Got a package delivery text you weren't expecting? Learn how fake delivery text scams work, what warning signs to check, and how to verify a delivery safely.
If you have received a text message about a package in the last month, there is a real chance it was fake. Fake delivery text scams are one of the most common smishing (SMS phishing) attacks in circulation, and they work because almost everyone is expecting a parcel at any given moment. The attacker does not need to know what you ordered, or even whether you ordered anything — they just need to send enough messages that some recipients self-select into plausibility.
The mechanics are simple and profitable. A scammer sends a text that looks like it came from USPS, Royal Mail, FedEx, UPS, DHL, or a local courier. The message claims a small fee, a customs charge, a missed delivery, or a package on hold. It includes a link to a fake payment or "redelivery" page that harvests your card details, your name, your address, and sometimes your online banking login. Because the message arrives on the device you carry everywhere and lights up your lock screen, it feels urgent and official in a way that a carefully considered email does not.
This guide breaks down how fake delivery text scams work, the warning signs you can check in under a minute, and how to verify a delivery safely without tapping anything in the message. Many of the same principles apply to text scams more broadly — for a wider checklist, see our guide on how to tell if a text message is a scam. If you want an instant assessment of a specific message, paste it into Scamlify's SMS Scam Checker.
The attack follows a predictable pattern, and understanding the steps makes the warning signs easier to spot.
The scammer sends a high-volume blast of text messages impersonating a courier or postal service. The message is short, references a package, and creates a reason for you to act: a small fee is owed, a delivery was missed, a parcel is being returned, or a customs charge needs paying. The wording is deliberately generic so the same message works against thousands of recipients.
The text contains a link. Sometimes it is a shortened URL (bit.ly, tinyurl, t.co); sometimes it is a lookalike domain designed to resemble the real courier (usps-package-redirect.com, royalmail-parcel-fee.com, fedex-delivery-uk.net). The link is the mechanism — everything else in the message exists to make you tap it.
Tapping the link opens a convincing copy of the courier's payment, tracking, or redelivery page. It uses the real brand's colours, logo, and layout. The page asks for information the real courier would never request by text: your full card number, CVV, billing address, or account login. Some pages charge a small "fee" (often £1.50 or $2) purely to capture card details — the tiny amount is chosen to feel plausible and avoid suspicion.
Once you submit the form, your details are captured. The card may be used for fraudulent purchases, sold on, or used to authorise further charges. In some variants the page also asks for an email address and password, enabling account takeover. The whole interaction takes under a minute, and the victim often only realises weeks later when unfamiliar charges appear.
You do not need technical knowledge to spot a fake delivery text. Run through these checks before you tap anything.
This is the single most important check. If you have not ordered anything, and you have not been told by a retailer that a parcel is on the way, treat any delivery text as suspect. Scammers rely on the fact that some recipients will have ordered something recently and assume the text relates to it. If you genuinely are expecting a parcel, identify which one — and verify through the retailer's own confirmation email or app, not the text.
A text demanding a small payment to "release" a package is the classic delivery scam pattern. Real couriers do occasionally charge customs fees, but they notify you through their official tracking system, their app, or a card left at your address — not an unsolicited text with a payment link. The USPS Postal Inspection Service explicitly warns that the Postal Service will never send a text asking for money or personal information to deliver a package.
Look at the domain in the link before you tap. On most phones you can long-press a link to preview the destination without opening it. A genuine USPS link uses usps.com. A genuine Royal Mail link uses royalmail.com. Anything else — usps.delivery-portal.net, royalmail-parcel.support, fedex.shipping-update.co — is a lookalike. Watch for:
Legitimate couriers sometimes send texts, but a delivery notification from an ordinary mobile number (especially one you do not recognise) is a strong signal of spoofing. Sender IDs can be faked, so a name like "USPS" or "Royal Mail" on the message is not proof either — your phone threads messages by sender string, and a spoofed ID can land in the same conversation as genuine alerts.
"Your package will be returned today." "Final delivery attempt." "Respond within 2 hours or your parcel will be disposed of." Urgency is the scammer's most effective tool because it pushes you past the moment where you would normally stop and verify. Real couriers do not dispose of parcels within hours. If a message insists you must act immediately, that pressure is itself the warning sign.
A real courier delivering a package to you already has your name and address — that is how the parcel reaches you. A text that asks you to "confirm" your full address, date of birth, or payment details is asking for things no legitimate delivery notification needs. Any request for your card number, CVV, online banking login, or one-time passcode is a clear red flag.
Many fake texts include a fake tracking number. If you are unsure, go to the courier's official website by typing the address yourself and enter the number there. If the courier has no record of it, the text is not from them. Do not use the link in the text to "track" the package — that leads back to the scam page.
Mass-sent scam texts use generic language: "Your package is on hold" rather than "Your order #12345 from [Retailer]". Misspellings, odd capitalisation, or a brand name written incorrectly are all tells. A courier will almost never misspell its own name.
If you think a delivery text might be genuine, verify it through a channel you already trust — never the link in the message.
If none of these confirm a delivery, the text is not real. Report it and delete it.
Act quickly — the faster you respond, the more you limit the damage.
Yes — and it is often faster and more reliable than checking each sign manually, especially when a message looks convincing. An AI scam checker reads the full text, evaluates the sender, the link, the language, and the behaviour the message asks for, and returns a risk score along with the specific warning signs it triggered.
If a delivery text has you unsure, copy the message (and the sender, if visible) into Scamlify's SMS Scam Checker for an instant assessment. It runs the same checks described in this guide automatically, and it works for any suspicious text — not just delivery scams.
Some couriers send genuine delivery updates by text, but they will not send a link asking you to pay a fee, "verify" your details, or enter your card information. If a text contains a payment link, treat it as suspect and verify through the courier's official app or website.
Not necessarily. Scammers send delivery texts in huge volumes precisely because many people are expecting a parcel at any time. Being expecting a delivery does not confirm the text is about your delivery. Verify through the retailer's confirmation or the courier's official tracking.
No. Tapping the link can load a credential-harvesting page, trigger tracking, or in some cases attempt to install malware. Long-press the link to preview the destination where your phone supports it, and if you are unsure, do not tap — verify through an official channel instead.
An address alone is less damaging than card or login details, but it can still be used for further targeted scams or identity fraud. Stay alert to follow-up messages and calls, and report the original text to 7726.
No. Scammers impersonate whichever courier is most recognised in a given region — USPS in the US, Royal Mail and Evri in the UK, DHL and UPS internationally. The pattern is the same regardless of the brand being faked.
The warning signs above are exactly what our tool checks for — instantly and for free. Use Scamlify's free SMS Scam Checker the next time a delivery text feels off, and share it with someone who might need it.