01
A new domain on a supplier claiming a long history
The gap between the story and the registration date is the cheapest signal there is.
A first purchase order or a tooling deposit goes to a supplier nobody in the building has paid before, on terms agreed over email.
A buyer, a sourcing manager, or accounts payable, at the moment the PO is raised. Paste the email address or the web address, read the reasons, and make the call. The first check needs no account.
Typical wire $10K – $500K · illustrative transaction size, not a loss estimate
What matters here
01
The gap between the story and the registration date is the cheapest signal there is.
02
A compromised inbox keeps the real invoice and swaps the account. Treat any change as fraud until a voice call.
03
No sender rules on a supplier domain means a lookalike email is trivial to send.
What a check reads
In supply, the mail setup is the one people skip: a domain with no sender rules can be impersonated by anyone, including on a real supplier you have used for years.
How the score is builtBefore the money leaves
A worked example
The situation
A tooling supplier confirms a $40K deposit, then emails updated bank details before payment.
What the record says
The domain checks out and is years old, but there are no sender rules on its mail — spoofed mail from that domain is easy.
The reading
Caution band on the mail setup, with the plain instruction to confirm the account change on a number found independently.
Illustrative example built from the record types a check reads — registration dates, mail setup, site history, and near-match names. Not a real vendor.
Questions we get
Paste the supplier's email address or website for a score out of 1,000 in about 10 seconds, then do the manual steps: registration number against the public registry, and a callback on a number you found yourself.
It is the classic compromised-inbox pattern: the document is genuine and the account is not. Nothing moves until a voice call to a known number confirms it. A check will also show whether the sending domain can be impersonated.
No. Registries, credit, litigation, and banking are not part of a check. It reads the public digital record behind the email address and the web address.
No. An old domain with no sender rules on its mail can still be impersonated, which is why the check reports mail setup next to registration date instead of one number without reasons.
What a score does not say
A score reads public records about an email address or a web address. It is an observation, not a guarantee, and it does not tell you whether a specific payment is safe. The manual steps still matter.
Built and run by a named person, not an anonymous site — who is behind this and how the score is built.
Building this into software your industry already uses? For platforms.
Paste the vendor's email address or website. About 10 seconds.
Run a free check