Parcel delivery scams: the fake missed-delivery message explained

    A text says a parcel could not be delivered and asks for a small redelivery fee. The amount is trivial, the branding is convincing and the timing often lands in the same week you genuinely ordered something. The fee is not the point: the card details you type are, and the second act of the scam is a phone call from someone pretending to be your bank.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Why this scam works so well

    Almost everyone is waiting for a parcel. Criminals send millions of messages knowing that a meaningful share will reach someone with a genuine delivery pending, and that person has a ready-made reason to believe the message. Nothing about the text needs to be clever when the timing does the persuading.

    The fee is deliberately small, usually between one and three pounds, dollars or euros. A small charge feels low-risk and bypasses the caution people apply to larger payments, while the real value to the criminal is the full card number, expiry, security code and the personal details typed alongside it.

    • A believable reason: you probably are expecting something
    • A tiny fee that feels too small to be worth a scam
    • Urgency: the parcel is returned to the depot in 48 hours
    • Brand names people trust: Royal Mail, USPS, DHL, Evri, FedEx, An Post
    • A link that looks close enough to the real domain at a glance

    What the fake messages actually look like

    The current wave uses short domains that combine a carrier name with an unrelated suffix, such as a carrier word followed by a country code or a random string. The page that opens is often a faithful copy of the real tracking site, sometimes with a live-looking map and a progress bar, because the HTML is simply cloned from the genuine one.

    Email versions add an invoice or a customs charge, which is the variant most likely to catch people who order from overseas. The message claims that duty is outstanding and the parcel is held at customs. Genuine customs charges are collected by the carrier through their own app or an official notification card, never through a link in an unsolicited text.

    • 'Your parcel is held at our depot — pay the £1.99 redelivery fee'
    • 'Customs duty of $3.40 is outstanding on your package'
    • 'We attempted delivery today. Reschedule within 24 hours'
    • A link on a domain that is not the carrier's own website
    • A form asking for full card details, address and date of birth

    The second call is the expensive part

    Paying two pounds is not what costs people thousands. Days later, a caller says they are from your bank's fraud team, references the exact small transaction you made, and says your account is compromised. Because they know a real detail you have not told anyone, the call sounds legitimate.

    They then ask you to move money to a 'safe account', read out a code, or install remote-access software so they can 'secure' your device. No bank ever does any of these things. Hang up, wait five minutes or use a different phone, and call the number printed on your card.

    How to check a delivery safely

    Never use the link in the message. Open the carrier's own app or type their website address yourself, then paste in the tracking number from your order confirmation. If there is no tracking number in your own email from the retailer, there is no parcel.

    Remember that carriers do not have your mobile number unless the sender gave it to them, and that legitimate redelivery is arranged inside their app or website, not through a card form on a page you reached from a text.

    • Check in the carrier's app, never through the message link
    • Match the tracking number against your own order confirmation
    • Treat any fee request in an unsolicited message as fraudulent
    • Report the text by forwarding it to your national spam-reporting service
    • Tell older relatives about the follow-up 'bank fraud team' call

    What to do if you already entered your card

    Freeze the card in your banking app immediately, which takes seconds and is reversible, then call the bank on the number on the card and ask for it to be replaced. Watch for small test transactions in the following days: criminals often trial a tiny amount before attempting a large one.

    If you also gave your address and date of birth, treat it as an identity exposure rather than just a card loss. Consider a credit-file notice, change passwords on accounts that use those details for recovery, and expect impersonation calls for several weeks.

    Protection that reduces the damage

    A password manager will not fill your details into a lookalike domain, which turns a convincing copy into an obvious fake before you type anything. Security software that blocks known phishing domains stops many of these pages from loading at all, and mobile suites increasingly filter scam texts as well.

    Card controls matter as much as software: virtual or single-use card numbers, app notifications on every transaction, and a low contactless limit all shrink the window between a leak and a loss.

    • A password manager that refuses to autofill on a fake domain
    • Security software with phishing and scam-message filtering
    • Virtual card numbers for one-off online payments
    • Instant transaction notifications on every card
    • Two-factor authentication on the email address that resets your bank

    Frequently asked questions

    Is a £1.99 delivery fee ever genuine?

    Carriers do charge for some redeliveries and customs handling, but they collect it through their own app, website or an official card posted to your door, never through a link in an unsolicited text.

    I clicked the link but did not pay. Am I at risk?

    Usually not. The risk comes from what you typed. Close the page, and if you entered anything at all, change that password and watch the card.

    Can my phone be infected just by opening the page?

    On an up-to-date phone this is very unlikely. The danger is the form, not the page. Android users who then installed an app from that page should remove it in safe mode.

    How do the scammers know I ordered something?

    They usually do not. They send the same message to millions of numbers, and coincidence does the rest. Occasionally the number comes from a retailer data breach.

    Where do I report it?

    Forward scam texts to your national reporting number, report phishing emails to your national cybersecurity centre, and tell your bank if any payment details were entered.