Fake USPS delivery texts are not a minor nuisance, they are the single most-reported text scam in the country. In 2024, Americans reported losing $470 million to scams that started with a text message, and the Federal Trade Commission found that copycat package-delivery alerts, most of them impersonating the U.S. Postal Service, topped the list. The scam works because it is plausible: almost everyone has a package on the way, and a text saying it cannot be delivered feels routine enough to tap without thinking. This guide shows you exactly how to tell a fake USPS text from a real one, how to verify a package safely, and how to report the scam, plus what it means when these texts start landing on your employees’ phones.
A fake USPS text is a form of smishing, which is phishing carried out by SMS. Instead of an email in an inbox many people already scan with suspicion, the scam arrives in the text thread you trust most and read within minutes. The attacker impersonates the Postal Service, invents a delivery problem, and attaches a link to a fake site. The whole scheme is built to exploit a simple fact: at any given moment, a huge share of people genuinely have a package in transit, so the message lands as a plausible coincidence rather than an obvious con.
The scale is documented in federal data. The Federal Trade Commission’s Consumer Sentinel Network found that reported losses to text-based scams reached $470 million in 2024, five times the total reported in 2020, even though the number of reports fell. Fake package-delivery texts were the most-reported text scam of the year, ahead of phony job offers, bogus bank fraud alerts, fake unpaid-toll notices, and wrong-number scams.
These delivery texts are one thread of a much larger problem. Phishing and spoofing were the most-reported cybercrime of any kind in 2024, generating 193,407 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. A fake USPS text is the same playbook as a phishing email you would catch in your inbox, aimed at the device where your guard is lowest.
The good news is that fake USPS texts share a small set of tells, and unlike a sophisticated email spoof, the postal version has one rule working in your favor that almost no scam can fake. The next six steps walk through the checks in the order a careful person would run them, starting with that rule.
Source: FTC Data Spotlight, Top Text Scams of 2024 | FBI IC3 2024 Internet Crime Report

What to do: Ask yourself one question before anything else. Did you sign up for USPS tracking alerts and give the Postal Service your number for this specific shipment? If you did not, the text is not from USPS, full stop.
Why this step matters: This is the tell almost no scam can survive. The U.S. Postal Inspection Service states plainly that USPS will not send customers text messages unless the customer first requested the service with a tracking number. Unsolicited delivery texts are not how the Postal Service operates, so an alert you never signed up for is fraudulent by definition, no matter how official it looks.
What success looks like: You can answer, honestly, whether you opted in to alerts for a real tracking number. If the answer is no, you already know the message is a scam and can stop here, report it, and delete it.
What to do: Scan the message for any link, whether it is a full web address, a shortened link, or a “tap here to track or reschedule” button. If there is a link, do not tap it.
Why this step matters: A legitimate USPS text will never contain a link. The Postal Inspection Service is explicit that a real message includes a tracking number and will not contain a link. Scam texts, by contrast, exist to get you to that link, because the link is where the theft happens. It leads to a page dressed up to look like usps.com that asks you to “confirm” an address, pay a fee, or verify your identity, and everything you type goes straight to the scammer.
What success looks like: You treat the presence of any link in a delivery text as disqualifying on its own. Tracking number with no link can be genuine, any link means walk away.
A tracking-number format is trivial to fake, and scam texts often include an invalid or made-up number precisely to look official. The number is decoration. What actually separates real from fake is the rule above: a genuine USPS text has no link, and you only receive one if you requested it. Never let a plausible-looking tracking number talk you into tapping a link.
What to do: Look at who sent the text and, without tapping, read any web address in it carefully. Real USPS alerts come from a short official shortcode, not a random 10-digit cell number, an international number, or an email-address-turned-text.
Why this step matters: The sender and the domain are far harder to fake convincingly than the words in the message. Scam links lean on lookalikes: an address that puts “usps” in the middle of a longer string, a different ending such as .com replaced by an unusual country domain, or a link shortener that hides the real destination entirely. The one address a real USPS page uses is usps.com. Anything that only resembles it, like usps-tracking-help dot com or a string of random characters, is a counterfeit.
What success looks like: You can name the actual domain a link points to and confirm it is usps.com, not a lookalike. If the sender is a strange number or the address is anything other than the real usps.com, you treat the message as hostile.
Source: U.S. Postal Inspection Service guidance on package-tracking smishing

What to do: Notice what the message is trying to make you feel. Fake USPS texts follow a script: your package cannot be delivered, your address is incomplete, redelivery requires a small fee, or you must “update your preferences” within a short window or lose the shipment.
Why this step matters: Urgency is the mechanism, not a detail. The Postal Inspection Service notes that these scams are engineered to lure you into handing over personal or financial information by manufacturing a problem you feel you must fix immediately. A small, believable amount, often just a dollar or two of “postage due,” makes paying feel easier than questioning. That friction between reading and reacting is exactly where the scam lives.
What success looks like: You recognize the artificial deadline or the tiny fee as a warning sign in its own right, and you let it slow you down rather than speed you up. A real delivery issue will still be there after you verify it through official channels.
What to do: If you are genuinely expecting a package and the text makes you worry, do not use the message to check on it. Open a browser and type usps.com yourself, or open the official USPS Mobile app, and enter the tracking number from your own order or shipping confirmation.
Why this step matters: Verifying through a channel you control defeats the scam entirely, because the attacker owns the text but not the real USPS website or your original order email. This single habit, going to the source yourself instead of following the link, neutralizes not just fake USPS texts but nearly every delivery-scam variant impersonating UPS, FedEx, or a retailer.
What success looks like: You confirm a package’s real status using a tracking number you already had, on a site or app you opened yourself. If the official site shows no problem, you know the text was a scam.
What to do: Refuse, on principle, any delivery text that asks for money or personal information. Do not pay a “redelivery” or “customs” fee, and never enter a card number, bank login, password, date of birth, or Social Security number in response to a text.
Why this step matters: This is the payload of the entire scam. The Postal Inspection Service warns that these schemes are after personally identifiable information: usernames and passwords, Social Security numbers, dates of birth, and card or PIN numbers. USPS does not charge for standard delivery through a text link, and no legitimate carrier collects sensitive personal data by SMS. The request itself is the confession.
What success looks like: You never hand over payment or personal details in response to a delivery text. When a package truly needs a fee, such as customs on an international parcel, you handle it through the official carrier site or a notice you can independently confirm, never a texted link.
See how managed cybersecurity stops scams before they reach your team
Reporting takes under a minute and does real good: it helps carriers filter the sender and helps investigators shut down the campaign before it reaches more people. The U.S. Postal Inspection Service and the FTC recommend a simple sequence.
If you handle a shared or business phone, add one more step: tell whoever manages your IT or security so they can warn the rest of the team and check whether any work account was touched.
Source: U.S. Postal Inspection Service reporting guidance | CISA guidance on recognizing and reporting phishing
For an individual, spotting and deleting a fake USPS text is the end of the story. For a business, it rarely is. Employees receive these texts on the same phones that hold work email, Microsoft 365 logins, and multi-factor authentication prompts, so a single tapped link and one reused password can hand an attacker a foothold in your systems. That is the moment awareness alone stops being enough.
A managed IT and security partner closes those gaps with layers no single employee can maintain alone: mobile device management on the phones that touch work data, enforced multi-factor authentication so a stolen password is not enough, monitoring that flags a compromised account fast, and training that treats text scams as seriously as email. A Virtual CIO can fold this into a broader security strategy so smishing defense is a documented program, not a matter of who happened to be paying attention that day. These same habits, verify before you act and confirm through a trusted channel, are the core of defending against social engineering in all its forms.
Get managed security across every employee device
If you tapped the link, paid a fee, or entered information, do not panic and do not stay quiet. How fast you respond is what limits the damage. Match your situation to the row below and act now.
| What happened | What to do right now |
|---|---|
| I tapped the link but did not enter anything | Close the page immediately, do not enter any data, and delete the text. Run a scan with your phone’s security software. Report the sender to 7726 and, if it was a work phone, tell your IT team. |
| I entered my credit or debit card number | Call your bank or card issuer now using the number on the back of your card, report the fraud, and ask to freeze or replace the card. Watch your statements and dispute any charge you did not make. |
| I entered a password I use elsewhere | Change that password immediately from a different device, and change it anywhere you reused it. Turn on multi-factor authentication, and if it was a work login, alert IT so they can check for unauthorized access. |
| I gave my Social Security number or other personal data | Go to identitytheft.gov for the FTC’s step-by-step recovery plan, consider a credit freeze with the three bureaus, and monitor your accounts closely for new activity. |
| An employee reported one on a work phone | Warn the whole team so others recognize it, confirm multi-factor authentication is on for their accounts, and have IT or your security provider check for account access and reset anything exposed. |

The worst outcome is not tapping a scam link, it is hiding that you did. In a business, a blame-free reporting culture contains incidents in minutes instead of days, because people speak up early. And if credentials or data were exposed, tested backups and a clear recovery plan are what get you back to normal, which is why reliable backup and recovery belongs in every conversation about scams like this.
Catching one fake USPS text is a skill. Keeping a whole team safe as scams evolve is a system. A few ongoing practices turn one-time awareness into durable protection.
Most security awareness training still focuses on the inbox, yet smishing now rivals email for reach. Brief, regular training that includes real delivery-scam examples keeps recognition sharp, and it is far more effective than a once-a-year lecture. The goal is a team that reports a suspicious text by reflex. The mechanics carry over directly from how text-message scams work in general.
Assume a password will eventually be phished, and make that not enough. Multi-factor authentication on email, financial, and cloud accounts means a single stolen credential cannot open the door. It is the strongest safety net behind human awareness, provided employees also know never to read a one-time code aloud or type it into a page reached from a text.
Personal phones running work email and authentication apps are part of your attack surface whether you manage them or not. Mobile device management and mobile threat defense filter known malicious links and give you a way to respond when a phone is compromised, without taking over the employee’s personal device.
Give employees a one-tap way to flag a suspicious text and a clear message that reporting is always the right call, even after a mistake. One quick report lets you warn everyone else before the same campaign spreads across the company.
Build phishing and smishing defense into your security strategy
All statistics in this article come from Tier 1 primary sources only, with no blog-to-blog citations. Text-scam loss figures and the ranking of fake package delivery as the most-reported text scam of 2024 are from the Federal Trade Commission’s Consumer Protection Data Spotlight, Top Text Scams of 2024 ($470 million reported lost, five times the 2020 total, with reports declining over the same period). The classification of phishing and spoofing as the most-reported cybercrime type, at 193,407 complaints in 2024, is from the FBI Internet Crime Complaint Center 2024 Internet Crime Report. Guidance on how USPS actually communicates (only after a customer requests tracking, and never with a link), the information these scams seek, and how to report a smishing text comes from the U.S. Postal Inspection Service. Reporting and prevention guidance also reflects the Cybersecurity and Infrastructure Security Agency. Figures reflect the most recently published data available as of August 2026; readers are encouraged to consult the primary sources directly. No statistics in this article are estimated or invented.
Primary sources: FTC Data Spotlight: Top Text Scams of 2024, FBI IC3 2024 Internet Crime Report, U.S. Postal Inspection Service: Package Tracking Text Scams, CISA: Recognize and Report Phishing.
Cyber insurance is a business insurance policy that pays for the financial fallout of a cyberattack…
TTPs, short for tactics, techniques, and procedures, describe how a cyber attacker behaves: the goal they…
An IT standard operating procedure (SOP) is a documented, step-by-step set of instructions for performing a…
Passkey, defined: A passkey is a phishing-resistant login credential that replaces your password with a cryptographic…