A package holding fee delivery scam texts or emails that a parcel is delayed, seized, or waiting at customs—and you must pay a small holding, redelivery, or postage-due fee through a link. The link is usually phishing. Do not tap it. Do not pay with gift cards or crypto for a mystery package. If you already entered card data, call your bank, change passwords, and report to the FTC.

This guide covers fake delivery-fee messages—not fake Amazon customer service phone calls about account charges or remote-access refunds. Timing often follows a real purchase so the story feels plausible—similar phishing patterns appear in how to spot a phishing email and fake delivery text scams. No software purchase required.

1. How package holding fee scripts work

SMS messages claim USPS, UPS, FedEx, DHL, or Amazon Logistics need $1–$5 (or more) to release a package. Short links lead to pages that harvest card numbers, addresses, and sometimes ID uploads. Emails use tracking numbers that look real but are random.

  1. Postage-due bait — Tiny fee to release a package that may not exist.
  2. Customs or warehouse holds — Urgency to pay before the parcel is destroyed.
  3. Credential harvest — Pages that look like carrier portals (FTC phishing guidance).
  4. Follow-up calls — Voice calls still push payment links or codes.

2. Red flags before you tap

CueLikely legitimateLikely scam
How you pay postage dueCarrier instructions you verify on the official site/app after you look up tracking yourselfCold text with a pay link
URLExact carrier or retailer domainMisspelled domains, odd short links, strange subdomains
Amount and urgencyMatches a real shipping exception you can see in trackingPay in 2 hours or package destroyed
Payment methodNormal card checkout on an official pageGift cards, crypto, wires
Data askedMinimal delivery confirmation detailsFull SSN or photo ID upload for a $3 fee
Account pathYou open the retailer/carrier app yourselfMessage pretends to be support and asks for OTP codes

3. Safer habits (buy-nothing)

  1. Do not tap the link. Delete or report the text as junk.
  2. If you expect a package, open the carrier or store app yourself and check tracking (USPS.com as a starting point for USPS).
  3. Use official redelivery tools from the carrier’s real website.
  4. Never pay a holding fee with gift cards.
  5. Share the sample with household members who receive lots of deliveries.
  6. If a caller claims to be Amazon account support rather than a fee link, see fake Amazon customer service calls.

4. If you already paid or typed data

  1. Contact your bank or card issuer to watch for charges and replace the card if needed (FTC if you were scammed).
  2. Change passwords for email and shopping accounts; enable two-factor authentication.
  3. Save screenshots of the message, URL, and any pages.
  4. Report at ReportFraud.ftc.gov; report phishing to the carrier if they publish a channel.
  5. If you uploaded ID images, review steps at IdentityTheft.gov.
  6. Ignore callers who promise to “clear” the fee for another payment.

FAQ

I really am waiting on a package. Could the text be real?

Possibly rare legitimate notices exist, but safe practice is to ignore the link and check tracking yourself on the official app.

The tracking number format looks right.

Scammers generate realistic-looking numbers. Matching format is not proof.

How is this different from a fake Amazon customer service call?

Holding-fee scams center on a delivery surcharge link. Fake Amazon CS calls impersonate account support with unauthorized charges, refunds, codes, or remote access.

Is a $1.99 fee too small to be a scam?

Small amounts are intentional—they train you to type card data. The card theft is the goal.

What if I only entered an address?

Still risky. Watch for follow-up phishing that references that package story.

Do I need paid antivirus to avoid a holding-fee scam?

No. Ignoring cold links and checking tracking yourself is enough. Buy-nothing is valid.

Avoiding a package holding fee delivery scam does not require paid antivirus. Careful habits and official support paths are a valid buy-nothing stack. If you want multi-device paid protection later, use only these on-site paid links: TotalAV (paid link), Norton (paid link), Bitdefender (paid link), McAfee (paid link), Avast (paid link).