Package Delivery Scam Texts: How to Spot Fake USPS, FedEx and DHL Messages
Your phone buzzes. "USPS: Your package could not be delivered due to an incomplete address. Please update your details within 24 hours or the item will be returned." There is a link. You are waiting on a parcel. You tap.
That single tap is one of the most profitable attacks running today. Fake delivery texts — a form of SMS phishing known as smishing — work because almost everyone has something in transit at any given moment. The attacker does not need to know anything about you. They send the same message to a hundred thousand numbers and let statistics do the rest.
This guide breaks down exactly how these texts work, the tells that give them away in under five seconds, and what to do if you already entered your card details.
Why Delivery Texts Are the Perfect Scam
Three things make this attack unusually effective compared to email phishing:
- Timing is guessed, not known. With online shopping now routine, a random person has a genuine delivery pending far more often than not. The scam does not need to be targeted to feel targeted.
- Phones strip away context. On a desktop you can hover a link and read the destination. On a phone the URL is truncated, the browser bar hides after scrolling, and the padlock icon only means the connection is encrypted — not that the site is honest. Criminals buy TLS certificates for free.
- The stakes look tiny. Most fake delivery pages ask for a small "redelivery fee" — often the equivalent of one or two dollars. That number is deliberately low. You are not evaluating a risk, you are clearing a minor annoyance. The fee is not the payday; your card number is.
Once you enter card details on the fake page, one of two things happens. Either the card is sold on in bulk within hours, or — increasingly common — the page immediately asks for the one-time code your bank just texted you. That code authorises the criminal to add your card to a digital wallet on their own phone. From that point they can tap-to-pay in shops without ever touching your physical card.
The Warning Signs That Take Five Seconds to Check
1. Look at the domain, not the words
Real courier links live on the courier's own domain. Read the address from right to left, starting at the first single slash. In usps.tracking-update.info/parcel, the actual domain is tracking-update.info — "usps" is just decoration placed at the front to reassure you. Legitimate USPS links end in usps.com, DHL in dhl.com, FedEx in fedex.com, Royal Mail in royalmail.com.
Be especially suspicious of link shorteners in delivery texts. Genuine couriers rarely use them because they cannot afford the ambiguity.
2. Real couriers do not charge you by text
This is the single most reliable rule. USPS, FedEx, UPS, DHL, Royal Mail and Australia Post do not send unsolicited texts asking for a redelivery payment or customs fee via a link. Where genuine customs charges exist, they are handled through the courier's official app or a letter, and never with a 24-hour countdown.
3. You did not opt in
Courier tracking texts are something you sign up for, usually at checkout. If you never gave that retailer your number for delivery updates, an unprompted courier text is a red flag by itself.
4. The sender number is wrong
Genuine courier alerts come from short codes or consistent business numbers. Scam texts arrive from ordinary mobile numbers, frequently with a foreign country code, or from an email-to-SMS gateway address.
5. Pressure and vagueness together
"Within 24 hours or it will be returned to sender" is manufactured urgency. Note also what is missing: no order number, no retailer name, no item description, no last four digits of anything. A real notification knows what it is talking about.
How to Verify a Delivery in Under a Minute
- Do not tap the link. Ever. Not even to "just look."
- Go to the source you already trust. Open the retailer's app or your order confirmation email and check the tracking there.
- Or type the courier's address by hand and paste in the tracking number from your own order confirmation — never a number supplied by the text.
- If you genuinely cannot tell, phone the courier using the number on their official website. Never a number provided in the message.
Applying this consistently costs about forty seconds and removes the entire category of risk. The rule is simple: verification always travels through a channel you opened yourself.
Locking the Door Before They Knock
A few settings reduce your exposure permanently:
- Turn on spam filtering for messages. On iPhone, Settings → Apps → Messages → Filter Unknown Senders. On Android, open Messages → Settings → Spam protection. Neither is perfect, but both remove a large share of bulk smishing before you see it.
- Use a device-level wallet rather than typing card numbers. Apple Pay and Google Pay send a one-time token to the merchant, not your real card number. A tokenised payment cannot be replayed by anyone who intercepts it.
- Enable transaction alerts in your banking app. Set the threshold to zero so every single charge pings your phone. Skimming and card-testing fraud usually start with a very small transaction. Catching that first small hit is the difference between a five-minute call and a three-week dispute.
- Never approve a one-time code you did not personally trigger. No legitimate organisation will ever ask you to read a code aloud or type it into a page you reached from a text.
- Report and delete. In the US and UK you can forward scam texts to 7726 (it spells SPAM), free of charge. This feeds carrier-level blocking and genuinely shortens the life of a campaign.
If It Already Happened
Speed matters far more than embarrassment. Work through this list in order:
- Freeze or lock the card immediately in your banking app. Most banks offer an instant toggle — you do not need to phone anyone to do this first step.
- Call the number on the back of your card and tell them the details were entered on a phishing site. Ask them to cancel and reissue, not just block. A blocked card can sometimes be unblocked; a cancelled one cannot.
- Check for a digital wallet you did not add. Ask the bank explicitly whether your card has been provisioned to any new device recently. This step is skipped constantly and it is where the ongoing damage lives.
- Change the password of any account whose credentials you entered, and any other account sharing that password. Enable two-factor authentication while you are there.
- Watch your statements for ninety days, not ninety hours. Stolen card data is often warehoused and sold months later.
- Report it. In the US, reportfraud.ftc.gov. In the UK, Action Fraud. Reporting will rarely recover your money directly, but it is what builds the case that eventually shuts a network down.
If you only tapped the link and closed the page without typing anything, your risk is low — these pages harvest data you submit rather than infecting the phone silently. Still, run a check for any app you do not recognise, and stay alert for a follow-up call from someone claiming to be your bank's fraud team. That follow-up is a standard second stage.
The Bottom Line
Fake delivery texts survive because they exploit a moment when your guard is legitimately down. The defence does not require technical skill — it requires one habit: never act inside a message you did not ask for. Check the order in the retailer's app. Type the courier's address yourself. Treat any request for a small fee by text as fraudulent until proven otherwise, because it almost always is.
One habit, applied every time, retires the whole scam category.
Comments
Post a Comment