Why Delivery Smishing Works So Reliably

A delivery text arrives at exactly the right moment. You ordered something online three days ago and you are vaguely expecting it. An SMS appears on your phone with a carrier logo and a reference number. The message says delivery failed and asks you to rebook for a small fee. Everything about the moment makes you want to act quickly.

This is not coincidence. Fraudsters send delivery smishing messages in enormous volume, knowing that a significant proportion of recipients will have a parcel in transit at any given time. The combination of universal online shopping habits, genuine urgency around missed deliveries, and the psychological authority of a recognised carrier brand creates one of the highest-yield fraud vectors operating at scale today.

For a side-by-side breakdown of genuine and fraudulent courier notifications, the visual similarities are striking, and understanding precisely what differs is more useful than a general warning to "be careful."

Anatomy of a Real Courier Message

Genuine courier SMS messages have consistent characteristics that, once known, are easy to recognise. Real messages from carriers like Royal Mail, DPD, Hermes, UPS, or FedEx arrive from consistent sender IDs: often the carrier's brand name rather than a mobile number. The URL in a genuine message uses the carrier's primary domain (royalmail.com, dpd.co.uk, fedex.com) with no additional characters or subdomains inserted before the main domain name.

Critically, real delivery notifications do not ask you to pay a redelivery fee via a link in the text message itself. If a carrier does have an outstanding charge (a customs duty on an international parcel, for example), the notification will direct you to log in to a named account or call a number you can independently verify, not click a payment link embedded in an SMS. Real notifications also tend to include your actual tracking number, which you can verify independently on the carrier's website.

Anatomy of a Fake Delivery Text

Fraudulent delivery texts share a set of structural features that distinguish them from genuine notifications, once you know what to look for. The sender ID may mimic a carrier name ("Royal-Mail" or "RYLMAIL") or arrive from a mobile number rather than a branded ID. The domain in the link is almost always not the carrier's primary domain: it may be a lookalike (royalmal.com, royal-mail-delivery.com) or an entirely unrelated domain designed to sound official.

The fee requested is deliberately small. Most delivery smishing messages ask for between £1.25 and £2.99. The small amount is psychologically engineered: it feels too trivial to hesitate over, and it gets your card details into a harvesting page that will be used for much larger transactions later.

Grammatical errors, odd punctuation, and generic salutations are common but not universal. AI-generated smishing messages are increasingly grammatically clean, which makes text quality alone an unreliable filter.

The 30-Second Checklist: Six Questions to Ask Every Time

Apply this checklist to any delivery-related SMS before clicking a link or entering any details:

One: Did you receive a tracking number when you placed the order? If yes, go to the carrier's website directly and enter that number. Ignore the link in the text entirely.

Two: Does the sender ID match the carrier's official name exactly? Subtle misspellings or additions ("Royal-Mail" versus "RoyalMail") indicate a spoofed sender.

Three: Does the link domain match the carrier's primary domain? Check whether the domain directly before ".com" or ".co.uk" is the carrier's actual name with nothing added. "uk.royalmail-redelivery.com" is not Royal Mail's domain.

Four: Is the message asking you to pay via a link in the SMS? Legitimate carriers do not process redelivery payments through SMS links. If a payment is required, navigate to the carrier's website independently.

Five: Did you actually expect a delivery from this carrier today? Not having a parcel in transit from the named carrier is an immediate signal. The message is mass-distributed, not targeted.

Six: Is there unusual urgency, a deadline within hours to avoid return to sender? Artificial time pressure is a consistent feature of smishing messages and absent from genuine carrier notifications.

What Happens If You Click: Card Harvesting and Malware Paths

Clicking the link in a fake delivery text typically leads to one of two destinations. The more common is a card-harvesting page: a convincing replica of a payment portal asking for your card number, expiry date, and CVV alongside name and billing address. This information is transmitted immediately to the fraudsters and used for unauthorised transactions, often within minutes.

The less common but more damaging outcome is a download prompt. On some Android devices, clicking a smishing link will trigger a prompt to install an APK file described as a delivery tracking app. Approving this installs malware capable of accessing banking credentials, reading SMS authentication codes, and transmitting them to a remote server. Victims of this variant often do not discover the breach until bank statements reveal transactions they did not make.

Neither outcome requires you to complete a transaction or approve a download knowingly. The card-harvesting page takes your details the moment you submit them. The malware installs if you approve a single prompt.

How to Report a Smishing Message and Block Future Attempts

In the UK, forward the smishing message to 7726 (SPAM on a standard keypad). This is a free service run by network operators that analyses and blocks reported numbers. In the United States, forward to 7726 and file a report with the FTC at reportfraud.ftc.gov. In Australia, report to Scamwatch at scamwatch.gov.au.

After reporting, delete the message and block the sending number. If you clicked a link but did not enter any information, check your device's browser history and clear it. If you entered card details, contact your card issuer immediately to report potential fraud and request a replacement card. Do not wait to see if fraudulent transactions appear.

Enabling your carrier's built-in spam detection (available on major UK and US networks at no charge) reduces the volume of smishing messages that reach your inbox without filtering legitimate messages. It is not a complete solution, but it eliminates the bulk of low-sophistication attempts.