Smishing evidence lab
Package Delivery Text Scams: Check the Message Without Clicking
The message says your package has a problem. Your first move is to leave the message and check whether the package exists.
Break the spell: check for a real package
Delivery scams borrow credibility from probability. Millions of people are expecting something, so the sender does not need to know your order history; it only needs the story to feel plausible for a few seconds.
Open the retailer account or carrier app you already use. Compare the tracking number, delivery status, and requested action there. If the message contains no tracking number—or the number does not exist in your real order history—the story has already lost a major support beam.
Read the URL from right to left
The registrable domain—the part immediately before .com, .net, or another suffix—matters more than brand words elsewhere in the address. A domain such as usps.example.com belongs to example.com, not USPS. Extra hyphens, misspellings, unfamiliar endings, and brand names buried in a long hostname deserve scrutiny.
HTTPS means the connection is encrypted. It does not mean the site is honest. Pretty pages lie just as efficiently as ugly ones.
- Displayed link and final destination domain
- Tracking number and whether it exists in the real order
- Requested fee, credentials, address, or payment details
- Deadline or threat used to accelerate action
- Brand named in the message versus owner of the domain
Preserve the evidence before the domain disappears
Save a screenshot showing the complete sender, timestamp, message, and URL. Copy the text into a separate note and correct any OCR errors in phone numbers and domains. One missing character can point an investigation at the wrong infrastructure.
Do not crop away the number or conversation context. Those details help distinguish a one-off message from a repeated script, rotating-number campaign, or domain cluster.
Report through channels the attacker does not control
Use the phone’s report-junk feature or forward the text to 7726 when supported by your carrier. Report suspected fraud to the FTC and alert the impersonated carrier through contact information found independently.
Do not revisit the suspicious site to gather more evidence after reporting it. Preserve what you already have and let providers or investigators handle active infrastructure.
If you clicked or paid, change missions
Contact the card issuer or bank using a trusted number, dispute unauthorized charges, replace exposed credentials, and enable account alerts. If a password was reused, change it anywhere else it appears.
If identity information was submitted, follow the FTC’s identity-theft recovery process. The objective is no longer deciding whether the message was suspicious; it is limiting what the collected data can do.
How this guide was built
Reporting and review note
This guide combines FTC and US Postal Inspection Service guidance with CallSlayer’s screenshot, OCR-correction, number, message, and domain-evidence workflow. The example is a composite anatomy of a common delivery-smishing pattern.
Sources
Dissect the delivery text without trusting it
Upload the screenshot or paste the exact message, correct the extracted text, and inspect the sender and link clues together.