Package help

Customs or Carrier Asks for ID, Tax Number, Invoice, or Proof: What to Do Safely

Verify a customs request for ID, a tax number, an invoice, proof of payment, or authorization before sharing sensitive information.

A customs-related request for an ID, tax or import number, invoice, proof of payment, address evidence, or authorization can be legitimate. But the document type, a real order, and a correct tracking number do not authenticate the requester or justify sending every requested field. Before disclosing anything, independently reproduce the request on an official surface, confirm who is acting for whom and why, identify who owns the record, and verify the exact accepted payload and submission route.

What to do in the first five minutes

Pause disclosure, but do not ignore the deadline shown in the notice. Preserve the message or paper notice, record the date and timezone privately, and then start from a source you already trust.

  1. Open the seller or marketplace account and confirm that the order, goods, buyer, recipient, destination, and shipping method match.
  2. Open the carrier, postal operator, broker, or customs service independently—from a saved app, a typed official address, or the authenticated order—not from the message link, QR code, attachment, reply address, or displayed phone number.
  3. Look for the same shipment, customs case, document dependency, reference, and deadline on that official surface.
  4. Ask what exact clearance task is blocked, which authority is responsible, and what role must supply the information.
  5. Do not upload yet if the purpose, data owner, accepted document, required fields, or applicable route is still unclear.

If you do not recognize the shipment or cannot reproduce the request, do not send identity or financial evidence merely because the sender knows a tracking number. If you already clicked, uploaded data, disclosed credentials, installed software, or paid a suspicious recipient, move to Fake Delivery Text, Email, Fee, or Tracking Link for exposure-response steps.

Verify two separate chains before disclosure

A request can pass one chain and fail the other. Confirm both.

Chain Questions that must have an answer What a failure means
Authority and purpose Which shipment and customs case? Who is asking? Which customs authority or principal does that actor represent? What exact decision needs the evidence? Who owns the requested fact or record? A genuine company or real parcel may still be unrelated to the required role, purpose, or data owner. Do not disclose yet.
Disclosure and state What number, field, page, document, or alternative is accepted? Is masking expressly permitted? Which independently reached route applies? How will receipt and validation appear? Even a correct document can go to the wrong tool, expose too much data, or arrive without being accepted for the case.

Customs authorities often work through postal operators, express carriers, authorized couriers, or customs brokers. A carrier request is therefore not automatically fraudulent. The reverse is equally important: a real carrier domain or employee does not prove that a particular portal applies to your country, carrier division, product, shipment, or role.

Identify what the request is supposed to prove

“Customs documents required” is not a sufficient explanation. Different records answer different questions.

Request Possible case-specific purpose Key question before submission
Passport, national ID, or residence document Match the importer, ultimate consignee, recipient, identity, or address Is a full image required, or is a less sensitive accepted alternative available for this exact role?
SSN, EIN, TIN, EORI, CPF, PCC, PAN, GSTIN, or another import identifier Identify an importer, economic operator, business, or personal-import record Is this person or business actually the party that the customs case requires?
Commercial or pro forma invoice Establish the transaction, goods, quantity, origin, value, or shipping terms Who created the shipment and owns the true source invoice?
Order confirmation or marketplace receipt Link the purchase, buyer, seller, goods, and price Is the authenticated order record accepted for the stated customs purpose?
Proof of payment Test the amount paid, ownership, or declared value Which transaction fields are needed, and what unrelated financial information may be omitted or masked if the process expressly allows it?
Address evidence Match the consignee, importer, or delivery address Which documents and matching rules apply, and who owns that address record?
Authorization or power of attorney Permit a broker, courier, or third party to act Is the signer the principal with authority, and what is the exact scope of the authorization?
Business registration or item-use evidence Establish commercial status, admissibility, ownership, repair, gift, or end use Does the request belong to the business, seller, sender, owner, or another named actor?

The name of an identifier is not a global rule. U.S. importer-identification requirements, EU EORI rules, Brazilian recipient identifiers, Korean personal-import codes, and Indian courier KYC are different systems. Use the identifier and role named by the current official case; do not borrow another person’s number or transfer a requirement from another country.

Identify who owns the requested record

The recipient is not automatically the importer, buyer, payer, declarant, exporter, or account holder. Determine ownership before deciding who should act.

Record Likely source owner Common unsafe mistake Correct route
Personal ID or personal import number The named importer, ultimate consignee, or recipient in the verified case Sending a spouse’s, colleague’s, sender’s, or employer’s identifier The named person responds through the official process or the case owner corrects the party record
Business importer registration The importing business and its authorized officer or broker Using company data for a personal shipment, or personal data for a business import Confirm the importer role and business authorization first
Commercial invoice Seller, exporter, shipper, or authorized trade workflow Creating a replacement invoice or changing the value or description locally Obtain the truthful source record from the seller/exporter; route substantive errors to the declaration-correction owner
Order confirmation Buyer or marketplace account holder Asking a different recipient to expose an account they do not control The buyer supplies the authenticated record through the accepted route
Proof of payment Payer or account holder Sharing another person’s statement or unrelated transactions The payer confirms the narrow evidence accepted for this case
Address proof The person or business tied to the address Editing a document because the delivery and ID addresses differ Use a published alternative or the official mismatch-correction route
Broker authorization Importer, exporter, or other named principal Signing a broad authorization without being the principal Verify the agent, shipment, scope, and official form

UPS U.S. states in its export workflow that the person creating the export shipment prepares the commercial invoice. That is a useful ownership boundary, not a global invoice format: a recipient should not invent or alter a seller/exporter record to make it fit the request.

If the invoice, declared value, goods description, origin, Harmonized System code, or named party is materially wrong, the problem is no longer just safe submission. The responsible seller, exporter, importer, or declarant must correct the underlying source record through the official case. Do not turn a factual mismatch into a cleaner-looking document.

Confirm the minimum accepted disclosure—do not invent a redaction rule

Data minimization is a reason to ask precise necessity questions. It is not proof that every customs process accepts a cropped, edited, or partly masked document. Some verified processes accept one field or a less sensitive alternative; others require a complete readable page, an exact name/address match, a signature, or additional proof.

Before uploading, obtain process-specific answers to these questions:

  1. Is a number or field enough, or is a document image required?
  2. Which alternative documents or identifiers are accepted for this role?
  3. Which pages, fields, photographs, dates, signatures, seals, names, and addresses must remain readable?
  4. Is masking or redaction expressly permitted? If so, exactly which fields may be masked?
  5. What file type, size, image quality, language, translation, certification, or signing rule applies?
  6. Who receives and stores the data, is it reused for later shipments, and where is the current privacy notice?

If the official instructions are silent about masking, ask through the verified case. Do not assume either that full disclosure is necessary or that your preferred redaction will be accepted. Never send a password, one-time code, recovery code, card security code, or bank login to a customs requester. Do not provide another person’s identity or tax number unless you are the verified authorized representative and the official process expressly requires that record.

Proof of payment requires the same discipline. It may be relevant to customs valuation, but “proof” does not automatically mean a complete bank statement. Ask whether an order receipt, transaction receipt, transfer confirmation, statement segment, or another case-approved record is accepted and which fields must remain visible. Do not alter the amount, currency, seller, date, discount, shipping charge, refund, or payment method to remove an inconsistency.

Use scoped official examples to test universal advice

Current official systems point in different directions. These examples show why the method must be case-specific:

  • DHL Express India lists several KYC document alternatives for a resident individual and separate address-proof rules when the KYC address does not match the delivery address. This does not establish an acceptable-document or masking rule for another DHL division or country.
  • Korea Customs Service describes a Personal Customs Clearance Code that substitutes for a resident-registration number in personal-import declarations and publishes an in-person route for a foreigner who has only a passport and cannot obtain the code online. This is a Korean personal-import process, not a global passport rule.
  • Canada Border Services Agency says a casual importer using its published self-accounting route presents the shipment identifier, invoice or receipt, and personal ID at an eligible office; a third party also needs authorization and a copy of the importer’s ID. That is a scoped Canadian alternative, not a general instruction to email those documents to a courier.
  • Brazil’s Receita Federal describes cases in which an ecommerce platform failed to transmit a CPF or transmitted mismatched information. Data already entered at checkout may therefore require correction or retransmission; it does not prove that the customs case received or accepted it.

These examples do not let 11Tracking identify the correct document for a particular parcel. They establish the safer general rule: discover the accepted evidence, owner, channel, and state inside the exact current process.

Verify the submission route, not just the brand

Use a trust ladder rather than one visual clue.

Evidence reached independently What it establishes What remains to verify
Order and official tracking match The shipment exists and is connected to the user Requester, customs case, purpose, and channel
Official account, tracker, postal portal, customs notice, or known support confirms the dependency A real action is recorded Who acts for whom and which role owns the response
Carrier or customs authority confirms the broker or processor and case reference The authority chain is supported Accepted payload, privacy notice, and route applicability
Authenticated portal, official app, published office, or verified case channel applies to this country, product, and role The destination is suitable for this case Whether the submission was received and validated
Receipt, timestamp, file list, or case acknowledgment appears The submission reached the process Readability, completeness, matching, acceptance, and customs decision

Do not rely on a logo, HTTPS padlock, caller ID, message grammar, urgency, search advertisement, or a URL that resembles the carrier. Also do not assume that every genuine page on a carrier domain is an appropriate recipient tool. Some document systems are for shippers, brokers, businesses, or particular countries only.

If the request began by email, SMS, call, or chat, the channel type alone does not decide legitimacy. Preserve the solicitation, then reproduce the action through a known official route. Ordinary email may be a published channel in one process and an unsafe reply destination in another.

Submit truthfully and preserve the case state

Use the verified route for one coherent case. Avoid sending duplicate copies to several unconfirmed addresses or opening a new case when the authenticated process provides a correction path.

Keep a private local record of:

  • the exact request and stated purpose;
  • the requester and represented authority;
  • the deadline and trigger shown in the authenticated notice;
  • the document type or identifier submitted, without copying its sensitive contents into casual notes;
  • the official route, date, time, case reference, and receipt;
  • the validation result or exact rejection reason; and
  • later customs release and later carrier movement as separate events.

The state sequence matters:

submitted
→ received
→ readable and complete
→ accepted for the stated purpose
→ customs review or another dependency
→ customs release
→ carrier movement
→ delivery

An upload confirmation proves only the state it names. It does not prove that the file is readable, that the facts match the customs record, that customs accepted it, or that the parcel was released. Even accepted evidence can be followed by valuation review, a payment request, inspection, a permit question, or another agency decision.

If the document is rejected or the records do not match

Use the rejection reason to separate a submission defect from an underlying-record defect.

Verified state Responsible next action Do not do
File is unreadable, incomplete, unsigned, in the wrong format, or missing a required page Follow the correction or resubmission route inside the existing verified case Send uncontrolled copies to new addresses or change factual content
Name or address does not match Identify which official identity, shipment, or consignee record is wrong and which owner may correct it Edit an ID image or borrow another person’s record
Invoice, value, currency, goods description, origin, or party is wrong Have the seller, exporter, importer, or declarant correct the source record truthfully Fabricate an invoice, recharacterize a purchase as a gift, or manipulate proof of payment
Tax/import number was entered at checkout but is absent or mismatched in customs Ask the marketplace or submitting actor whether it was attached to this order, transmitted, matched, and validated Assume that marketplace possession equals customs receipt
Request is addressed to the wrong person or business Ask the carrier, broker, marketplace, seller, or customs case owner to correct the importer/consignee/authorization route Supply someone else’s identifier to keep the parcel moving
Evidence was accepted but the parcel remains under review Check the current named customs dependency and responsible actor Resubmit the same file or assume acceptance guaranteed release

If the current blocker becomes a charge rather than a document, use Customs Fee, Duty, Tax, Brokerage, or Release Payment Request. If the parcel remains held and no specific dependency is visible, use Package Stuck in Customs. A later post-release tracking silence belongs to the carrier handoff state, not to this document-request workflow.

If you cannot use the published portal or document format

Do not create an unofficial route by sending files to an address found in a forum or social-media reply. Contact the verified authority, carrier, postal operator, broker, or marketplace and ask whether it publishes:

  • an accessible version of the portal or form;
  • an assisted-submission method;
  • an in-person, postal, or telephone-supported route;
  • language support or an authorized-representative process; or
  • a correction path that keeps the existing case and deadline.

Some authorities publish offline or in-person alternatives; others do not. Ask early and preserve the response. If an authorized representative may act, confirm the required authority and scope before sharing the principal’s ID or signing a power of attorney.

Protect privacy and deadlines while the request is reviewed

A customs response date can be real even when the incoming message uses urgency. Record the date and trigger from the independently opened official case, then verify through the fastest official route. Do not publish or send customs references, tracking numbers, identity images, tax numbers, invoices, payment records, addresses, QR codes, or account screenshots to 11Tracking.

The customs-document process does not automatically pause a seller response date, marketplace case window, return deadline, payment dispute, card chargeback, insurance notice, or carrier claim. Discover each clock, its owner, its trigger, and whether another process is compatible before opening, pausing, or closing it. Use Protect Package Refund, Dispute, and Chargeback Deadlines for that separate deadline work.

If a seller will not provide a truthful invoice or order record, preserve the request and the seller’s response while protecting the relevant commercial remedy. Do not create substitute evidence to avoid losing the customs deadline.

What this method cannot determine

This method cannot authenticate a particular requester for you, decide who is legally the importer, prescribe a passport or tax number, approve a redaction, interpret a power of attorney, determine the correct customs value or classification, validate a document, correct an official record, or guarantee release. 11Tracking does not accept, inspect, redact, store, or transmit identity documents, customs records, invoices, payment evidence, credentials, or personal identifiers.

Use Customs Processing when the immediate question is what the tracking event means. Use Who to Contact About a Package when the responsible actor remains unclear. If payment was already made or the request has changed into a restriction, declaration, or post-release problem, follow the owner of that new state rather than continuing to upload documents to the first requester.