SmishingGuides

Fake Delivery Texts: How USPS, UPS, and FedEx Smishing Scams Work

Phony package-tracking texts claiming a delivery needs a small fee or address fix are one of the most widespread smishing scams in America. Here's how to spot them.

N
By NoCall team
NoCall Editorial
4 min read
Fake Delivery Texts: How USPS, UPS, and FedEx Smishing Scams Work
#smishing#USPS scam#package delivery scam#phishing text#tracking link

Your phone buzzes: "USPS: Your package could not be delivered. Please update your delivery preferences," followed by a link. Maybe you are actually expecting a package — these days, most of us almost always are — and that single detail is what makes fake delivery texts the most widespread smishing scam in the country. The message is a trap, the link leads to a phishing site, and the "small shipping fee" it asks you to pay is really a credit card and identity harvest.

Why the scam works so well

Fake delivery scams succeed because they ride on genuine anticipation. Americans collectively receive tens of millions of packages every day from USPS, UPS, FedEx, DHL, and Amazon couriers, so a delivery-related text almost never feels like it could be random. The scammer does not need to guess anything about you; the mere base rate of packages in transit does the persuading.

The typical lure follows one of a few predictable patterns:

  • "Unpaid shipping fee" or "customs charge." You are asked to pay a trivial amount — usually under a few dollars — to release a package. The goal is your card details, not the fee; small amounts feel safe to enter.
  • "We could not deliver your package." You are told to reschedule or update your address via a link.
  • "Your package is held at our warehouse." Often paired with a tracking number that looks official and a link to a convincing replica of the carrier's site.
  • "Confirm your delivery window" or an invitation to earn rewards or gift cards by completing a "short survey" after your delivery.

The red flags

Real delivery notifications exist, so blanket suspicion is impractical. Instead, look for these signals, which distinguish phishing texts from legitimate ones:

  • A link with a wrong domain. Legitimate carrier links go to usps.com, ups.com, fedex.com, or dhl.com — not close imitations like "usps-delivery-help" or random domains with the carrier's name buried in the middle of the URL.
  • Urgency. "Within 24 hours" or "your package will be returned" is pressure, not logistics. Real carriers give you days and let you reschedule at your convenience.
  • An unexpected fee. Genuine shipping charges are paid when you order, not by text afterward. The exception is legitimate customs duties on international shipments — which you verify on the carrier's own site, never through a texted link.
  • A number that does not match the carrier. USPS texts come from recognized short codes, not random 10-digit numbers. When in doubt, compare against the short codes listed on the carrier's official website.
  • Generic greeting plus odd phrasing. "Dear customer," awkward grammar, or mixed-up brand names (a UPS text that mentions "USPS tracking") are classic signs of a mass-produced scam.

How to handle a suspicious delivery text safely

If a text arrives and you cannot immediately tell whether it is real, do this instead of tapping the link:

  1. Go to the source directly. Open the carrier's official app or type the website into your browser yourself, then check tracking there. If a real issue exists, it will show up on the official site without any text.
  2. Use the tracking number you already have. If you ordered something, copy the tracking number from the retailer's order page and paste it into the carrier's site — not into the texted link.
  3. Do not reply, even to say "stop." Replying confirms your number is active and owned by a human, which makes it more valuable for the next wave of scams.
  4. Report and delete. Forward the text to 7726, your carrier's spam-reporting number, then delete it.
  5. Report it to the FTC at ReportFraud.gov if you engaged with the site at all — and if you entered card details, call your bank immediately to cancel the card.

What to do if you already paid or entered details

If you entered payment information, contact your bank or card issuer right away to freeze the card and dispute the charge; speed dramatically improves recovery odds. If you created an account on the phishing page with a password you use elsewhere, change that password everywhere it is reused and enable multifactor authentication. Watch for follow-up scams — phishing victims are often retargeted with "package recovery" or "refund" calls, which are just a second scam layered on the first.

Filter the noise before it reaches you

Because these texts arrive in waves — often around holidays and Prime Day-style shopping events — automated filtering pays off. A call- and text-blocking app like NoCall can screen known phishing links and sender patterns before you ever see them, and registering with the carrier's spam-reporting tools makes each 7726 report you send more effective. Between cautious habits and a decent filter, the fake delivery text goes from a daily nuisance to a non-event.

Sources and review

Reviewed:

Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.

Article details

Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.

Author: NoCall team4 min read

Received a suspicious call?

Look up the number in NoCall before sharing data, calling back, or clicking any link.

Search a phone number or a company name (Bank of America, Verizon and AT&T...) to check if it has been reported as spam.