delynt AITalk to us

The RFQ that looks real, names your parts, and asks for net-30

Fraudulent quote requests are aimed at manufacturers specifically, because the payoff is a shipment of physical goods on credit terms. They do not look like spam. That is the point.

Scored messageLow trust — verify
From
purchasing@ — first contact, lookalike domain
Pre-screen
External · buying language · not automated
Trust
19
Spam
4

Correct product terminology and a plausible company name, but the sending domain is one character off the company's public site, the delivery address is a freight forwarder, and a first order asks for net-30.

→ Flagged for a phone call before quoting

Sample · sender redacted

Why manufacturers are the target

Most email fraud is after a credential or a wire transfer. Both require the victim to do something that feels, at some level, like a financial transaction — and most people have been trained to hesitate there.

Fraud aimed at a manufacturer asks for something else entirely: a quote. Then an order. Then a shipment. The thing being stolen is inventory, and it leaves your building before any money was ever supposed to arrive, because the whole point of net-30 is that payment comes later. By the time the invoice goes unpaid, the goods have been resold and the domain has gone quiet.

That is why the scam is worth running against a machine shop and not against a software company. You make something shippable, you extend credit to buyers you have not met, and the industry norm is that a new customer asking for terms is ordinary business rather than a red flag.

What a fraudulent RFQ looks like

It looks like work. That is the uncomfortable part — the pattern is designed to read as a good week, not a bad one.

  • A plausible company name, and very often a real one. Impersonating an established firm is easier than inventing a company, because the buyer's own due diligence turns up a real website, a real address and real revenue — none of which belong to the sender.
  • Correct product terminology, frequently lifted from your own site. Material grades, tolerances, part families, the phrasing you use in your capabilities page. It reads like someone who knows what they are buying because it was copied from someone who does.
  • A sending domain that is close to the real one rather than identical. One transposed letter, an added hyphen, a different top-level domain. It survives a glance and fails a comparison.
  • Urgency with a reason attached. A production deadline, an end-of-quarter budget, a supplier who fell through — a story that explains why there is no time to verify anything.
  • A delivery address that does not reconcile with the company's real one. Freight forwarders and short-term storage are the usual destinations.
  • A request for terms on a first order. This is the payload. Everything before it exists to make this ask feel routine.

Why spam filters miss it

A spam filter is a bulk detector. Almost every signal it relies on is a property of sending a lot of mail: the same body text going to thousands of addresses, a sending IP with a reputation history, a known campaign fingerprint, recipients who marked earlier copies as junk, list-unsubscribe headers, a template that has been seen before.

A fraudulent RFQ has none of those properties. It is written once, for you, referencing your parts, and sent once, from a domain registered recently enough to have no reputation at all — good or bad. There is no campaign to fingerprint and no earlier copy for anyone to have complained about. It is, by every measure a bulk-mail filter can take, an ordinary piece of business correspondence.

So it lands in the inbox. Not because the filter is bad, but because the filter is answering a different question. "Is this bulk?" and "is this honest?" are not the same question, and a tool built to answer the first one has no opinion on the second.

Why one score can't do this job

Follow that through and you get an architectural conclusion, not just an observation. If "bulk" and "honest" are independent properties, then a system that collapses them into a single number is throwing away the distinction it most needs.

How four kinds of message score on spam and trust independently, and why a single blended score cannot express the difference.
MessageSpamTrustWhat you want to happen
Supplier newsletterHighNeutralDropped, silently
Genuine first-contact RFQLowHighOn someone's phone now
Fraudulent purchase orderLowLowSurfaced, with a warning
Bulk SEO pitchHighLowDropped, silently

Look at rows two and three. Both are low-spam. On a single blended score they sit next to each other, and whichever way you set the threshold you get one of two failures: surface both, and the fraud arrives looking exactly like a good lead; suppress both, and you have hidden a real quote request to avoid a fraudulent one.

Delynt AI scores them separately. A message can be simultaneously "not bulk mail" and "do not extend credit to this sender," and those two facts arrive as two numbers plus a written sentence explaining what drove them. That sentence is the part that matters — a score you cannot interrogate is a score you cannot overrule.

No product required

What you can check yourself

None of this needs software. If you do nothing else after reading this page, do these.

  1. 01

    Verify the domain against the company's public site, not the signature block

    A signature block is typed by whoever sent the message. Look up the company independently and compare the domain character by character — a swapped letter, an added hyphen, or a .net where the real company uses .com is the whole trick.

  2. 02

    Call a number you looked up, not one in the email

    Every phone number, extension and contact name in a fraudulent message routes back to the sender. A number from the company's own website, or from a directory, does not.

  3. 03

    Check whether the delivery address matches the company's registered address

    Freight forwarders, self-storage units and residential addresses are common destinations, because the goods need to move before anyone notices. A real buyer's delivery address usually reconciles with a real facility.

  4. 04

    Be suspicious of credit terms on a first order

    Net-30 on a first order from a company you have never sold to is the payload of the entire scam. It is not automatically fraud — plenty of legitimate buyers ask — but it is the point at which verification stops being optional.

  5. 05

    Notice when urgency and flattery arrive together

    A deadline that leaves no time to verify, paired with a message that has clearly read your website, is a combination worth slowing down for.

Where automated screening helps, and where it doesn't

What it is good for: consistency and timing. A checklist works perfectly on the message you are already suspicious about. It works less well on the one that arrives at 4pm on a Friday in the middle of forty other messages, which is the one the scam is timed for. Automated screening applies the same reading to every message, including that one, and it does it before anyone has decided the message is worth attention.

What it is not: a verdict. Delynt AI does not verify a company, check a registry, contact anyone, or block a sender. It reads the message, scores it, and writes down why. A low trust score is a reason to make a phone call — nothing more than that, and it should never be treated as more.

The failure mode worth naming is the one in the other direction. A cautious system that quietly suppressed anything it distrusted would eventually suppress a real buyer with an unusual domain and a genuine rush job, and you would never know it happened. So nothing is hidden and nothing is deleted. A flagged message is a flagged message, sitting where it always was, with a sentence next to it telling you what looked wrong.

This is one job inside a larger one

Fraud screening falls out of a system built to do something more ordinary: read the mailbox your quote requests land in, drop the junk, and get the real ones to whoever quotes.

Connecting a mailbox is a real ask.Here is exactly what we can and cannot see.

Last reviewed 6 August 2026