An email says your USDOT or MC record needs an “off-cycle update.” Another says a payment or fuel system tied to your number must be verified. The branding looks official, the deadline feels urgent, and the button appears to lead to FMCSA.
Stop there.
FMCSA’s current Fraud Alerts page warns about messages impersonating both Motus and SAFER. For a brokerage owner, operations manager, dispatcher, or new-authority broker, the safest response is not to decide whether the email *looks* legitimate. It is to open a separate, known-good path to the official system, compare the request there, and use an independently sourced contact route if anything remains unclear.
This checklist is an operational security aid, not legal, cybersecurity, registration, or incident-response advice. Follow your company’s security policy and involve a qualified security professional when credentials, financial information, or systems may be exposed.
What the public sources currently say
FMCSA’s Fraud Alerts page currently names a “Bogus Motus App and Links” campaign. It says the legitimate Motus URL is `https://motus.dot.gov/` and describes messages using the subject “Notice of Required Off-Cycle Update” to push recipients toward lookalike sites. The same page separately warns about SAFER impersonation messages that ask recipients to verify payment or fuel-system information associated with an MC or USDOT number. It identifies the official SAFER Company Snapshot page.
FMCSA’s Move into Motus page says Motus is available at `motus.dot.gov`, uses Login.gov and identity verification, and can be used by brokers to manage registration actions. The SAFER Company Snapshot describes itself as a free, one-company-at-a-time public record that can be searched by USDOT number, MC/MX number, or company name.
The FTC advises people who receive a suspicious request to contact the organization through a phone number or website they already know is real—not through the contact information in the message. CISA similarly recommends pausing on urgent requests and typing the known website directly instead of following an emailed shortcut.
Those are public-source facts and agency recommendations. They do not prove that a particular message is malicious, verify your authority status, or establish any ServeOps capability.
The 10-minute independent-path check
Assign one person to run the check and one person to review the decision whenever the message touches credentials, money, registration status, company ownership, or user access.
Minute 0–1: freeze the interaction
Do not click the link, open an attachment, reply, call a number in the message, scan its QR code, or forward it casually. Do not enter a Login.gov password, one-time code, payment detail, EIN, banking instruction, or company-account information.
Preserve the original message according to your security policy. Record the received time, subject, visible sender, actual sender address, requested action, stated deadline, attachment names, and displayed destination. If your mail system has a “report phishing” control, use the approved internal process rather than redistributing the message.
Minute 1–3: inspect without navigating
Expand the full sender address. Preview the real link destination without opening it; FMCSA specifically recommends hovering over suspicious links to see the underlying URL. Note misspellings, added words, unrelated domains, URL shorteners, and a visible label that does not match its destination.
Do not use a green padlock, logo, signature block, MC number, or accurate company detail as proof. A convincing message can copy public information and still lead somewhere false.
Minute 3–5: open a clean, known-good route
Start a new browser tab. Type a saved official address yourself or use a bookmark your team previously approved:
- Motus: `https://motus.dot.gov/`
- FMCSA Fraud Alerts: `https://www.fmcsa.dot.gov/registration/fraud-alerts`
- SAFER Company Snapshot: `https://safer.fmcsa.dot.gov/CompanySnapshot.aspx`
- FMCSA Contact Center: open the contact route from `fmcsa.dot.gov`, not from the email
Sign in only from the known-good Motus route when a sign-in is actually needed. Compare the official account or public record with the claim in the message. A message that says “not authorized,” “payment verification required,” or “update now” is not itself the official record.
Minute 5–7: verify the action independently
Write down four answers:
- Does the same action or alert appear after entering through the official route?
- Does the legal name, USDOT/MC identifier, and requested filing match your own records?
- Is the action consistent with a change your authorized team initiated?
- Can FMCSA confirm the request through contact information obtained independently from its official site?
If any answer is no or unknown, hold the action. Do not let the sender’s deadline override independent verification.
Minute 7–10: classify and route
Use four states:
| State | Minimum evidence | Next action | |---|---|---| | Verified official | Same action is confirmed through the independently opened official system or FMCSA contact route. | Follow the normal authorized change process; retain the verification record. | | Suspicious | Lookalike domain, mismatched sender/destination, unexpected payment/profile request, or pressure to bypass normal access. | Report internally; use the official FMCSA/FTC routes as appropriate; do not interact with the sender. | | Possible compromise | A link or attachment was opened, or credentials, codes, company data, or payment information were entered. | Escalate immediately under the company incident plan; involve IT/security and affected account or financial providers. | | Unresolved | Evidence is incomplete or official confirmation is unavailable. | Keep the request on hold, record the owner and next review time, and use an independent FMCSA contact path. |
Do not label a message “safe” merely because no obvious typo was found. The passing condition is independent confirmation of the requested action through a known-good route.
If someone already clicked or responded
Do not continue experimenting with the message. Tell the internal security or IT owner exactly what happened, including which link or attachment was opened and what information was entered. Use a known-clean route to review affected accounts and follow the organization’s credential-reset, device-check, financial-control, and incident-reporting procedures. If personal information may be exposed, the FTC points users to IdentityTheft.gov for situation-specific steps.
FMCSA’s Fraud Alerts page links to an FMCSA Contact Center route and an FTC reporting route. The FTC also accepts phishing reports at ReportFraud.ftc.gov. Reporting is not a substitute for containing an active account or financial compromise.
Turn one alert into a repeatable broker runbook
Keep a one-page internal record with:
- approved Motus, FMCSA, SAFER, FTC, and internal help-desk bookmarks;
- the people allowed to change registration, company, user, or payment information;
- a two-person review rule for credentials, ownership, banking, and authority actions;
- the internal phishing-report button or mailbox;
- FMCSA and financial-provider contacts sourced independently;
- the evidence fields and four classification states above;
- a short after-action note for new domains, subject lines, or tactics encountered.
Review the bookmarks against the official FMCSA Fraud Alerts page rather than copying a domain list indefinitely. Campaign details change; the independent-path method is the durable control.
ServeOps product boundary and restrained next step
This guide does not claim that ServeOps connects to Motus, Login.gov, SAFER, FMCSA, the FTC, or any reporting service. It does not claim that ServeOps verifies authority or identity, inspects email, detects phishing, blocks malicious links, protects credentials, monitors registrations, produces incident evidence, or prevents fraud. No ServeOps functionality is used to establish any public fact above.
After the registration-security question is separately resolved, a brokerage can evaluate its operating TMS on a different track. The verified ServeOps offer language is unchanged: 60-day free trial; card collected upfront; no charge for 60 days; cancel anytime; then $49 per seat/month or $490 per seat/year. Card is required upfront. No charge during the trial. Confirm the complete checkout terms before signup.
Related Broker Guides
- Diagnose a broker authority that remains pending in Motus
- Work through a suspended or revoked broker authority status
- Understand the BOC-3 filing and process-agent boundary
Confirm each related route is approved and live before inserting it in the CMS.
Sources
- FMCSA, Fraud Alerts (current page reviewed August 24, 2026)
- FMCSA, Move into Motus (current page reviewed August 24, 2026)
- FMCSA SAFER, Company Snapshot (current page reviewed August 24, 2026)
- FTC, How To Recognize and Avoid Phishing Scams (current page reviewed August 24, 2026)
- FTC, ReportFraud (reporting destination reviewed August 24, 2026)
- CISA, Recognize and Report Phishing (current page reviewed August 24, 2026)
- ServeOps registration (offer destination; complete terms require publication-day recheck)