A text that says your package needs a fee, a reschedule, or a click to “track” is usually a fake delivery scam. The FTC and the U.S. Postal Inspection Service warn that scammers impersonate USPS, FedEx, UPS, or DHL, push a link, and harvest card numbers or passwords on a look-alike site. Do not tap the link. Open the retailer or carrier app you already use, or type the official site yourself, to check tracking. Forward the text to 7726 (SPAM) and report at ReportFraud.ftc.gov. If you already paid or typed card details, call the number on the back of your card and follow credit card fraud: first hour.

How to tell a real delivery text from a scam

Fake package texts work because households expect boxes. The message is the bait; the link is the trap.

  1. You did not start tracking. USPIS notes that USPS does not text you out of the blue with a link unless you requested tracking for a specific number. An unexpected “postage due,” “held at facility,” or “update delivery preferences” text with a link is a red flag.
  2. Pressure to pay or “confirm” fast. Real carriers do not demand card details by SMS. Phrases like unpaid postage, missed delivery, or update shipping preferences that force a click are classic phishing stories the FTC lists.
  3. The link is not the carrier’s site. Long-press (do not open) and look at the domain. Look-alikes, random short links, or misspellings are not usps.com, fedex.com, or ups.com typed by you.
  4. Generic greeting + urgent problem. Same pattern as email phishing: “your package,” “account on hold,” “click to fix.” Compare with how to spot a phishing email.
  5. You were not expecting a package. Brushing and random “your item is ready” texts are common. If you did order something, verify in the store or carrier account — never in the text.
SignalLikely scamSafer next step
Unexpected text with a tracking linkYes — especially if you did not request SMS trackingIgnore the link; open the retailer or carrier app you already use
Asks for card, “postage,” or shipping fee by textYesDo not pay; carriers do not collect that way by random SMS
Looks like USPS/FedEx/UPS but odd sender numberYesForward to 7726; check tracking only on the official app or site
In-app notification from the store where you orderedUsually saferStill open tracking inside that app, not from a separate SMS link

What to do if you already tapped the link

  1. Stop. Do not enter a card, password, or Social Security number on the page that opened from the text.
  2. If you typed a card number, call the number on the back of the card, report unauthorized use, and walk the first-hour credit card fraud steps.
  3. If you typed a password, change it on a device you trust, starting with email, then that shopping or carrier account. Turn on multi-factor authentication that is not only SMS when the account offers an authenticator app or security key.
  4. If a file tried to download, do not open it. Treat it like a risky download — see check a download before you open an .exe or .zip. Update security software and run a full scan. Microsoft Defender alone is enough for many homes (is Microsoft Defender enough?).
  5. Report. Forward the text to 7726. Report at ReportFraud.ftc.gov. For USPS-themed smishing, USPIS also accepts reports at spam@uspis.gov (paste the text body; attach a screenshot of the sender number — do not click the scam link).

Phone calls that claim “Geek Squad” or “Windows support” after a fake package click are a separate play — use tech support scam phone calls.

FAQ

How do I know if a package delivery text is a scam?

If you did not request tracking and the text pushes a link or a fee, treat it as a scam. Verify only inside the retailer or carrier account you already use.

Will USPS text me about a package?

USPIS says USPS will not send customers texts or emails with a link unless the customer first requested tracking with a tracking number. Unexpected linked texts are smishing.

What should I do with a fake FedEx or UPS text?

Do not click. Open the official FedEx or UPS app or site yourself if you have a real shipment. Forward the text to 7726 and report at ReportFraud.ftc.gov.

I already entered my card on a fake tracking site — now what?

Call the number on your card, report the charges, and follow credit card fraud: first hour. Change any password you reused. Use IdentityTheft.gov if you shared a Social Security number or bank details.

Do I need to buy antivirus because of a package scam text?

No. The scam is phishing and theft of payment data. Keep Windows and phone software updated. Microsoft Defender on a home PC is a valid buy-nothing choice for malware.

A fake delivery text is a phishing and payment problem; Microsoft Defender on a home PC remains a valid buy-nothing choice for malware. Habits that actually help are: never tap SMS tracking links, verify in the store app, and report to 7726. If the household later wants a multi-device paid suite, use only these on-site paid links: TotalAV, Norton, Bitdefender, McAfee, Avast.