Skip to main content

CNiC Solutions

Hand holding a smartphone showing a text notification with delivery parcels blurred in the background

Fake USPS delivery texts are not a minor nuisance, they are the single most-reported text scam in the country. In 2024, Americans reported losing $470 million to scams that started with a text message, and the Federal Trade Commission found that copycat package-delivery alerts, most of them impersonating the U.S. Postal Service, topped the list. The scam works because it is plausible: almost everyone has a package on the way, and a text saying it cannot be delivered feels routine enough to tap without thinking. This guide shows you exactly how to tell a fake USPS text from a real one, how to verify a package safely, and how to report the scam, plus what it means when these texts start landing on your employees’ phones.

Key Takeaways

  • Fake package-delivery texts were the top text scam of 2024. The FTC reports that copycat delivery alerts, largely posing as USPS, were the most-reported text scam as losses to text fraud hit $470 million.
  • A real USPS text never contains a link. USPS only texts customers who requested tracking alerts, and those messages carry a tracking number, not a link.
  • The link is the trap. Tapping it opens a lookalike USPS page that harvests your card number, password, or Social Security number.
  • Verify, do not tap. Track any real package by typing usps.com yourself or using the official app, never through a link in a text.
  • Report it: forward to 7726, send a screenshot to spam@uspis.gov, and delete. For businesses, one tapped link on an employee phone can reach a work account.

What’s in This Guide

Why USPS Scam Texts Work So Well

A fake USPS text is a form of smishing, which is phishing carried out by SMS. Instead of an email in an inbox many people already scan with suspicion, the scam arrives in the text thread you trust most and read within minutes. The attacker impersonates the Postal Service, invents a delivery problem, and attaches a link to a fake site. The whole scheme is built to exploit a simple fact: at any given moment, a huge share of people genuinely have a package in transit, so the message lands as a plausible coincidence rather than an obvious con.

The scale is documented in federal data. The Federal Trade Commission’s Consumer Sentinel Network found that reported losses to text-based scams reached $470 million in 2024, five times the total reported in 2020, even though the number of reports fell. Fake package-delivery texts were the most-reported text scam of the year, ahead of phony job offers, bogus bank fraud alerts, fake unpaid-toll notices, and wrong-number scams.

$470M
reported lost to text-message scams in 2024, five times the 2020 total, with fake package-delivery texts the most-reported type.Source: FTC Consumer Protection Data Spotlight, Top Text Scams of 2024

These delivery texts are one thread of a much larger problem. Phishing and spoofing were the most-reported cybercrime of any kind in 2024, generating 193,407 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. A fake USPS text is the same playbook as a phishing email you would catch in your inbox, aimed at the device where your guard is lowest.

193,407
phishing and spoofing complaints to the FBI in 2024, the most-reported cybercrime type of the year.Source: FBI IC3 2024 Internet Crime Report

The good news is that fake USPS texts share a small set of tells, and unlike a sophisticated email spoof, the postal version has one rule working in your favor that almost no scam can fake. The next six steps walk through the checks in the order a careful person would run them, starting with that rule.

Source: FTC Data Spotlight, Top Text Scams of 2024 | FBI IC3 2024 Internet Crime Report

 

 

Infographic labeling the four red flags in a fake USPS delivery scam text message
The four tells that mark a delivery text as a scam: an odd sender, invented urgency, a non-USPS link, and a request for money or data.

 

 

Step 1: Confirm You Actually Asked USPS to Text You

What to do: Ask yourself one question before anything else. Did you sign up for USPS tracking alerts and give the Postal Service your number for this specific shipment? If you did not, the text is not from USPS, full stop.

Why this step matters: This is the tell almost no scam can survive. The U.S. Postal Inspection Service states plainly that USPS will not send customers text messages unless the customer first requested the service with a tracking number. Unsolicited delivery texts are not how the Postal Service operates, so an alert you never signed up for is fraudulent by definition, no matter how official it looks.

What success looks like: You can answer, honestly, whether you opted in to alerts for a real tracking number. If the answer is no, you already know the message is a scam and can stop here, report it, and delete it.

Step 2: Look for a Link, the Single Biggest Tell

What to do: Scan the message for any link, whether it is a full web address, a shortened link, or a “tap here to track or reschedule” button. If there is a link, do not tap it.

Why this step matters: A legitimate USPS text will never contain a link. The Postal Inspection Service is explicit that a real message includes a tracking number and will not contain a link. Scam texts, by contrast, exist to get you to that link, because the link is where the theft happens. It leads to a page dressed up to look like usps.com that asks you to “confirm” an address, pay a fee, or verify your identity, and everything you type goes straight to the scammer.

What success looks like: You treat the presence of any link in a delivery text as disqualifying on its own. Tracking number with no link can be genuine, any link means walk away.

Myth: “It shows a real tracking number, so it must be legitimate.”

A tracking-number format is trivial to fake, and scam texts often include an invalid or made-up number precisely to look official. The number is decoration. What actually separates real from fake is the rule above: a genuine USPS text has no link, and you only receive one if you requested it. Never let a plausible-looking tracking number talk you into tapping a link.

Step 3: Inspect the Sender and the Web Address

What to do: Look at who sent the text and, without tapping, read any web address in it carefully. Real USPS alerts come from a short official shortcode, not a random 10-digit cell number, an international number, or an email-address-turned-text.

Why this step matters: The sender and the domain are far harder to fake convincingly than the words in the message. Scam links lean on lookalikes: an address that puts “usps” in the middle of a longer string, a different ending such as .com replaced by an unusual country domain, or a link shortener that hides the real destination entirely. The one address a real USPS page uses is usps.com. Anything that only resembles it, like usps-tracking-help dot com or a string of random characters, is a counterfeit.

What success looks like: You can name the actual domain a link points to and confirm it is usps.com, not a lookalike. If the sender is a strange number or the address is anything other than the real usps.com, you treat the message as hostile.

Common mistake: Trusting a page because it “looks like” the USPS site once you land on it. Scammers copy the logo, colors, and layout exactly. Visual polish proves nothing, the web address in the bar is what matters, and by then you should not be on the page at all.

Source: U.S. Postal Inspection Service guidance on package-tracking smishing

 

 

Numbered checklist infographic with six steps to identify a fake USPS scam text
Run these six checks, in order, on any delivery text before you tap anything.

 

 

Step 4: Recognize the Pressure Tactic

What to do: Notice what the message is trying to make you feel. Fake USPS texts follow a script: your package cannot be delivered, your address is incomplete, redelivery requires a small fee, or you must “update your preferences” within a short window or lose the shipment.

Why this step matters: Urgency is the mechanism, not a detail. The Postal Inspection Service notes that these scams are engineered to lure you into handing over personal or financial information by manufacturing a problem you feel you must fix immediately. A small, believable amount, often just a dollar or two of “postage due,” makes paying feel easier than questioning. That friction between reading and reacting is exactly where the scam lives.

What success looks like: You recognize the artificial deadline or the tiny fee as a warning sign in its own right, and you let it slow you down rather than speed you up. A real delivery issue will still be there after you verify it through official channels.

Step 5: Verify Tracking Only on USPS.com or the Official App

What to do: If you are genuinely expecting a package and the text makes you worry, do not use the message to check on it. Open a browser and type usps.com yourself, or open the official USPS Mobile app, and enter the tracking number from your own order or shipping confirmation.

Why this step matters: Verifying through a channel you control defeats the scam entirely, because the attacker owns the text but not the real USPS website or your original order email. This single habit, going to the source yourself instead of following the link, neutralizes not just fake USPS texts but nearly every delivery-scam variant impersonating UPS, FedEx, or a retailer.

What success looks like: You confirm a package’s real status using a tracking number you already had, on a site or app you opened yourself. If the official site shows no problem, you know the text was a scam.

 

CNiC Solutions — Cybersecurity

 

Step 6: Never Pay a Fee or Enter Personal Details by Text

What to do: Refuse, on principle, any delivery text that asks for money or personal information. Do not pay a “redelivery” or “customs” fee, and never enter a card number, bank login, password, date of birth, or Social Security number in response to a text.

Why this step matters: This is the payload of the entire scam. The Postal Inspection Service warns that these schemes are after personally identifiable information: usernames and passwords, Social Security numbers, dates of birth, and card or PIN numbers. USPS does not charge for standard delivery through a text link, and no legitimate carrier collects sensitive personal data by SMS. The request itself is the confession.

What success looks like: You never hand over payment or personal details in response to a delivery text. When a package truly needs a fee, such as customs on an international parcel, you handle it through the official carrier site or a notice you can independently confirm, never a texted link.

See how managed cybersecurity stops scams before they reach your team

How to Report a USPS Scam Text

Reporting takes under a minute and does real good: it helps carriers filter the sender and helps investigators shut down the campaign before it reaches more people. The U.S. Postal Inspection Service and the FTC recommend a simple sequence.

If you handle a shared or business phone, add one more step: tell whoever manages your IT or security so they can warn the rest of the team and check whether any work account was touched.

Source: U.S. Postal Inspection Service reporting guidance | CISA guidance on recognizing and reporting phishing

When to Call a Professional

For an individual, spotting and deleting a fake USPS text is the end of the story. For a business, it rarely is. Employees receive these texts on the same phones that hold work email, Microsoft 365 logins, and multi-factor authentication prompts, so a single tapped link and one reused password can hand an attacker a foothold in your systems. That is the moment awareness alone stops being enough.

A managed IT and security partner closes those gaps with layers no single employee can maintain alone: mobile device management on the phones that touch work data, enforced multi-factor authentication so a stolen password is not enough, monitoring that flags a compromised account fast, and training that treats text scams as seriously as email. A Virtual CIO can fold this into a broader security strategy so smishing defense is a documented program, not a matter of who happened to be paying attention that day. These same habits, verify before you act and confirm through a trusted channel, are the core of defending against social engineering in all its forms.

Get managed security across every employee device

Troubleshooting: I Think I Already Fell for One

If you tapped the link, paid a fee, or entered information, do not panic and do not stay quiet. How fast you respond is what limits the damage. Match your situation to the row below and act now.

What happened What to do right now
I tapped the link but did not enter anything Close the page immediately, do not enter any data, and delete the text. Run a scan with your phone’s security software. Report the sender to 7726 and, if it was a work phone, tell your IT team.
I entered my credit or debit card number Call your bank or card issuer now using the number on the back of your card, report the fraud, and ask to freeze or replace the card. Watch your statements and dispute any charge you did not make.
I entered a password I use elsewhere Change that password immediately from a different device, and change it anywhere you reused it. Turn on multi-factor authentication, and if it was a work login, alert IT so they can check for unauthorized access.
I gave my Social Security number or other personal data Go to identitytheft.gov for the FTC’s step-by-step recovery plan, consider a credit freeze with the three bureaus, and monitor your accounts closely for new activity.
An employee reported one on a work phone Warn the whole team so others recognize it, confirm multi-factor authentication is on for their accounts, and have IT or your security provider check for account access and reset anything exposed.

 

 

Infographic showing five response steps to take after clicking a USPS scam text link
If you already tapped the link, these five fast steps limit the damage.

 

 

The worst outcome is not tapping a scam link, it is hiding that you did. In a business, a blame-free reporting culture contains incidents in minutes instead of days, because people speak up early. And if credentials or data were exposed, tested backups and a clear recovery plan are what get you back to normal, which is why reliable backup and recovery belongs in every conversation about scams like this.

Maintain and Monitor: Keeping a Team Scam-Resistant

Catching one fake USPS text is a skill. Keeping a whole team safe as scams evolve is a system. A few ongoing practices turn one-time awareness into durable protection.

Train for text scams, not just email

Most security awareness training still focuses on the inbox, yet smishing now rivals email for reach. Brief, regular training that includes real delivery-scam examples keeps recognition sharp, and it is far more effective than a once-a-year lecture. The goal is a team that reports a suspicious text by reflex. The mechanics carry over directly from how text-message scams work in general.

Enforce multi-factor authentication everywhere

Assume a password will eventually be phished, and make that not enough. Multi-factor authentication on email, financial, and cloud accounts means a single stolen credential cannot open the door. It is the strongest safety net behind human awareness, provided employees also know never to read a one-time code aloud or type it into a page reached from a text.

Manage the devices that touch work data

Personal phones running work email and authentication apps are part of your attack surface whether you manage them or not. Mobile device management and mobile threat defense filter known malicious links and give you a way to respond when a phone is compromised, without taking over the employee’s personal device.

Make reporting easy and expected

Give employees a one-tap way to flag a suspicious text and a clear message that reporting is always the right call, even after a mistake. One quick report lets you warn everyone else before the same campaign spreads across the company.

Frequently Asked Questions

Does USPS send text messages about package deliveries?

Only if you asked it to. USPS sends texts to customers who signed up for tracking alerts with a specific tracking number, and those messages never contain a link. Any unrequested delivery text, or any USPS text with a link in it, is a scam.

What happens if you clicked a link in a USPS scam text?

Tapping the link opens a fake USPS page built to steal information. If you only tapped the link, close it, do not enter anything, and delete the text. If you entered card details or a password, contact your bank or card issuer immediately, change the password from a different device, turn on multi-factor authentication, and watch your accounts.

How do I report a fake USPS text?

Do not tap the link. Forward the message to 7726 (SPAM) to alert your carrier, then send a screenshot showing the sender’s number and the date, along with the message text and your name, to spam@uspis.gov. You can also report it to the FTC at reportfraud.ftc.gov and the FBI at ic3.gov, then delete the text.

Why am I getting USPS texts when I am not expecting a package?

Because scammers send these texts in bulk to phone numbers pulled from data breaches and lists, not because they know you have a package. The message is a guess that works often enough, since many people have something on the way. Getting one does not mean your information was specifically targeted, but you should still report and delete it.

How can businesses protect employees from USPS smishing texts?

Employees receive these texts on the same phones that hold work email and logins, so one tapped link can expose a business account. Combine security awareness training that covers text scams, enforced multi-factor authentication, mobile device management, and a simple way to report a suspicious text, ideally managed as one program rather than left to individual judgment.

Build phishing and smishing defense into your security strategy

Methodology and Sources

All statistics in this article come from Tier 1 primary sources only, with no blog-to-blog citations. Text-scam loss figures and the ranking of fake package delivery as the most-reported text scam of 2024 are from the Federal Trade Commission’s Consumer Protection Data Spotlight, Top Text Scams of 2024 ($470 million reported lost, five times the 2020 total, with reports declining over the same period). The classification of phishing and spoofing as the most-reported cybercrime type, at 193,407 complaints in 2024, is from the FBI Internet Crime Complaint Center 2024 Internet Crime Report. Guidance on how USPS actually communicates (only after a customer requests tracking, and never with a link), the information these scams seek, and how to report a smishing text comes from the U.S. Postal Inspection Service. Reporting and prevention guidance also reflects the Cybersecurity and Infrastructure Security Agency. Figures reflect the most recently published data available as of August 2026; readers are encouraged to consult the primary sources directly. No statistics in this article are estimated or invented.

Primary sources: FTC Data Spotlight: Top Text Scams of 2024, FBI IC3 2024 Internet Crime Report, U.S. Postal Inspection Service: Package Tracking Text Scams, CISA: Recognize and Report Phishing.

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog