URLVIS.
All Guides

Guide

How to identify a fake Royal Mail text

URLVIS Security Team · Last updated: August 29, 2026

A text claiming Royal Mail is holding your parcel over a small unpaid fee is almost always a scam: genuine postal fee cases in the UK arrive as a physical "Fee to pay" card through your letterbox, and payment happens on the official website or at a Post Office branch — not through a link in an unsolicited text. The UK's parcel-fee scam wave follows the same economics as its international siblings: a tiny claimed amount, typically £1.45 to £2.99, positioned as the only thing standing between you and your delivery. The amount is bait — the page behind the link collects your full card number, expiry date, and security code. The most damaging versions do not stop at the card form. Days after the "fee" is paid, victims receive a call from someone posing as their bank's fraud team, quoting the exact card details and the fake delivery incident to build trust, then talking the victim into "moving money to safety". The initial £2 harvest is reconnaissance for a much larger strike. Campaigns intensify around holiday shopping periods, customs-rule headlines, and postal strike news — any moment when a held parcel feels routine and plausible. Delivery-fee messages also rotate freely between carrier brands, so the same page template reappears under different names. The brand on the message is set dressing; the structure — unexpected text, small fee, card form — is the scam. Verification never happens through the message: if you are expecting a parcel, check the tracking number from your retailer's confirmation on the carrier site you typed yourself, and remember that a genuine underpaid-postage case produces a physical card, not a text.

How to Identify

  • Expect real fee cases on paper: a genuine underpaid-postage or customs charge in the UK produces a physical card through your door with a reference number payable on the official site or at a Post Office. A text link is not that process.
  • Treat small amounts as the tell, not as reassurance. £1.45 to £2.99 "shipping fees" are calibrated to feel too small to question while justifying a full card form.
  • Inspect the domain before anything else. The genuine domain is royalmail.com; hyphenated variants ("royalmail-fee"), other endings, and shortened links are hostile pages.
  • Check the sender type. Smishing campaigns arrive from random mobile numbers or email-to-text gateways; judge the request rather than trusting any sender label, which can be forged.
  • Refuse card details for redelivery. Rearranging a genuine delivery is free; no UK carrier charges a card fee by text link to release an ordinary parcel.
  • Stop if the page wants identity data — date of birth, account passwords, or one-time codes. A parcel needs an address, never your identity portfolio.
  • Distrust urgency windows: "your parcel will be returned to sender within 24 hours". Real held items wait for weeks and are documented in tracking, not in countdowns.
  • Match the claim to reality: no recent order, no expected parcel, or a carrier you never use means the message was sent blind to millions of numbers.
  • Watch for the follow-up call. If you entered card details and someone later calls "from your bank's fraud team" asking you to move money, hang up and call your bank yourself on the number from its card or official site — banks never ask you to transfer money to a safe account.

Real-World Examples

The examples below are illustrative only. They do not refer to any real person, brand, or organization and exist solely to show the scam pattern.

Fabricated fee-to-pay text

Fictional example — Parcel Notification: Your item is held at our depot due to an unpaid shipping fee of £1.99. Settle it at parcel-fee.example to arrange redelivery within 24 hours.

Fabricated customs charge text

Fictional example — Delivery Hub UK: A customs handling charge of £2.47 is due on parcel DH-55102. Pay now at customs-settle.example or the item will be returned to sender.

Fabricated follow-up bank call script

Fictional example — "This is the fraud team. We flagged the £1.99 delivery charge on your card ending 4471. To protect your balance, we will move your funds to a secure holding account while we investigate — please confirm the transfer code I am about to send."

Sources

  • National Cyber Security Centre
  • GOV.UK — report phishing
  • Action Fraud

Reporting Channels

  • Mobile network smishing reporting: Forward the scam text to 7726 — free on all UK networks.
  • National Cyber Security Centre: Forward suspicious emails to [email protected].
  • Action Fraud: Report fraud with financial loss in England, Wales, or Northern Ireland.
  • Your bank: If card details were entered, call the number on the back of your card immediately — or 159, the UK anti-fraud banking line.

FAQ

Does Royal Mail ever send text messages?

Yes — genuine tracking notifications exist for items where the sender added your mobile number. But real messages do not ask for payment through a link. Fee cases produce a physical card, payable through official channels you reach yourself.

How do I pay a genuine postal fee safely?

Use the reference number printed on the physical card you received, and type the carrier's official website address yourself — or pay at a Post Office branch. If there is no physical card and no record in official tracking, there is no fee.

I entered my card details on a fake fee page. What should I do?

Call your bank now using the number on the back of your card (or dial 159), report the card as compromised, and ask for a replacement. Then be ready for the follow-up: any later call about "suspicious activity" that asks you to move money is the second stage of the same scam.

Why do these scams charge so little?

The fee is not the profit — the card details are. A sub-£3 amount lowers vigilance enough that people complete the full card form, and the harvested details are then used for larger fraud or sold on.

The text knew a parcel was coming. Was I targeted?

Almost certainly not. Campaigns are blasted to millions of numbers, and much of the population is expecting a parcel in any given week. Unless a specific retailer leak affected you, the timing is coincidence doing the scammer's work.

Is a link worrying you right now?

Paste it into our free checker. We follow it through any redirects, show you where it actually lands, and flag brand impersonation, blocklist hits and freshly registered domains. No account, nothing stored.

Check a link — free

URLVIS also runs this same scan on every short link our customers publish on their own domain.

Related Risks

How to identify a fake package delivery messageHow to identify a fake HMRC tax refund messageUtility Bill Payment Scams: A Guide to Recognizing Fake Texts and Links

How This Guide Was Prepared

This guide was compiled from publicly available fraud-reporting sources and URLVIS's own multilingual risk taxonomy; an AI-assisted draft was reviewed before publication. It is for general information only and is not legal or financial advice. Spotted an error or outdated detail? Report it to [email protected].

URLVIS.

Create secure, measurable short links on your own domain. Keep your domain — export your data whenever you want.

Start for free →

Product

  • Free link checker
  • Custom domain
  • Dynamic QR code
  • How it works
  • Scam guides
  • Bitly alternative
  • Security filter
  • Dashboard preview
  • Pricing

Account

  • Start for free
  • Log in
  • FAQ

Legal

  • About URLVIS
  • Privacy policy
  • Terms of service
  • KVKK disclosure (Türkiye)

© 2026 URLVIS

Your own domain · Exportable data · No lock-in