Is a missed delivery notification I received by email always genuine?
No. Fake delivery notifications are one of the most widely distributed phishing methods used to steal card details and login credentials.
Last reviewed: 1 August 2026
Explanation
Parcel delivery phishing emails closely mimic the branding of genuine carriers such as FedEx, UPS, DHL, Royal Mail, and Amazon. They claim a delivery was missed and offer a link to reschedule or pay a small redelivery fee. Clicking the link leads to a fake carrier website that collects your card details or credentials. The tell-tale signs are a sender email address that does not match the carrier's official domain, a generic greeting rather than your name, and a fee for redelivery — real carriers typically do not charge to reattempt a delivery. If you are expecting a parcel, log in directly to the carrier's website by typing the address yourself, and check your tracking number there.
Delivery phishing dominates by volume for a simple statistical reason: at any given moment, a large fraction of recipients genuinely are waiting for a parcel, so an indiscriminate blast lands 'in context' for millions of people without the sender knowing anything about them. Timing amplifies it — campaigns surge around shopping seasons and sales events, exactly when people juggle multiple orders and can no longer remember which carrier serves which purchase. The fake page's small 'redelivery fee' is card harvesting, and the details captured often feed a second act: a call from your 'bank's fraud team' referencing the charge you just made.
One habit makes you immune regardless of how convincing the next template is: delivery problems get checked only in the retailer's order page or the carrier's own app or website, reached by your own typing, never through message links. Applied consistently, it converts every delivery notification — real or fake — into a harmless prompt to check a place you already trust. If card details went into a fake page, contact your bank before charges appear, and treat any follow-up call about 'fraud on your card' as the second stage of the same operation.
Common red flags
- Sender email address does not match the official carrier domain
- Generic greeting such as 'Dear Customer' instead of your name
- Link in the email leads to a domain you do not recognise
- Small payment requested to redeliver a parcel
- You are not expecting any delivery from the carrier named
What to do now
- Do not click any link in the email
- Go directly to the carrier's official website to check your tracking
- Report the phishing email to the carrier and your email provider
- Forward UK phishing emails to [email protected]
Frequently asked questions
What if I did recently order something?
Even if you are expecting a delivery, verify the notification by logging in to the retailer's tracking system directly — not by clicking the link in the email.
Why are delivery emails such a dominant phishing theme?
Statistics. At any moment a large share of people are genuinely expecting parcels, so a mass blast lands 'in context' for millions without the sender knowing anything about them — especially during shopping seasons.
I paid a small 'redelivery fee' on a linked page — what happens next?
Assume full card compromise: contact your bank before larger charges appear. Be ready for a follow-up call posing as your bank's fraud team, referencing the fee to sound credible — that call is stage two of the same scam.