Delivery messages

A tiny fee can open the door to a larger theft.

A missed-delivery message uses a small believable problem to collect payment details, passwords and personal information.

8 minute readPublished 26 July 2026Reviewed 23 August 2026Individuals

What is changing now

The current pattern.

Delivery smishing remains a common text-message lure. The message may mention unpaid postage, an incomplete address, a missed delivery or a final chance to reschedule. The small fee makes the page feel low risk while the form collects much more valuable information.

How it works

Confidence first, then pressure.

Scammers send large numbers of messages because many recipients are expecting a parcel. The timing does not need to be precise: normal online shopping makes the story relevant to a wide audience.

The link opens a look-alike carrier or postal page and asks for an address, card details or an account sign-in. Some pages add a countdown or claim the parcel will be returned. Information entered into the form can be used for unauthorised payments, identity fraud or more convincing follow-up calls.

The real question is not whether you expect a parcel. It is whether the delivery can be confirmed independently through the retailer, a known tracking number or the carrier’s official service.

Worked example

A realistic pattern, separated into evidence.

This composite example is educational. It does not describe a real person or reproduce a live malicious message.

Composite scenario

A small redelivery fee hides a larger collection form

  1. 01
    The opening

    A text says a parcel could not be delivered because the address is incomplete. The recipient is expecting an order, and the message asks for only €1.99 to schedule another attempt.

  2. 02
    The escalation

    The linked page copies a carrier’s colours and first asks for the address, then full card details and a one-time banking code. A timer warns that the parcel will be returned today.

  3. 03
    The decision point

    Expecting a parcel explains why the message feels relevant; it does not connect the sender to the real order. The unverified link, tiny fee and expanding request for data form the scam pattern.

Warning signs

Reasons to stop and verify.

  • An unexpected text with a shortened, misspelled or unfamiliar link
  • A small redelivery, customs, address-correction or unpaid-postage fee
  • A threat that the parcel will be destroyed or returned immediately
  • A request for card details before showing verifiable tracking information
  • A generic greeting with no retailer, order number or recognisable shipment
  • A sender that asks you to reply or move to a different messaging app

Independent verification

Test the request without using its evidence.

These checks deliberately move the decision away from the person, link, number or account that introduced the request.

  1. 01

    Start with the purchase record

    Open the retailer account or original order confirmation. Identify the carrier and tracking number without using information from the text.

  2. 02

    Use the carrier’s known service

    Type the official address or use its app. A real delivery event should be visible against the known tracking number.

  3. 03

    Compare the requested information

    A request that expands from a delivery detail to full card data, credentials or an approval code is not a routine tracking update.

  4. 04

    Treat timing as unverified

    A coincidental message can arrive while you are expecting a parcel. Timing alone does not prove that the sender has access to the order.

Safer response

Move the decision outside the contact.

  1. 01

    Check the order account

    Open the retailer’s app or website from your own bookmark and review the order status there.

  2. 02

    Use known tracking

    Type the carrier’s official address yourself and enter the tracking number from the original purchase confirmation.

  3. 03

    Do not test the card form

    A small amount does not make the page safe. Do not enter information to see whether the payment succeeds.

  4. 04

    Report and delete

    Use the phone’s report-junk feature or forward unwanted texts to 7726 where that reporting service is supported.

If you already acted

Protect access and contact the real provider.

  • Contact the card issuer immediately if card details were entered.
  • Change any reused or submitted password through the real service.
  • Watch for follow-up calls that reference the information entered on the fake page.
  • Review statements and account alerts rather than waiting for a visible fraudulent charge.
  • Report the fake message to the carrier or postal service using its official website.

Sources

Official guidance used for this article.

Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.