URLVIS.
All Guides

Guide

How to identify a fake USPS package text

URLVIS Security Team · Last updated: August 29, 2026

A text about a held or undeliverable USPS package is very likely a scam if you never requested tracking notifications for that shipment: USPS sends tracking texts only to people who explicitly signed up for them, and those messages do not ask for money, card details, or personal information. Postal-themed smishing is among the highest-volume scam categories in the United States because the lure works on almost everyone — a missed package is plausible year-round and near-certain during holiday seasons, which is exactly when campaigns surge. The standard script claims an "incomplete address" or "held at facility" problem and links to a page imitating the postal service, which asks for name, address, and a small redelivery or service fee — often under two dollars. The fee is not the point: the card number, expiry date, and CVV entered to pay it are. A second variant skips the fee and harvests identity data instead, asking for date of birth or the last digits of a Social Security number "to verify the recipient". No postal delivery requires identity verification by web form. The messages usually arrive from random mobile numbers or foreign email addresses rather than a recognised shortcode, and the links use lookalike or unrelated domains, sometimes behind URL shorteners. Verification is simple: if you are expecting a package, find the tracking number in your original order confirmation and enter it on the postal service's official website, typed by hand. A real delivery problem shows up there; one that exists only in a text does not exist.

How to Identify

  • Ask whether you signed up for tracking texts for this specific shipment. Unsolicited postal texts with links are fraudulent by default — USPS does not send them.
  • Look at the sender. Random 10-digit mobile numbers and overseas email addresses are how smishing campaigns are blasted out; legitimate carrier notifications come through consistent, recognised channels.
  • Inspect the link domain. The genuine domain is usps.com; hyphenated variants, extra words, different endings, and shortened links all point to hostile pages.
  • Refuse any redelivery, address-correction, or customs fee requested through a text link. The fee is a pretext to capture your full card details — the amount is kept small so it feels harmless.
  • Stop immediately if a "delivery" page asks for identity data: date of birth, Social Security digits, or account passwords. Parcels are delivered to addresses, not to verified identities.
  • Take the tracking number from your retailer's order confirmation — not from the text — and check it on the official site you typed yourself. A mismatch or missing number settles it.
  • Ignore countdowns: "package will be returned within 12 hours". Real carriers hold parcels for days and communicate through notices, not through pressure timers.
  • Be wary of vague texts naming no carrier at all ("Your package is on hold — update your info"). Mass campaigns are sent blind, hoping the recipient fills in the blank themselves.
  • Never install an app or "tracking tool" a text told you to download. Malicious delivery apps read your messages and can intercept one-time bank codes.

Real-World Examples

The examples below are illustrative only. They do not refer to any real person, brand, or organization and exist solely to show the scam pattern.

Fabricated held-package text

Fictional example — Postal Notice: Your parcel #PN-30417 is held due to an incomplete address. Update your details within 12 hours at postal-hold.example to avoid return.

Fabricated redelivery-fee page

Fictional example — ParcelPoint Express: A $1.35 redelivery fee is required to schedule a new delivery window. Enter your card details to confirm your slot.

Fabricated identity-check text

Fictional example — Delivery Desk: Recipient verification failed. Confirm your name, date of birth, and address at verify-recipient.example so your item can be released.

Sources

  • U.S. Postal Inspection Service
  • Federal Trade Commission
  • FBI Internet Crime Complaint Center

Reporting Channels

  • United States Postal Inspection Service: Forward postal-themed scam texts and emails to [email protected], then delete them.
  • Mobile carrier spam reporting: Forward the text to 7726 (SPAM) so your carrier can block the sender.
  • Federal Trade Commission: Report the scam and any charges through ReportFraud.ftc.gov.
  • FBI Internet Crime Complaint Center: File a complaint if you lost money or submitted personal information.

FAQ

Does USPS ever send text messages about packages?

Only if you explicitly requested tracking updates for a shipment, and those texts report status — they do not contain links asking for payment, card details, or personal information. An unsolicited postal text with a link is a scam.

I clicked the link but entered nothing. Am I at risk?

Probably not — close the page, do not download anything, and clear any notification permission the site requested. If a file downloaded or an app installed, run a security scan and change important passwords from a different device.

I paid a small "redelivery fee" with my card. What now?

Call your card issuer immediately, report the card as compromised, and request a replacement — the real loss is the stored card details, not the small fee. Watch statements for follow-on charges and dispute anything unfamiliar.

How do I check a package if I am genuinely expecting one?

Open your retailer's order confirmation, copy the tracking number from there, and enter it at the carrier's official website typed by hand. Never navigate from the text — a real problem will be visible through the official tracking page.

Why did the scam text arrive right when I was expecting a delivery?

Coincidence at scale. Campaigns send millions of identical messages, and at any given moment a large share of recipients happen to be expecting something. The match feels personal but is statistical.

Is a link worrying you right now?

Paste it into our free checker. We follow it through any redirects, show you where it actually lands, and flag brand impersonation, blocklist hits and freshly registered domains. No account, nothing stored.

Check a link — free

URLVIS also runs this same scan on every short link our customers publish on their own domain.

Related Risks

How to identify a fake package delivery messageUtility Bill Payment Scams: A Guide to Recognizing Fake Texts and LinksHow to tell if an online store is fake

How This Guide Was Prepared

This guide was compiled from publicly available fraud-reporting sources and URLVIS's own multilingual risk taxonomy; an AI-assisted draft was reviewed before publication. It is for general information only and is not legal or financial advice. Spotted an error or outdated detail? Report it to [email protected].

URLVIS.

Create secure, measurable short links on your own domain. Keep your domain — export your data whenever you want.

Start for free →

Product

  • Free link checker
  • Custom domain
  • Dynamic QR code
  • How it works
  • Scam guides
  • Bitly alternative
  • Security filter
  • Dashboard preview
  • Pricing

Account

  • Start for free
  • Log in
  • FAQ

Legal

  • About URLVIS
  • Privacy policy
  • Terms of service
  • KVKK disclosure (Türkiye)

© 2026 URLVIS

Your own domain · Exportable data · No lock-in