Skip to content
ScamiroScamiro
Online Scams8 min read1,494 words

Three delivery messages, and which one is real

Fraudulent parcel texts no longer look fraudulent. Three structural tests separate them from a genuine notification, and one fifteen-second habit defeats all of them.

ScamiroScamiro
A phone screen showing a message being composed to an unsaved phone number
A phone screen showing a message being composed to an unsaved phone number

Short answer

A delivery scam always needs you to act inside the message — pay a small fee, confirm an address, or call a number it supplies. A genuine courier notification only tells you something, and the same information also appears in the courier's own app and on the retailer's order page. Verify there, never through the link you were sent.

On this page
  1. How do you tell a fake parcel text from a real one?
  2. How do you read a link without clicking it?
  3. What the good version looks like
  4. What about the version that asks you to call?
  5. What if the parcel really is delayed?
  6. If you already tapped
  7. The one-line rule

Three messages arrive in the same week. One says a parcel could not be delivered and asks you to confirm your address. One says a customs fee of £1.99 is outstanding. One says the courier will attempt delivery again on Tuesday between nine and eleven. Two are a delivery scam and one is your actual parcel, and the difference is not in how they are written.

Modern fraudulent texts have no spelling errors, use real courier branding and arrive during business hours. Judging them by tone stopped working several years ago. What still works is a small number of structural tests, because a delivery scam has to do things a real notification never needs to.

How do you tell a fake parcel text from a real one?

Test one: was money mentioned? A courier that already has your parcel is not chasing £1.99. Redelivery is free everywhere it is offered, and genuine customs charges in most countries are collected by the postal operator at the door or through their own app after a formal notice — not by text with a link. Royal Mail and An Post both publish standing notices saying exactly this, because the impersonation is that consistent. Any small payment request in a delivery message is the single strongest signal of a delivery scam, and it is small deliberately: the amount is set below the level at which people stop to think, because the payment is not the point. The card details are the point.

Test two: did you order anything? Obvious, and people talk themselves out of it. "Maybe it's a gift." "Maybe work sent something." A delivery scam is sent to millions of numbers at once and relies precisely on that reasoning, because in any given week a meaningful share of recipients genuinely are expecting a parcel. If you cannot name the order, there is no parcel.

Test three: does the message need you to leave it? Real notifications are informational — a time window, a driver's name, a tracking reference. A fraudulent one always needs an action performed on a page it controls, because until you reach that page nothing has been stolen. The presence of urgency plus a link is the shape of the attack, independent of wording.

A genuine courier message tells you something. A fraudulent one asks you to do something.

If you want to check the address, press and hold on it rather than tapping — every mobile browser and messaging app shows the full destination in a preview without navigating there. Then read it right to left.

The domain is the last two parts before the first single slash. In royalmail.delivery-update.info/track, the domain is delivery-update.info and royalmail is just a subdomain that anyone can create in thirty seconds. This is the most common structure in a delivery scam, and reading left to right is exactly the mistake it is built to exploit — you see the brand first, and stop.

Three specific patterns worth recognising:

What you seeWhat it means
dhl.tracking-parcel.co/xReal domain is tracking-parcel.co
dhl-tracking.comA hyphen is not a dot; unrelated domain
bit.ly/3xKqDestination hidden entirely
dhI.com (capital i)Character substitution

Shortened links deserve their own rule: no courier uses them in customer notifications, because they have no reason to hide their own domain.

What the good version looks like

Legitimate delivery communications share a few traits that are inconvenient to fake at scale.

  • They reference something only the real sender knows — the retailer, the order number, or the item.
  • They do not ask for payment details, ever, for a parcel already in the network.
  • They are also visible elsewhere. A real update appears in the courier's own app and in the retailer's order page, which is the reliable way to check.

That last one is the whole answer, and it takes fifteen seconds. Do not use the link in the message. Open the courier's app, or go to the retailer you ordered from and look at the order. If the delay, the fee or the failed attempt is real, it is there too. If it is not there, the message was a delivery scam and no further analysis is needed.

What about the version that asks you to call?

The more expensive version does not use a link at all. You receive a text asking you to call a number about a parcel, or a missed-call from a number you do not recognise, and calling back reaches someone who sounds entirely professional. They confirm details you already gave them, then ask for a card to release the item.

Two things are worth knowing here.

A number you call is not verified by you calling it. Trust flows from where you got the number, not from the fact that a person answered. The only safe number is the one printed on the courier's own website, which you navigated to yourself.

Caller ID is not evidence. Displayed numbers can be set to almost anything, so a call appearing to come from a known company proves nothing about who is calling.

If you need to contact an unknown number back — a courier, a seller, a customer — without adding it to your contacts, a tool like Espresso: Quick Message opens a conversation from a pasted number directly. That is a convenience, not a safety check: the number still has to be one you sourced yourself. And it cuts the other way too, which is worth saying plainly — the same ease of messaging an unsaved number is what makes unsolicited contact cheap for the other side.

What if the parcel really is delayed?

Sometimes it is, and the anxiety a delivery scam exploits is real anxiety about a real order. The way to resolve it is the same either way, and it does not involve the message at all.

Start at the retailer, not the courier. The retailer is the party you have a contract with, they hold the tracking reference, and they are the ones obliged to resolve a non-delivery. Their order page will show the current status pulled directly from the courier, which is the same information a genuine text would have carried.

If the retailer's page shows a real problem, three things are worth knowing before you contact anyone.

  • A parcel is not lost until the courier says so, and most carriers do not open an investigation until a stated number of working days after the expected date. Checking before then produces nothing.
  • "Delivered" with no parcel is a specific case, and it is worth photographing the delivery point and asking neighbours before escalating, because the resolution path differs from a parcel that never arrived.
  • The retailer owes you the remedy, not the courier. In the UK this is set out in the Consumer Rights Act, and the practical effect is that arguing with a courier is usually the slower route.

None of this is reached through a link in a text message, which is the point. Once the habit is "go to the order page", the fraudulent message has nowhere left to insert itself — it becomes an item to delete rather than a decision to make.

If you already tapped

Tapping a link is not, by itself, a compromise. Entering something is. Work through this in order.

  1. If you entered card details, contact the bank now and have the card cancelled. This is the only step that is genuinely time-sensitive; everything else can wait an hour.
  2. If you entered a password, change it on the real site, and change it anywhere you reused it. Reuse is what turns one loss into several.
  3. If you only tapped, close the page. On a current, updated phone, visiting a page does not install anything.
  4. Check the account for pending transactions, not just completed ones — a test charge of a pound or two typically precedes a larger attempt.
  5. Report it. In the UK, forwarding the text to 7726 is free and feeds the network operators' blocking lists, and Action Fraud takes the report if money was actually lost.

Step five is the one people skip because it appears to do nothing for them personally. It shortens how long that number stays active for everybody else.

The one-line rule

Never act inside a message about a parcel. Read what it claims, then verify it somewhere you navigated to yourself — the courier's app, or the retailer's order page.

That single habit defeats every variant of the delivery scam described here, including the ones written well enough that nothing about them looked wrong. More on the patterns behind these messages in online scams, on link structure in suspicious links, and on brand impersonation generally in impersonation.

Frequently asked questions

Why is the requested fee always so small?
Because the money is not the goal. An amount below the level at which people stop and think gets card details entered, and the card is what has value.
Is tapping the link enough to infect my phone?
On a current, updated phone, opening a page does not install anything. The risk begins when you enter card details, a password, or personal information on that page.
How do I read a link to tell if it is fake?
Press and hold to preview it without opening it, then read the domain — the last two parts before the first single slash. In royalmail.delivery-update.info the real domain is delivery-update.info, and the brand name in front is just a subdomain.
The number called me, so isn't it genuine?
No. Displayed caller ID can be set to almost any number, so an incoming call appearing to come from a courier proves nothing. Only a number you sourced from the company's own website is trustworthy.

Sources

  1. How to spot, report and recover from a scam textUK National Cyber Security Centre
  2. Report suspicious texts to 7726Ofcom
  3. Espresso: Quick Message on the App StoreTecno Blocks
Scamiro

Published by

Scamiro

Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.

About the publication

Related reading

Keep going

Browse everything