Quick answer
A real courier does not ask you to pay a small fee through a link in an SMS, and it does not move your parcel to a different site. Check the domain letter by letter, check that the message names a shipment you actually expect, and never enter card details on a page reached from a text.
Delivery-fraud SMS are the highest-volume scam in Europe because they need no personal data: the same text works on millions of numbers that have never ordered anything from the courier named. A small fee — usually between one and three euro — is low enough not to raise alarm and high enough to be worth harvesting in bulk.
The message rarely steals the fee. It captures the full card number, expiry and CVV on a page that copies a courier's design, and the card is then used for larger purchases or resold.
The three checks, in order
- Do you actually have a shipment in progress with that company? If you ordered nothing, the message is wrong before you even open it — no courier sends a fee request to someone with no parcel.
- Read the domain character by character, from the dot before the extension backwards. `sameday-post.ro`, `sameday.co`, `sameday-plata.info` and `sameday.xyz` are four different companies from Sameday.
- Has the message kept the courier's normal tone? Real notifications state a number and a status; fraud messages invent urgency ("last attempt", "destroyed in 24 hours") to prevent exactly this kind of reading.
Ranges you can recognise without checking
- Sender shown as a plain 10-digit mobile number rather than a short alphanumeric ID. Companies use registered sender IDs; fraudsters use phones or recycled short codes.
- Links shortened with bit.ly, cutt.ly, t.co or a random five-letter domain. A courier's tracking link is on the courier's domain, because that is the only place it can work.
- A "re-delivery fee" of a few cents to a few euro, payable by card only, with no cash-on-delivery option.
- Grammar that is almost right: an automated text from a large company is proof-read, and the near-miss sentence is the most reliable single signal.
If you already entered your card
- Freeze the card in your banking app immediately. This stops recurring charges, which is where these operations earn most of their money.
- Call the bank and ask for the card to be cancelled, not just blocked. Reported-card numbers are still usable for card-not-present fraud until the card is replaced.
- Ask for a dispute on the unauthorised transaction, mentioning that the payment was made on a page reached from a fraudulent SMS — that fact is part of the fraud report.
- Change the password on any account using the same email and password combination, and enable two-factor authentication there.
- Report the message as spam in your phone's messaging app, so the same sender is filtered for everyone on the network.
Why blocking the sender is not enough
Blocks work on a sender ID, and sender IDs are cheap: the same campaign reappears the next morning from a different number or a different country's routing. The durable protection is a habit — never open a payment page from a message you did not request, and always type the courier's domain yourself in the browser.
Frequently asked questions
The questions this article gets asked most, answered directly.
How do they get my number if I never ordered anything?
Numbers are dialled at random or drawn from lists leaked in old breaches. Volume is the point: a campaign sent to a hundred thousand numbers needs a handful of people who are expecting a parcel and tap the link without reading the domain.
I opened the link but did not enter anything. Am I safe?
Visiting the page does not give away your card. It does tell the operator that your number is live, which makes follow-up messages more likely, and some pages try an automatic download. Clear the tab, and do not install anything you did not ask for.
The page looked exactly like the real courier's site. How is that possible?
Copying a page is trivial: the design, the logo and the tracking form can be saved from the real site in a few minutes. What cannot be copied is the domain, which is why the domain — not the design — is the only thing worth checking.
Does reporting the SMS do anything?
Yes. Network-level reports feed the filters that block a sender ID for all recipients. It also gives your mobile operator the evidence it needs to act, which an individual complaint to a courier cannot.
Written by The BaitScan editorial team
Results are automated risk estimates based on public indicators and heuristics.