← All stories

"Your Package Couldn't Be Delivered" ๐Ÿ“ฆ๐Ÿ“ฑ

The text scam that lands in millions of phones a week. It's not clever โ€” it just catches you at the exact moment you're expecting a package. Here's how it works, and the one habit that beats it every time.


The Setup: They Don't Need To Know You. They Just Need Good Timing.

You ordered something recently. Everyone did. So when this slides in at 8:14 on a Tuesday, it doesn't feel like an attack โ€” it feels like an errand:

Text message ยท +1 (382) 004-9911
USPS: Your package has been held due to an incomplete delivery address. Please confirm your details within 12 hours to avoid return:
usps.delivery-confirm-track.com/us

Notice what it does: a real-sounding company, a tiny problem ("incomplete address" โ€” could be true!), and a ticking clock ("within 12 hours"). That's the whole trick. Urgency turns off the part of your brain that would've noticed the weird web address.

The Crime Scene: Follow The Link, Meet The Trap

Tap it and you land on a page that looks exactly like the post office โ€” same red-white-and-blue, same logo (copied straight off the real site). It says your package is waiting and there's just a tiny redelivery fee. Like 30 cents.

Thirty cents is the genius part. It's small enough that you don't hesitate โ€” and it's not really about the 30 cents. The form asks for:

  1. Your name and home address โ€” feels reasonable, it's a delivery.
  2. Your full card number, expiry, and CVV โ€” "to process the fee."
  3. Sometimes a texted code right after โ€” that's them logging into your bank as you and asking you to read back the verification code. Now they're past your bank's security too.

You didn't lose 30 cents. You handed a stranger the keys to your card โ€” and they were polite about it.

The Tell: Where It Always Falls Apart

Here's the good news: this scam is lazy, and it leaves the same fingerprints every single time.

๐Ÿšฉ The web address is wrong. Real USPS is usps.com. Scams bolt the real name onto junk: usps.delivery-confirm-track.com. The real owner of a web address is the last two words before the first single slash โ€” here that's delivery-confirm-track​.com, not USPS.
๐Ÿšฉ It came as a text at all. The post office doesn't text you a payment link out of the blue.
๐Ÿšฉ A "fee" to release a package. USPS, UPS, and FedEx don't hold your package hostage for pocket change over text.
๐Ÿšฉ A countdown. "Within 12 hours or it's returned." Real logistics doesn't threaten you like a ransom note.
๐Ÿšฉ A phone number that isn't a company. A random 10-digit cell, or an email-looking sender, not "USPS."

The quiet-hero bit: this is precisely the kind of message GuardDex is built to catch. Long-press the text → "Check with GuardDex," and it reads the link the way a suspicious human would โ€” flags the look-alike web address, the payment-over-text pattern, the urgency โ€” and tells you scam before you tap. It's one of the free apps; no judgment if you'd rather just remember the tells above.

๐Ÿ›ก๏ธ How To Never Get Burned (the part that actually helps)

One habit beats all of these: never act from the message. Go to the source yourself.

The Moral of the Story

Scammers aren't master hackers. They're just patient, and they know you're busy and expecting a package. The message wants you to react. The whole defense is to slow down and go check the real place yourself. Boring beats clever, every time.


Rule of thumb to hand to anyone you love: "If a message tells me to hurry and tap a link, I put the phone down and go to the real app myself." That one sentence is worth more than this whole page.

← More stories ยท The free apps