A text lands on your phone: “FedEx: your package is held pending a small unpaid delivery fee. Reschedule here.” It looks routine, and that is exactly the problem. Fake FedEx delivery texts, a form of SMS phishing known as smishing, were part of the most commonly reported text scam of 2024, and consumers lost 470 million dollars to text scams that year, according to the Federal Trade Commission. This guide shows you how to spot a fake FedEx text in seconds, how to verify a real one safely, and what to do if you already tapped the link.

Delivery scams succeed because they hit a nerve almost everyone shares: at any given moment, a lot of us are waiting on a package. A scammer does not need to know your order history. They send the same “delivery problem” message to thousands of numbers and let the odds work. Enough recipients are genuinely expecting a delivery that a small percentage will click, and that is all a mass-scale phishing operation needs.
The numbers show how effective this has become. The Federal Trade Commission reported that fake package delivery was the single most commonly reported text scam of 2024, ahead of bogus job offers, fake bank fraud alerts, and phony unpaid-toll notices.
This is not only a consumer nuisance. Phishing and spoofing were the top-reported cybercrime category overall in 2024, and the volume keeps climbing.
Reported U.S. Text-Scam Losses: 2020 vs 2024
2024 figure reported by the FTC. The 2020 baseline reflects the FTC’s statement that 2024 losses were “five times higher” than 2020. Source: Federal Trade Commission.
Because the same delivery-text playbook targets personal phones and work phones alike, the risk crosses over into business security. If an employee taps a smishing link on a device that also holds email or SaaS logins, a personal scam becomes a company incident. That overlap is why we treat delivery smishing as part of a broader approach to recognizing phishing across email and text.
Source: Federal Trade Commission | FBI Internet Crime Complaint Center
Start with who the message claims to be from. Fraudulent delivery texts frequently arrive from ordinary 10-digit mobile numbers, international numbers, or email-to-text gateways (an address ending in something like @something.com that shows up as a text). A real carrier notification does not come from a stranger’s cell phone.
Why this step matters: the sender line is the first and fastest filter. A random personal number carrying a “FedEx” alert is a near-certain tell.
What success looks like: you can state, out loud, exactly what number or address sent the text, and whether that matches how you normally hear from FedEx.
Source: FedEx Trust Center
The payload of almost every fake FedEx text is a link. The entire scam depends on you tapping it, so this is the step where you win or lose. Do not tap. Instead, preview the true destination: on most phones you can press and hold the link to see the full URL, and if it is a shortened link you can expand it with a reputable link-preview or link-expander service before going anywhere.
Real FedEx tracking lives on fedex.com. Scam links lean on tricks that look right at a glance:
Why this step matters: the domain is the ground truth. Logos and formatting can be copied perfectly, but the address bar is much harder to fake.
What success looks like: you have read the actual domain and confirmed whether it is fedex.com or an impostor, without ever loading the page.

Look at what the message wants you to do. Fraudulent delivery texts almost always push one of a few urgent asks, and each one is a bright red flag:
Here is the anchor fact that cuts through all of it: FedEx states plainly that it does not request payment or personal information in return for goods in transit through unsolicited mail, email, or SMS. So a text demanding money to release your package is not a FedEx message. Full stop.
Why this step matters: the request reveals intent. A real delivery update informs you; a scam pressures you to pay or log in.
What success looks like: you can name what the text is asking for, and confirm it falls into “pay a fee” or “enter information,” which FedEx never does by unsolicited text.
Source: FedEx Trust Center | Federal Trade Commission
Ask two simple questions. Are you actually expecting a FedEx package right now? And does any tracking number in the text match a real order you placed? Because scammers blast messages to huge lists at random, a large share of recipients are not waiting on anything from FedEx at all. A delivery alert for a package you never ordered is one of the clearest signs of a scam.
If you are expecting something, do not trust the tracking number in the text. Match it against the confirmation email or order page from the retailer you actually bought from.
Why this step matters: context beats presentation. A message that does not line up with a real order you placed has already failed the test.
What success looks like: you have tied the text to a specific real order, or confirmed there is no such order, in which case you are done and the message is a scam.
When you genuinely need to check on a delivery, go to the source yourself. This single habit defeats nearly every delivery scam, because it removes the scammer’s link from the equation entirely.
Why this step matters: a link or number you sourced yourself cannot be the scammer’s. Verifying independently is the one move that works even when a text is a flawless copy of the real thing.
What success looks like: your package status is confirmed (or disproven) on fedex.com or the retailer’s site, with zero interaction with the text message.
The Federal Communications Commission and FTC give the same core advice for every delivery-scam text: do not click, verify through a channel you trust, and report it. For a deeper look at how these messages are engineered, see our breakdown of real-world phishing examples and the patterns they share.
Source: Federal Communications Commission
Reporting a scam text takes under a minute and helps carriers and investigators shut the operation down faster. Do all three, then delete the message:
Then delete the text. Do not reply, and do not send “STOP,” because any response tells the scammer your number is live and active, which can invite more messages.
Why this step matters: reporting improves the filters that protect everyone else, and it removes a message that could still tempt you later.
What success looks like: the text is forwarded to 7726, reported to FedEx and the FTC, and deleted from your phone.
Source: Federal Trade Commission | FedEx Trust Center
If you reach this step and the smishing link was tapped on a work phone, a company laptop, or any device that stores business email, VPN, or SaaS logins, treat it as a potential security incident rather than a personal mistake. A single harvested credential can give an attacker a foothold into your company’s systems, and delivery-themed lures are a favorite way in.
Report it to your internal IT or security contact immediately, or if your business does not have one, this is exactly where a managed security partner earns its keep: rapid triage, credential resets, device malware scans, and a check for any downstream account access. CNiC Solutions helps Texas and national businesses contain phishing and smishing incidents before they spread, and build the monitoring that catches the next one.
Talk to CNiC About Threat Protection
If you (or an employee) got further than you meant to, do not panic, but do move quickly. Match your situation to the row below.
| What happened | What to do now |
|---|---|
| I tapped the link but entered nothing | Close the page and clear that browser tab. Do not return to it. Watch your accounts for unusual activity over the next few days. Run a mobile security or antivirus scan if your device offers one. |
| I entered a username and password | Change that password immediately, and change it anywhere else you reused it. Turn on multi-factor authentication on the account. If it was a work login, tell IT or security now. |
| I entered credit or debit card details | Contact your bank or card issuer right away to flag the card and dispute charges. Ask about a replacement card. Monitor statements closely. |
| I paid a “delivery fee” | Treat it as card fraud: call your bank to dispute and reissue the card, and report the loss to the FTC at ReportFraud.ftc.gov. |
| It happened on a company device | Report to your IT or security team before doing anything else. They may need to isolate the device, reset credentials, and check whether the link delivered malware or reached business accounts. |
When any of this touches company systems, a professional response is faster and safer than guessing. A managed IT and support team can lock down affected accounts and confirm nothing spread.
Spotting one bad text is a skill. Making sure the next one does not slip through, across an entire team, is a system. After the immediate threat is handled, a few ongoing practices keep delivery smishing from turning into a breach:
These controls are the day-to-day work of a security-minded IT partner. If your business does not have that coverage today, a Virtual CIO can build the training, policies, and monitoring that turn one lucky catch into consistent protection.
Get a Free Security Consultation
This guide draws on primary-source reporting from U.S. government agencies and FedEx’s own fraud guidance. Statistics on text-scam losses and the prevalence of fake package delivery come from the Federal Trade Commission’s April 2025 data spotlight on 2024 text scams. Phishing and spoofing complaint volume comes from the FBI Internet Crime Complaint Center’s 2024 Internet Crime Report. Guidance on what FedEx will and will not send, and how to report impersonation, comes from the FedEx Trust Center. Verification and reporting advice reflects Federal Communications Commission and FTC consumer guidance.
To change where Windows 11 saves your screenshots, open File Explorer, go to Pictures, right-click the…
A cybersecurity incident response plan is the difference between a bad day and a business-ending one.…
Healthcare has been the most expensive industry in the world to breach for 13 straight years,…
Google Workspace and Microsoft 365 are the two dominant productivity suites for business, and there is…