Quick answer: A text that asks you to click a link to “reschedule delivery”, “pay a small customs fee”, or “confirm your address” is almost always a scam. Real carriers do not ask for card details by SMS, they do not use shortened or misspelled domains, and they do not threaten to send your parcel back within hours. If you already tapped a link, stop, close the page, and check the delivery directly on the carrier’s own website using the tracking number from the merchant’s original order email.
Why this scam works, and why it exploded
Package impersonation is now one of the largest single categories of text-message fraud reported to authorities in the US and the UK. The US Federal Trade Commission tracks “fake package delivery problems” as one of the top text scams by report volume every year since 2022, and the UK’s National Cyber Security Centre took down more than 329,000 delivery-impersonation URLs in its first year of running the Suspicious Email Reporting Service. Ofcom has reported that roughly seven in ten UK mobile users received a suspicious text in a single three-month window, with parcel scams the most common single theme. Numbers this large only happen because the attack is cheap to send and psychologically hard to ignore.
The reason the scam is now industrial rather than opportunistic is data. Address books, phone numbers, and even fragments of order history leak out of retailer breaches, loyalty programs, and third-party couriers every year. That gives scammers just enough real context (your first name, your postcode, sometimes a real order pending) to make a generic “your parcel is on the way” message feel plausible. If you are actually waiting for something, a scam text hitting your phone in that window feels like a coincidence, not a lure.
The second reason is timing. Parcel scams spike during known retail peaks (Black Friday, the run-up to Christmas, back-to-school, Mother’s Day), when a large share of the population is genuinely tracking multiple deliveries. A scammer only needs a tiny click-through rate on tens of millions of messages for the campaign to pay off.
The 8 warning signs, ranked by how reliable each one is
Any single one of the following signals is enough to justify deleting the message. Two or more together is effectively proof.
- A link that is not on the carrier’s real domain. Genuine tracking links from major carriers use their own domain (usps.com, ups.com, fedex.com, dhl.com, royalmail.com, evri.com, dpd.co.uk, hermes-germany.de, and so on). If the link goes to a shortener (bit.ly, tinyurl.com), a lookalike domain (usps-parcel-tracking.top, dhl-info-help.xyz, royaImail-support.com with a capital I instead of an l), or a random subdomain on a hosting provider, it is a scam. This is the single most reliable indicator.
- A request for payment. No major carrier collects “small redelivery fees”, “customs handling fees”, or “address correction fees” through an SMS link. Any legitimate customs charge is either collected by the sender at checkout, handled at your door, or invoiced through a formal letter with a case number you can verify on the carrier’s official site.
- Urgency framed as a threat. “Your parcel will be returned within 24 hours” or “final notice before disposal” is a psychological trick. Real carriers give you multiple days and multiple channels to reschedule.
- A tracking number that does not match your actual order. Legitimate tracking numbers are issued by the merchant at fulfillment and appear in your order confirmation email. If the number in the text is different from the number in that email, or if the text has no reference to the order at all, treat it as fake.
- Poor English, odd spacing, or unusual characters. Carriers translate their SMS templates carefully. Scam texts often mix locales (“your package has arrived on our warehouse”) or slip in Cyrillic look-alike letters to bypass keyword filters.
- An unknown sender ID or a mobile number instead of a short code. UK and German carriers usually send from an alphanumeric sender ID (for example “RoyalMail” or “DHL”). US carriers use short codes. A message from a random mobile number, especially an international one, is a red flag.
- A demand for full card details, CVV, or a one-time password. If the page after the link asks you to type a full card number, expiry date, CVV, or a 2FA code, close it immediately. Real carrier payment pages, when they exist at all, only handle small optional services and use tokenized card fields provided by a well-known payment processor.
- You were not expecting a delivery from that carrier. If you have no open order routed via that carrier, the text is not for you. Do not click the link “just to see”.
What to do the moment a suspicious text arrives
Treat the message like unopened mail from someone you do not know. Do not tap the link, do not reply “STOP” (that confirms your number is active), and do not call any phone number the message provides. Instead, go to the carrier’s real website by typing the address yourself or opening the app you already have installed, and enter the tracking number from your original order confirmation. If nothing exists there, the SMS was not real.
Then take three quick actions:
- Forward the text to your national reporting number. In the US, forward it to 7726 (which spells “SPAM”) to alert your carrier. In the UK, forward to 7726 as well; Ofcom’s system routes it to the operators. In Germany, forward suspicious texts to your provider or report through the Verbraucherzentrale.
- Delete the message. Keeping it in your inbox raises the risk of an accidental tap later.
- Block the sender. Most modern phones let you block a number or sender ID directly from the message screen.
If you already clicked the link
Clicking a link alone rarely does damage on a fully updated phone, but any information you typed after the click is compromised. Work through this list in order:
- Freeze or replace your card immediately if you entered card details. Most banks have an in-app freeze; a replacement card issued within minutes stops fraudulent charges from clearing.
- Change the password of any account whose credentials you typed on the fake page, and turn on two-factor authentication on the real service.
- Watch your accounts for the next 30 days. Real bank fraud usually shows up as a small “test” charge first, then a larger one.
- Report the fraud to your bank and to your national fraud line (Action Fraud in the UK, ReportFraud.ftc.gov in the US). This creates a case number you may need for chargebacks.
- Run a phone security check. On iPhone, update to the latest iOS and review Settings then Privacy for any unexpected profile installations. On Android, run Google Play Protect and uninstall any app you do not remember installing.
If you sent money by bank transfer, the recovery timeline is tight. Most banks operate under a “Contingent Reimbursement Model” or an equivalent voluntary code and will assess whether they refund you, but the assessment goes faster the sooner you report. There is no formal guarantee of a refund, so speed matters more than perfection.
How to verify a real delivery in under 30 seconds
You do not need the SMS to check on a real parcel. Every legitimate order gives you three verification paths that are independent of any text you receive:
- The order confirmation email from the merchant, which contains the tracking number and the carrier name.
- The carrier’s own app or website, entered by typing the address yourself, where you paste the tracking number.
- Your account page on the merchant’s website, which almost always shows the same status.
If all three agree, you are safe. If the SMS says one thing and the carrier’s own site says another (or shows no matching parcel), trust the carrier’s site.
Frequently asked questions
Do carriers ever charge fees by SMS?
No major carrier collects fees through a link in a text. Customs and import charges, when they apply, are collected either at checkout by the merchant or through a formal invoice with a case number you can look up on the carrier’s site.
Is it dangerous to just tap a scam link?
On a fully updated phone, a single tap rarely installs anything. The real risk starts on the page that opens, which typically asks you to enter card details, log in, or install an app. Close the browser tab and do not enter anything.
Why do the scam messages know my name?
Your name and phone number have almost certainly been part of a public data breach in the last few years. Scammers rent these lists cheaply and personalize their messages to raise click rates.
Can I get my money back if I paid a “redelivery fee”?
Card payments can usually be disputed with your bank as a chargeback if you act quickly. Bank transfers are much harder to recover. Report the fraud immediately and open a formal complaint with your bank.
Should I reply “STOP” to unsubscribe?
No. For legitimate marketing SMS, STOP works. For scam texts, replying only confirms that your number is active and leads to more spam.
My whole family is receiving these. What can I do at home?
Turn on the carrier-level SMS filter (most iPhone and Android messaging apps have a “Filter Unknown Senders” toggle), talk older relatives through the three warning signs at the top of this article, and agree on a household rule: no clicking on any delivery link that did not arrive right after an order was placed.
Related reading
For the wider picture of how these campaigns fit into the modern scam economy, see our pillar guide on the most common online scams in 2026 and how to avoid them. To vet a suspicious link before you tap it, use the checks in how to check if a website is safe before you click. If you have already handed over payment details, our step-by-step recovery guide is what to do if you entered your card details on a scam site. And when a text points you at an unfamiliar shop, check the seller in the webwiki directory before you spend anything.
Sources and further reading
- US Federal Trade Commission, Consumer Sentinel Data Book (annual reports on text scam categories).
- UK National Cyber Security Centre, Active Cyber Defence report on Suspicious Email Reporting Service and delivery impersonation takedowns.
- Ofcom, research on scam SMS in the UK mobile market.
- UK Finance, Fraud Report and CRM Code coverage of authorised push payment fraud.
- USPS, UPS, FedEx, DHL, Royal Mail official guidance on smishing and impersonation.
- Action Fraud UK and the FTC ReportFraud portal, official reporting channels.
