Skip to main content
← Back to blog

Fake delivery text scam: what to do right now

“Your parcel is on hold, pay 1.99 € to reschedule delivery.” Millions of these messages go out every day in the name of DHL, DPD, GLS, UPS and national postal services. Here is exactly what to do if you only clicked, if you typed in your card details or if you installed an app, and how to keep proof before the scam page disappears.

Smishing Parcel scam Card fraud Evidence

In short

  • ✓Real couriers almost never ask for a small card payment through a link in an SMS. If in doubt, open the carrier's app or type its address yourself.
  • ✓Entered card details? Call your bank immediately, block the card and dispute every payment you did not authorise.
  • ✓Installed an app from the link on Android? Switch on airplane mode, do not open banking apps and contact your bank from another phone.
  • ✓Before you report, capture the SMS (with sender and time) and the phishing page URL. These domains often die within hours.
  • ✓Then report: forward the SMS to your national spam number where one exists (7726 in the UK and Czechia, 33700 in France) and file a police report if you lost money.

Why the 1.99 € parcel message works so well

Fake delivery messages, often called smishing (SMS phishing), work because they are boring and plausible. Almost everyone is waiting for some parcel, the amount is tiny and the text sounds like routine logistics. Nobody thinks twice about 1.99 € for a redelivery or customs fee.

  • The small fee is not the goal. The goal is your full card number, expiry date and security code, and often the one-time code from your bank.
  • With those, criminals make much larger payments, add your card to their own mobile wallet or sell the data on.
  • Some versions skip the card form and push you to install a “tracking app”, which on Android can be malware that reads your SMS codes.
  • The same scam also arrives by e-mail and through messaging apps such as WhatsApp, with the courier's logo copied perfectly.

The brands used are always the big ones: DHL, DPD, GLS, UPS, FedEx, national postal operators and popular parcel-locker networks. The courier is a victim here too. Its name is simply what makes you click.

How to recognise a fake delivery SMS or e-mail

No single sign proves a message is fake, but several of them together almost always mean it is. Check for these:

  • A request to pay a small fee (customs, redelivery, storage, “address confirmation”) by card through a link.
  • Urgency: the parcel will be returned or destroyed today, within 24 hours or “after the final attempt”.
  • A link to a domain that is not the courier's official one, often with extra words, hyphens or odd endings (for example a brand name plus “-delivery-help” on a strange top-level domain).
  • A sender that is an ordinary mobile number, often from another country, instead of the courier's usual sender name.
  • No tracking number, or a tracking number that does not work in the courier's official app or website.
  • A payment page asking for card details and then for a code from your banking app or SMS, even though the “fee” is tiny.
Safe check: never use the link. Open the courier's official app, or type the official website address yourself, and enter the tracking number from the shop where you ordered. If there is really a fee to pay, you will see it there.

First: which situation are you in?

What you should do depends on how far you got. Find your situation and jump to the matching section below. In every case, try to keep the SMS and the link before doing anything else, because the page may be gone by tomorrow.

  • You only received the message and did not click: capture it, report it, delete it. You are fine.
  • You clicked the link but typed nothing: the risk is low. Close the page, capture the evidence and watch out for follow-up messages.
  • You typed your card details or paid the fee: treat the card as compromised. Call your bank now, then collect evidence.
  • You installed an app from the link: treat the phone as compromised. Isolate it first, then contact your bank from another device.

For a general checklist after any online scam, see: Scammed online? What to do and which evidence to keep →

Capture the evidence before it disappears

Phishing domains are cheap and disposable. Many are taken down, blocked by browsers or simply abandoned within hours or a few days. If you later need to prove to your bank, the police or an insurer what you saw and where you entered your data, you want that proof before the page vanishes. Capture first, report second.

  1. Screenshot the SMS or e-mail so that the sender number or address, the date and time and the full text including the link are visible. On a phone, open the message details if the time is hidden.
  2. Do not delete the message. Keep the original on the phone; it contains the original sender and timestamp.
  3. Copy the full link as text (long-press, copy link) and save it in a note. Do not open it again on the device where you entered data.
  4. If you entered card details, also screenshot any bank notifications, SMS codes you received and the transactions in your banking app.
  5. Write down a short timeline: when the message arrived, when you clicked, what you typed, when you contacted the bank.
Never re-enter real data on the scam page to “show” what happens. You would only hand over your details a second time. Evidence of the page itself is enough.

How to capture the phishing page properly

A screenshot of the SMS is useful, but a screenshot is just an editable image. It shows neither where the page was hosted nor exactly when it existed. For the fake payment page itself, a forensic capture is much stronger, and it is safer too, because the page is loaded on a remote server, not on your phone.

  • Full-page screenshot of the phishing page exactly as it was served at that moment.
  • The complete HTML source and a network log (HAR) showing the domain, redirects and where the form sends your data.
  • SHA-256 hashes of every file, an eIDAS qualified timestamp and a Bitcoin anchor, so nobody can later claim the capture was edited.
  • A PDF report and an Evidence ZIP that anyone can verify independently, including your bank or the police.

With GetProofAnchor you paste the link from the SMS into the web app and the server captures the page; the one-time Starter pack costs 9 € for 3 proofs with no subscription. If you would rather not deal with it yourself, Assisted Capture captures a public URL for you within 60 minutes. Either way, do it quickly: once the domain is down, nobody can capture it any more.

Some phishing pages show the fake form only to mobile phones from a certain country and a harmless page to everyone else. If the capture shows something different from what you saw, keep your own screenshots and your timeline as well; together they tell the full story.

If you only clicked the link

Simply opening a phishing page on an up-to-date phone rarely infects it on its own. The danger lies in what you type or install afterwards. Still, a few steps are worth it:

  • Close the tab and do not download anything the page offered. If a file downloaded automatically, delete it without opening it.
  • Update your phone's operating system and browser, and restart the phone.
  • Expect follow-up contact. Scammers know your number works and may call pretending to be your bank or the courier. Real banks will not ask you for codes or to move money to a “safe account”.
  • Capture the SMS and the link as described above, then report the message and block the sender.

If you entered card details or paid the fee

Speed matters more than anything else here. Card data from phishing pages is often used within minutes.

  1. Call your bank's official number (on the back of your card or in the banking app) or block the card directly in the app. Ask for a new card.
  2. Tell the bank clearly that your card details were stolen through a phishing page and that any further payments are not authorised by you.
  3. Check your transactions and pending payments now and over the coming weeks. Report every payment you do not recognise immediately.
  4. If you also typed your online-banking login, change the password from a clean device and check whether a new device or mobile wallet was added to your account.
  5. File a police report, attach your screenshots, the capture of the phishing page and your timeline, and send the report number to your bank.
Be careful with the codes. If you confirmed a payment or a wallet registration in your banking app because the page told you to, say so honestly to the bank and explain how you were deceived. Banks sometimes treat this differently, and your evidence of the fake page matters a lot.

Step-by-step: how to get your money back after an online scam (chargeback and bank dispute) →

If you installed an app (Android APK)

Some fake delivery messages ask you to install a “tracking” or “delivery” app from outside the official app store. On Android these APK files can be banking malware that reads your SMS, overlays fake login screens and takes control of the phone via accessibility permissions. iPhones are rarely affected this way, but they can be tricked into installing configuration profiles.

  1. Switch on airplane mode or disconnect the phone from mobile data and Wi-Fi right away.
  2. Do not open any banking, payment or e-mail apps on that phone.
  3. From another phone or computer, call your bank, block cards and online banking, and ask them to watch your account.
  4. Uninstall the app. If it cannot be removed, check whether it has device admin or accessibility rights and withdraw them, or ask a professional for help. When in doubt, back up your photos and do a factory reset.
  5. Afterwards, change the passwords of important accounts (e-mail first, then banking and shopping) from a clean device and enable two-factor authentication.
Before resetting, take a screenshot of the installed app's name and permissions and keep the original SMS. Once the phone is wiped, that information is gone.

Where to report a fake delivery message

Reporting helps operators block the sender and helps browsers block the domain. Report only after you have your evidence, because a successful report can take the page offline.

  • Spam SMS: in the UK and in Czechia you can forward the SMS free of charge to 7726; in France the equivalent number is 33700; in Germany the Bundesnetzagentur accepts SMS spam complaints through an online form.
  • Phishing e-mails: use your e-mail provider's “report phishing” function. National services include signal-spam.fr in France and the Phishing-Radar of the Verbraucherzentrale in Germany.
  • The phishing link: report it to Google Safe Browsing and, if you can identify it, to the domain's registrar or hosting provider, so browsers start warning other people.
  • The real courier: most carriers have a page for reporting fraud in their name. They cannot refund you, but it helps them warn customers.
  • The police: if you lost money or your card was misused, file a report with the police in your country (online reporting is available in many EU countries). Your bank will often ask for it.

Then block the sender number and delete the message from your inbox only once you have your screenshots and have forwarded it.

More detail on reporting a scam website to authorities, hosts and browsers →

Your rights with the bank under EU payment rules

In the EU, the Payment Services Directive (PSD2), implemented in national law in every member state, protects you against unauthorised payments. In general terms:

  • You must notify your bank without undue delay after you notice an unauthorised payment, and at the latest within 13 months of the debit date.
  • For an unauthorised payment, the bank must in principle refund you immediately, no later than the end of the following business day, unless it has reasonable grounds to suspect fraud on your side.
  • Your own loss before you report is generally capped at 50 €, unless you acted fraudulently or with gross negligence.
  • After you have reported the loss or theft of your card data, you are in principle not liable for further payments.

The grey zone is gross negligence and payments you confirmed yourself. Banks sometimes argue that typing card details and approving a code on a fake page was grossly negligent. Whether that holds depends on the case and on how convincing the scam was, which is exactly why a verifiable capture of the fake page, your screenshots and your timeline are worth having. If the bank refuses, you can complain to your country's financial ombudsman or regulator.

Capture it before it disappears

Turn the page into evidence in 2 minutes

Paste the URL and get a sealed Evidence ZIP with an eIDAS qualified timestamp — much harder to challenge than a screenshot. No subscription needed.

Verify an existing proof → · Guides for Airbnb, Vinted, Amazon & more →

Frequently asked questions

Does DHL, DPD or the post office really send SMS asking for a fee?

Couriers do send delivery notifications, and genuine import duties do exist. But a request to pay a small fee by card through a link in an SMS is the classic scam pattern. Check in the courier's official app or website by typing the address yourself.

I only clicked the link. Is my phone infected?

Opening the page alone rarely infects an up-to-date phone. The risk comes from typing data or installing an app. Close the page, update the phone and watch for follow-up calls or messages.

I paid 1.99 €. Is that all I can lose?

No. The small fee is a pretext to collect your full card details. Block the card with your bank immediately and check for further payments over the next weeks.

Will my bank refund me?

For unauthorised payments, EU rules require the bank to refund you in principle, with your own loss generally capped at 50 € unless you acted with gross negligence or fraudulently. Payments you confirmed yourself are a grey zone, so report quickly and provide evidence.

Why should I capture the phishing page if I am not going to court?

Because your bank, insurer or the police may ask how the fraud happened, and the page is usually gone within days. A verifiable capture shows the fake domain and form exactly as they were.

Should I reply STOP to the message?

No. Replying confirms that your number is active and may lead to more scam messages. Forward it to your national spam number where available, then block the sender.

This article is general information, not legal or financial advice. Rules and reporting channels differ between countries and banks, so check with your bank and local authorities for your specific case.