the tier: two ordinary facts, neither of them an accusation, add up to worth verifying, not to a red alert. The pattern is not invented: a document delivered as .exe, .msi or .scr is the standard freight malware drop, which is why the check exists — and why .zip, .pdf and .doc are deliberately not flagged. Real rate cons travel as those, and a false alarm on every one of them would make the layer worthless.

You don’t need a load board for this part

The badge half of LaneScout needs a DAT One session to have anything to read. The mail layer does not. If you find your freight somewhere else, if you’re a brand-new authority still waiting on a board subscription, or if you’re the person in the office who opens the paperwork rather than the one who scans the board — the mail layer is the half that works for you without a board seat. It is the one half that costs something: Pro, $15/mo.

It also covers a different moment. The badge speaks before the call. The mail layer speaks after — at the rate con, the setup packet, the “update your carrier profile” notice. Those arrive whether or not you ever opened a load board that day.

What it checks

SignalWhat it means
Government impersonation The message references FMCSA or DOT but was sent from a domain that isn’t a .gov address.
Official link goes offsite A “sign in / portal / verify” link in a message invoking FMCSA leads somewhere that isn’t an official .gov site.
Look-alike broker domain The sender’s domain is within a couple of characters of a registered broker’s FMCSA email domain, but is not the same domain. Checked against our mirror of the FMCSA broker file — roughly 30,000 records.
Executable link A link points straight at a program file rather than a document.
Reported contact The sender domain or a link host was reported to LaneScout in connection with impersonation and confirmed by a moderator.
New sender domain The domain the mail came from was registered within the last 90 days. Suppressed when the domain is a registered broker’s own domain on the FMCSA record.
New link domain The sender looks ordinary — an established address, sometimes a genuinely compromised one — but the destination behind the link is days old.
Display-name mismatch The name on the message says one thing (“USDOT Compliance”); the address behind it is something else.
Account-action wording Urgency plus a sign-in link. Supporting only — it never raises a banner on its own, because urgent wording with nothing else behind it is not evidence of anything.

Each line on the banner is a checkable fact about the email in front of you. None of them is a statement about a company, and none of them is a verdict.

What leaves your machine

Read on your machine, and only there

The subject and the body are scanned locally, in the browser. That text is never transmitted, never stored, and never seen by us. Neither is the link path — the .exe filename in the example above is matched entirely on your side.

What we do receive

The sender’s domain and the hostnames the links point at — up to ten per message. That is what the denylist and the domain-age check need. Not addresses, not names, not content.

Off until you turn it on

Gmail access is an optional permission. Nothing is registered, requested or read until you switch the layer on in the extension popup, and Chrome shows its own permission prompt when you do.

Off means off

Switch the toggle back and the extension releases the permission and unregisters itself from Gmail. Not paused — released. The board badges keep working either way.

The full detail is in the privacy policy.

Turning it on

If a Pro subscription lapses, the layer stops on its own: the extension unregisters itself from Gmail and releases the permission, the same as switching the toggle off. Nothing keeps reading your mail on a plan that no longer includes it.

What it does not do

Worth being plain about, because a tool that is vague about its limits gets trusted for things it can’t do:

Where the rest of it lives

The mail layer is one of three surfaces. The other two read the DAT One load board: a Clear / Caution / High Risk / Unverified badge on every broker row from the public FMCSA record, and a panel showing the actual lines behind it. See how the board side works, or read why pre-call vetting is the part that matters.

Add to Chrome — free Back to home