In short
- ✓Real couriers almost never ask for a small card payment through a link in an SMS. If in doubt, open the carrier's app or type its address yourself.
- ✓Entered card details? Call your bank immediately, block the card and dispute every payment you did not authorise.
- ✓Installed an app from the link on Android? Switch on airplane mode, do not open banking apps and contact your bank from another phone.
- ✓Before you report, capture the SMS (with sender and time) and the phishing page URL. These domains often die within hours.
- ✓Then report: forward the SMS to your national spam number where one exists (7726 in the UK and Czechia, 33700 in France) and file a police report if you lost money.
Why the 1.99 € parcel message works so well
Fake delivery messages, often called smishing (SMS phishing), work because they are boring and plausible. Almost everyone is waiting for some parcel, the amount is tiny and the text sounds like routine logistics. Nobody thinks twice about 1.99 € for a redelivery or customs fee.
- The small fee is not the goal. The goal is your full card number, expiry date and security code, and often the one-time code from your bank.
- With those, criminals make much larger payments, add your card to their own mobile wallet or sell the data on.
- Some versions skip the card form and push you to install a “tracking app”, which on Android can be malware that reads your SMS codes.
- The same scam also arrives by e-mail and through messaging apps such as WhatsApp, with the courier's logo copied perfectly.
The brands used are always the big ones: DHL, DPD, GLS, UPS, FedEx, national postal operators and popular parcel-locker networks. The courier is a victim here too. Its name is simply what makes you click.
How to recognise a fake delivery SMS or e-mail
No single sign proves a message is fake, but several of them together almost always mean it is. Check for these:
- A request to pay a small fee (customs, redelivery, storage, “address confirmation”) by card through a link.
- Urgency: the parcel will be returned or destroyed today, within 24 hours or “after the final attempt”.
- A link to a domain that is not the courier's official one, often with extra words, hyphens or odd endings (for example a brand name plus “-delivery-help” on a strange top-level domain).
- A sender that is an ordinary mobile number, often from another country, instead of the courier's usual sender name.
- No tracking number, or a tracking number that does not work in the courier's official app or website.
- A payment page asking for card details and then for a code from your banking app or SMS, even though the “fee” is tiny.
First: which situation are you in?
What you should do depends on how far you got. Find your situation and jump to the matching section below. In every case, try to keep the SMS and the link before doing anything else, because the page may be gone by tomorrow.
- You only received the message and did not click: capture it, report it, delete it. You are fine.
- You clicked the link but typed nothing: the risk is low. Close the page, capture the evidence and watch out for follow-up messages.
- You typed your card details or paid the fee: treat the card as compromised. Call your bank now, then collect evidence.
- You installed an app from the link: treat the phone as compromised. Isolate it first, then contact your bank from another device.
Capture the evidence before it disappears
Phishing domains are cheap and disposable. Many are taken down, blocked by browsers or simply abandoned within hours or a few days. If you later need to prove to your bank, the police or an insurer what you saw and where you entered your data, you want that proof before the page vanishes. Capture first, report second.
- Screenshot the SMS or e-mail so that the sender number or address, the date and time and the full text including the link are visible. On a phone, open the message details if the time is hidden.
- Do not delete the message. Keep the original on the phone; it contains the original sender and timestamp.
- Copy the full link as text (long-press, copy link) and save it in a note. Do not open it again on the device where you entered data.
- If you entered card details, also screenshot any bank notifications, SMS codes you received and the transactions in your banking app.
- Write down a short timeline: when the message arrived, when you clicked, what you typed, when you contacted the bank.
How to capture the phishing page properly
A screenshot of the SMS is useful, but a screenshot is just an editable image. It shows neither where the page was hosted nor exactly when it existed. For the fake payment page itself, a forensic capture is much stronger, and it is safer too, because the page is loaded on a remote server, not on your phone.
- Full-page screenshot of the phishing page exactly as it was served at that moment.
- The complete HTML source and a network log (HAR) showing the domain, redirects and where the form sends your data.
- SHA-256 hashes of every file, an eIDAS qualified timestamp and a Bitcoin anchor, so nobody can later claim the capture was edited.
- A PDF report and an Evidence ZIP that anyone can verify independently, including your bank or the police.
With GetProofAnchor you paste the link from the SMS into the web app and the server captures the page; the one-time Starter pack costs 9 € for 3 proofs with no subscription. If you would rather not deal with it yourself, Assisted Capture captures a public URL for you within 60 minutes. Either way, do it quickly: once the domain is down, nobody can capture it any more.
If you only clicked the link
Simply opening a phishing page on an up-to-date phone rarely infects it on its own. The danger lies in what you type or install afterwards. Still, a few steps are worth it:
- Close the tab and do not download anything the page offered. If a file downloaded automatically, delete it without opening it.
- Update your phone's operating system and browser, and restart the phone.
- Expect follow-up contact. Scammers know your number works and may call pretending to be your bank or the courier. Real banks will not ask you for codes or to move money to a “safe account”.
- Capture the SMS and the link as described above, then report the message and block the sender.
If you entered card details or paid the fee
Speed matters more than anything else here. Card data from phishing pages is often used within minutes.
- Call your bank's official number (on the back of your card or in the banking app) or block the card directly in the app. Ask for a new card.
- Tell the bank clearly that your card details were stolen through a phishing page and that any further payments are not authorised by you.
- Check your transactions and pending payments now and over the coming weeks. Report every payment you do not recognise immediately.
- If you also typed your online-banking login, change the password from a clean device and check whether a new device or mobile wallet was added to your account.
- File a police report, attach your screenshots, the capture of the phishing page and your timeline, and send the report number to your bank.
Step-by-step: how to get your money back after an online scam (chargeback and bank dispute) →
If you installed an app (Android APK)
Some fake delivery messages ask you to install a “tracking” or “delivery” app from outside the official app store. On Android these APK files can be banking malware that reads your SMS, overlays fake login screens and takes control of the phone via accessibility permissions. iPhones are rarely affected this way, but they can be tricked into installing configuration profiles.
- Switch on airplane mode or disconnect the phone from mobile data and Wi-Fi right away.
- Do not open any banking, payment or e-mail apps on that phone.
- From another phone or computer, call your bank, block cards and online banking, and ask them to watch your account.
- Uninstall the app. If it cannot be removed, check whether it has device admin or accessibility rights and withdraw them, or ask a professional for help. When in doubt, back up your photos and do a factory reset.
- Afterwards, change the passwords of important accounts (e-mail first, then banking and shopping) from a clean device and enable two-factor authentication.
Where to report a fake delivery message
Reporting helps operators block the sender and helps browsers block the domain. Report only after you have your evidence, because a successful report can take the page offline.
- Spam SMS: in the UK and in Czechia you can forward the SMS free of charge to 7726; in France the equivalent number is 33700; in Germany the Bundesnetzagentur accepts SMS spam complaints through an online form.
- Phishing e-mails: use your e-mail provider's “report phishing” function. National services include signal-spam.fr in France and the Phishing-Radar of the Verbraucherzentrale in Germany.
- The phishing link: report it to Google Safe Browsing and, if you can identify it, to the domain's registrar or hosting provider, so browsers start warning other people.
- The real courier: most carriers have a page for reporting fraud in their name. They cannot refund you, but it helps them warn customers.
- The police: if you lost money or your card was misused, file a report with the police in your country (online reporting is available in many EU countries). Your bank will often ask for it.
Then block the sender number and delete the message from your inbox only once you have your screenshots and have forwarded it.
More detail on reporting a scam website to authorities, hosts and browsers →
Your rights with the bank under EU payment rules
In the EU, the Payment Services Directive (PSD2), implemented in national law in every member state, protects you against unauthorised payments. In general terms:
- You must notify your bank without undue delay after you notice an unauthorised payment, and at the latest within 13 months of the debit date.
- For an unauthorised payment, the bank must in principle refund you immediately, no later than the end of the following business day, unless it has reasonable grounds to suspect fraud on your side.
- Your own loss before you report is generally capped at 50 €, unless you acted fraudulently or with gross negligence.
- After you have reported the loss or theft of your card data, you are in principle not liable for further payments.
The grey zone is gross negligence and payments you confirmed yourself. Banks sometimes argue that typing card details and approving a code on a fake page was grossly negligent. Whether that holds depends on the case and on how convincing the scam was, which is exactly why a verifiable capture of the fake page, your screenshots and your timeline are worth having. If the bank refuses, you can complain to your country's financial ombudsman or regulator.
Capture it before it disappears
Turn the page into evidence in 2 minutes
Paste the URL and get a sealed Evidence ZIP with an eIDAS qualified timestamp — much harder to challenge than a screenshot. No subscription needed.
Verify an existing proof → · Guides for Airbnb, Vinted, Amazon & more →
Related guides
-
How to get your money back after an online scamChargebacks, bank disputes and what to send with them.
-
How to report a scam websiteWhere to report phishing domains so they get blocked.
-
Scammed online? What to do and which evidence to keepThe general first-aid checklist after any online fraud.
-
How to check if a website is legitQuick checks before you pay on an unknown site.
Frequently asked questions
Does DHL, DPD or the post office really send SMS asking for a fee?
Couriers do send delivery notifications, and genuine import duties do exist. But a request to pay a small fee by card through a link in an SMS is the classic scam pattern. Check in the courier's official app or website by typing the address yourself.
I only clicked the link. Is my phone infected?
Opening the page alone rarely infects an up-to-date phone. The risk comes from typing data or installing an app. Close the page, update the phone and watch for follow-up calls or messages.
I paid 1.99 €. Is that all I can lose?
No. The small fee is a pretext to collect your full card details. Block the card with your bank immediately and check for further payments over the next weeks.
Will my bank refund me?
For unauthorised payments, EU rules require the bank to refund you in principle, with your own loss generally capped at 50 € unless you acted with gross negligence or fraudulently. Payments you confirmed yourself are a grey zone, so report quickly and provide evidence.
Why should I capture the phishing page if I am not going to court?
Because your bank, insurer or the police may ask how the fraud happened, and the page is usually gone within days. A verifiable capture shows the fake domain and form exactly as they were.
Should I reply STOP to the message?
No. Replying confirms that your number is active and may lead to more scam messages. Forward it to your national spam number where available, then block the sender.
This article is general information, not legal or financial advice. Rules and reporting channels differ between countries and banks, so check with your bank and local authorities for your specific case.