Do not use the link, QR code, attachment, phone number, reply address, or payment page in a suspicious delivery message to verify the message itself. Open the retailer account, carrier app, or official carrier website independently and check whether the same shipment, tracking number, delivery problem, fee, and requested action appear there. An unexpected address update, small redelivery or customs fee, urgent threat, look-alike domain, attachment, QR code, or request for card, password, bank, tax, or identity data is suspicious—but no single clue proves fraud. A valid tracking number, real order, familiar logo, HTTPS, matching timing, or caller ID also does not authenticate the sender or link.
What did you already do?
Use the branch that matches the furthest action you took.
| What happened | Immediate priority |
|---|---|
| I only received or read it | Verify independently, report, block, and delete |
| I clicked or scanned it but entered nothing | Close it, review downloads, update the device and security software, and assess exposure |
| I opened an attachment | Treat it as a possible device-security event |
| I installed an app, profile, or extension | Remove it through official device guidance and review permissions |
| I granted remote access or powerful permissions | End access immediately and secure the device and accounts |
| I entered a username or password | Change the password through the real service and change reused passwords |
| I entered a one-time code | Contact the affected account, bank, card issuer, or service immediately |
| I entered card or bank details | Contact the financial institution through a known official route |
| I paid | Contact the payment provider immediately and preserve the transaction evidence |
| I entered identity, tax, or importer information | Use the relevant official identity-fraud recovery service |
| I replied, called, or texted STOP | Stop communicating, block, report, and verify the shipment independently |
Do not delay financial, account, identity, or device action while waiting for the delivery-message investigation.
Verify the message safely in under two minutes
1. Leave the message closed
Do not:
- click the link;
- scan the QR code;
- open the attachment;
- reply;
- text STOP;
- call the number supplied;
- use the payment page;
- download an app.
2. Check whether a real order exists
Open the retailer or marketplace account independently.
Verify:
- order;
- seller;
- expected item;
- delivery address;
- carrier;
- tracking number.
A real order confirms that an order exists. It does not authenticate the suspicious message.
3. Open the carrier independently
Use:
- a carrier app already installed from an official app store;
- a saved bookmark;
- the carrier website typed independently;
- the tracking link inside the authenticated merchant account.
Do not copy the suspicious URL and “correct” its spelling.
4. Locate the shipment using trusted order information
Prefer the tracking number from:
- the merchant account;
- the original order confirmation;
- a receipt;
- the official carrier account.
A number inside the suspicious message can be real, unrelated, recycled, exposed, or copied.
5. Compare the exact claim
Check whether the official record shows the same:
- tracking number;
- carrier and business division;
- address issue;
- missed-delivery event;
- customs or fee event;
- amount;
- currency;
- pickup instruction;
- delivery-management action;
- deadline.
6. Use only the action inside the official system
Even when the message describes a real problem, do not return to its link.
Complete the action through:
- the authenticated carrier account;
- official tracking;
- the merchant account;
- an official support route obtained independently.
What actually proves authenticity?
No single visual clue is enough.
| Evidence | What it tells you | What it does not prove |
|---|---|---|
| Carrier logo | The sender copied or used carrier branding | The carrier sent it |
| Professional grammar | The message is polished | The sender is genuine |
| Spelling mistakes | The message deserves caution | It is conclusively fraudulent |
| Sender display name | The app displays that name | The underlying sender is authentic |
| Caller ID | The phone displays that number or name | The caller controls that identity |
| HTTPS or padlock | The connection to that site is encrypted | The site belongs to the carrier |
| Correct name or address fragment | The sender knows or guessed some data | The communication is authorized |
| Valid tracking number | A carrier may return a record for that number | The message sender or link is genuine |
| Real expected package | A shipment exists | The message belongs to it |
| Matching delivery day | The timing is plausible | The sender is authentic |
| Official carrier record opened independently | The carrier recognizes the shipment | Every message about it is genuine |
| Same action inside an authenticated official record | The official system independently reproduces the request | A different message link should be used |
| Independent official support confirmation | The carrier or institution confirms the action | A suspicious attachment or page becomes safe |
The strongest practical evidence is not that the message looks real. It is that the same shipment-specific action appears inside an independently opened official system.
A real tracking number does not authenticate the message
A working tracking number proves only that the carrier returns a record for that number.
It does not prove:
- the sender owns the number;
- the message was addressed to the correct recipient;
- the link belongs to the carrier;
- the fee belongs to the shipment;
- the requested action is authorized;
- the person contacting you is a carrier employee.
A scammer can use:
- a number exposed on a shipping label;
- a number from a compromised account or seller;
- a number copied from another source;
- a real number sent to many recipients;
- a legitimate shipment as context for a fraudulent payment page.
The public tracking number may also belong to another person.
Do not publish a full number while asking others to verify the message.
I am expecting a package. Does that make the message genuine?
No.
Large delivery-scam campaigns reach many people who happen to be expecting packages.
A message can also arrive near:
- a genuine failed delivery;
- a real signature attempt;
- an actual customs event;
- a real delivery date;
- a carrier-status change.
Matching timing makes the message more persuasive. It does not authenticate the sender, link, fee, or requested action.
Do not assume a carrier, retailer, or seller suffered a data breach merely because the timing matches. The source of the information cannot be determined from timing alone.
The message says I must update my address
Common versions claim:
- apartment number is missing;
- postal code is invalid;
- street address is incomplete;
- delivery cannot continue;
- the parcel will be returned unless the address is updated immediately.
A real address problem can occur.
The message still does not prove:
- the carrier attempted delivery;
- the carrier found the problem;
- the recipient is allowed to change the address;
- the sender authorized a change;
- a fee is required.
Verify an address request
- Open the merchant account.
- Review the shipping address.
- Open official carrier tracking.
- Look for a real address-related event.
- Check whether the carrier offers an eligible delivery-management action.
- Contact the seller or carrier through an official route when no action appears.
Do not enter the address into the suspicious page.
The complete workflow for a genuine address problem belongs to the dedicated address guide.
The message asks for a small redelivery, postage, or customs fee
A small amount is not harmless.
The page can collect:
- card number;
- expiry;
- security code;
- billing address;
- phone number;
- email address;
- account password;
- one-time code.
The immediate charge can be small while the payment and identity exposure is much larger.
Legitimate fees can exist
Do not use the false rule:
Delivery companies never request fees.
Carrier and jurisdiction rules differ.
Examples from current official guidance include:
- UPS can expose eligible import-payment actions inside official tracking.
- DHL can have legitimate duties-and-taxes workflows.
- Canada Post has an official customs-duty and tax payment process, while its security guidance says it does not text users to request card, banking, login, or delivery-payment information.
- Royal Mail can send a documented customs-fee notification and also use a physical Fee to Pay card.
- USPS requested tracking notifications are free and, under its cited tracking-text process, contain no link.
Verify any fee independently
Confirm all of the following:
- expected shipment;
- correct carrier and business division;
- official tracking record;
- exact tracking number from the merchant account;
- same status or issue;
- named charge;
- amount;
- currency;
- recipient;
- official authenticated payment route;
- receipt.
Do not pay through:
- a shortened URL;
- an unrelated or look-alike domain;
- a personal bank account;
- cryptocurrency;
- gift card;
- wire to an individual;
- messaging-app payment;
- remote-access session;
- a page not reproduced in official tracking.
A legitimate charge may exist while the message carrying it is fraudulent.
Shortened, misspelled, or deceptive domains
Common look-alike patterns include:
- a missing or extra letter;
- swapped letters;
- hyphens;
- added words such as
track,secure,delivery, orsupport; - an unexpected country suffix;
- the carrier name placed in a subdomain of another domain;
- a URL shortener;
- a numeric IP address;
- a QR code that hides the destination.
The controlling domain matters
A carrier name can appear on the left side of a longer address without controlling the domain.
Do not attempt to repair, shorten, or manually edit the suspicious URL.
Open the official carrier site independently instead.
HTTPS is not proof
A padlock means the connection to the site is encrypted.
A fraudulent site can also use encryption.
HTTPS does not prove that:
- the carrier owns the domain;
- the payment page is authorized;
- the organization is genuine.
A browser or antivirus warning is a reason to stop. The absence of a warning is not proof of safety.
Urgency, threats, and final notices
Common pressure tactics include:
- final notice;
- act within hours;
- package will be returned;
- package will be destroyed;
- delivery suspended;
- customs release will fail;
- fee increases today;
- legal action;
- last delivery attempt.
Urgency is designed to reduce independent verification.
A real shipment or customs process can have a deadline. Therefore:
urgent language
→ stop and verify independently
Do not let the message’s deadline determine the verification route.
Requests for cards, passwords, codes, bank, tax, or identity data
Payment-card information
High-risk fields include:
- card number;
- expiry;
- security code;
- billing address.
Account credentials
High-risk fields include:
- carrier password;
- merchant password;
- email password;
- password-reset code;
- one-time login code.
Banking information
High-risk fields include:
- account details;
- routing information;
- online-banking credentials;
- transfer authorization.
Identity and importer information
A legitimate customs or broker process can sometimes request:
- tax or importer number;
- business registration;
- proof of identity;
- proof of purchase;
- authorization.
This does not make an unsolicited request trustworthy.
Before sending sensitive information:
- Open the carrier, broker, merchant, or customs portal independently.
- Confirm the same shipment-specific request.
- Verify the responsible business division and destination country.
- Review the official upload and privacy instructions.
- Submit only what the official process requires.
- Save confirmation.
One-time codes
A one-time code can authorize:
- payment;
- account login;
- password reset;
- device enrollment;
- card enrollment.
Do not provide it to a caller or message page unless you independently initiated the verified action and understand what the code authorizes.
I am not expecting a package
An unexpected package message with a link, QR code, attachment, or fee request is strongly suspicious.
Do not interact.
Check independently:
- retailer and marketplace accounts;
- household members, when relevant;
- known incoming business shipments.
A genuine notification can occasionally reach an old, mistyped, or recycled phone number or email.
Therefore:
But a person with no recognized shipment has no reason to use the message link or pay the requested fee.
The message or package contains a QR code
A QR code is a link in visual form.
It can lead to:
- fake carrier login;
- payment page;
- credential theft;
- app download;
- permission request;
- malicious redirect.
Do not scan an unexplained QR code in:
- a text;
- an email;
- a printed notice;
- an unsolicited package.
The FBI and USPIS have warned about unsolicited packages containing QR codes used to collect personal or financial information or to deliver malicious software.
Do not:
- install an app;
- grant accessibility access;
- grant device-management access;
- grant screen sharing;
- grant remote control;
- grant SMS or notification access.
A full unsolicited-package or brushing-scam workflow belongs to a separate guide.
Suspicious attachment or download
FedEx warns that fraudulent delivery notices can contain links or attachments associated with malware.
Canada Post also identifies suspicious download links and protected files as warning signs.
Do not:
- open or preview the attachment;
- enable macros;
- enter an attachment password;
- run an executable;
- install an extension;
- install an app or profile.
If you already opened or installed something, use the device-exposure branch below.
Phone call, voicemail, WhatsApp, or social-media message
Caller ID, a carrier logo, a familiar profile picture, and a display name can be spoofed or copied.
Do not call back using the number in the suspicious communication.
Obtain support information from:
- official carrier site;
- authenticated carrier app;
- merchant account;
- known card or bank app.
UPS says that a representative contacting a customer about a package should be able to provide a tracking number that can be verified independently at ups.com.
A working number is context—not proof of the caller’s identity or payment request.
Carrier-specific rules are not interchangeable
USPS
Current USPS and Postal Inspection Service guidance states that, under the cited USPS tracking-notification process:
- the customer first requests tracking notifications for a specific package;
- the texts use five-digit short codes;
- tracking notifications are free;
- the cited tracking texts do not contain a link.
An unsolicited USPS-branded message asking for delivery action through an unfamiliar link should not be used.
Verify through USPS.com independently.
USPS-related smishing can be reported to the Postal Inspection Service and forwarded to 7726 under current U.S. guidance.
These rules are USPS-specific.
UPS
UPS warns about fraudulent calls and texts that:
- claim a package is waiting;
- request payment or personal information;
- use malicious links.
UPS recommends verifying the tracking number independently at ups.com.
Do not use an embedded link merely because the number works.
FedEx
FedEx warns that fraudulent delivery notices can:
- imitate shipment communications;
- direct users to malware-hosting sites;
- include harmful attachments;
- request payment or sensitive information;
- provide unfamiliar email addresses or phone numbers.
Use official FedEx tracking and fraud resources independently.
DHL
DHL warns that phishing can use:
- email;
- websites;
- SMS;
- social accounts;
- WhatsApp;
- spoofed sender addresses;
- unfamiliar links;
- attachments.
DHL can also have legitimate duties-and-taxes processes.
Therefore, neither of these rules is safe:
- every DHL payment message is genuine;
- every DHL payment message is fake.
Verify the shipment and charge through the correct DHL division and official process.
Canada Post
Canada Post states that:
- its cited tracking and mail notifications are opt-in;
- it does not text users to request credit-card or banking information;
- it does not text for account-login details;
- it does not text for payments related to deliveries or tracking;
- suspicious messages should not be clicked, answered, or unsubscribed from;
- official tracking is the safest place to check whether duties or taxes are due.
Canada Post publishes sender codes for current legitimate notification processes. Those codes can change and should not be treated as permanent proof of authenticity.
Royal Mail
Royal Mail provides an important United Kingdom comparison.
Royal Mail says it can send a customs-fee notification under its documented process and can leave a grey Fee to Pay card.
It also warns that:
- logos can be copied;
- sender information can be forged;
- familiar branding does not prove authenticity;
- users should verify through official tracking;
- card details and confidential information should not be emailed.
This is why a universal “carriers never text about fees” rule would be unsafe.
If you only received the message
- Do not interact.
- Verify the shipment independently.
- Preserve a redacted screenshot if you plan to report it.
- Use the message app’s spam-reporting function.
- Block the sender.
- Delete the message after preserving needed evidence.
Do not reply, argue, or ask the sender to prove identity.
If you clicked or scanned but entered nothing
Opening a page confirms only that the page was opened.
It does not prove:
- the device was infected;
- the device is safe;
- credentials were stolen;
- no information was collected.
Use a proportionate response:
- Close the page.
- Do not return to it.
- Do not download or install anything.
- Review browser downloads.
- Update the operating system, browser, and security software.
- Run an appropriate security scan.
- Check whether any information was entered or permissions were granted.
- Report the message.
- Monitor relevant accounts when there is a reason to suspect exposure.
FTC guidance recommends updating security software and running a scan when a clicked link or opened attachment may have downloaded harmful software.
Do not assume that a factory reset is always required.
If you opened an attachment
Treat an unexpected delivery attachment as a possible device-security exposure.
- Stop interacting with it.
- Do not enable macros or protected content.
- Update security software.
- Run an appropriate scan.
- Review recent downloads and installed software.
- Review whether passwords, payment data, or permissions were supplied.
- Change exposed credentials from a trusted device.
- Use current official device support when compromise is suspected.
Do not upload the suspicious attachment to 11Tracking.
If you installed an app, profile, extension, or granted access
Higher-risk actions include:
- installing an app from the page;
- installing a device-management profile;
- installing a browser extension;
- granting accessibility permissions;
- granting remote-control or screen-sharing access;
- granting SMS or notification access;
- allowing a remote-support session.
Immediate priorities:
- End the remote session.
- Disconnect the device from untrusted remote access.
- Remove unfamiliar software or profiles using official device instructions.
- Revoke unnecessary permissions.
- Update and scan the device.
- Review account sessions and recent sign-ins.
- Change exposed passwords from a trusted device.
- Contact qualified technical support when compromise may remain.
Operating-system-specific removal instructions change frequently and are outside this page’s scope.
If you entered a username or password
- Open the real service independently.
- Change the password immediately.
- Use a new, strong password.
- Change the password anywhere else it was reused.
- Review active sessions.
- Sign out unfamiliar sessions.
- Review recovery email and phone settings.
- Review newly connected apps.
- Enable or repair multifactor authentication.
- Check recent sign-ins and security alerts.
If the exposed password was for email, secure the email account first. Email access can be used to reset other accounts.
If you entered a one-time code
A one-time code can authorize a login, payment, password reset, or device enrollment.
Contact the affected institution immediately through an independently obtained official route.
Possible institutions include:
- bank;
- card issuer;
- email provider;
- merchant;
- mobile carrier;
- payment app.
Tell the institution what the code may have authorized.
Do not wait for an unauthorized transaction to appear.
If you entered card information
Contact the card issuer or bank immediately using:
- the number on the physical card;
- the bank’s official app;
- a known official website.
Report:
- exposed card details;
- any unauthorized charge;
- the suspicious merchant or descriptor;
- when the exposure occurred.
Follow the issuer’s instructions regarding:
- card lock;
- replacement;
- transaction monitoring;
- dispute or reversal request.
A reversal or reimbursement is not guaranteed.
Do not contact the “bank support” number supplied by the suspicious message.
If you entered bank credentials or account details
- Contact the bank immediately through its official app or known number.
- Report credential or account exposure.
- Change online-banking credentials.
- Review transactions.
- Review linked payment services.
- Follow the bank’s instructions for securing the account.
- Preserve case numbers and confirmations.
Do not move money based on instructions from an unsolicited caller claiming to protect the account.
If you paid the fee
Act according to the payment method.
Credit or debit card
Contact the issuer immediately and ask about:
- card security;
- replacement;
- stopping or reversing the charge;
- monitoring.
Bank transfer or debit
Contact the bank immediately and ask whether the transfer can be stopped or reversed.
Payment app
Report the transaction to the app provider and the linked bank or card issuer.
Wire transfer
Contact the wire-transfer provider immediately.
Gift card
Contact the gift-card issuer and preserve the card and receipt.
Cryptocurrency
Contact the platform used to send the funds.
Cryptocurrency transfers are often difficult or impossible to reverse.
Preserve payment evidence
Save:
- amount;
- currency;
- payment method;
- transaction ID;
- recipient or merchant descriptor;
- receipt;
- screenshot;
- date and time.
Watch for recovery scams
A second scammer may promise to recover the money for an advance fee.
Do not pay someone who claims guaranteed recovery.
If you entered identity, tax, customs, or importer information
Possible exposed data includes:
- Social Security number;
- Social Insurance Number;
- passport;
- driver licence;
- tax identifier;
- importer number;
- date of birth;
- proof of address;
- identity document image;
- proof of purchase.
United States
Use IdentityTheft.gov for recovery steps based on the exact information exposed.
Canada
Use current Canadian Anti-Fraud Centre and national reporting guidance.
Preserve evidence, contact relevant financial institutions, change exposed passwords, and follow official credit-bureau or document-replacement steps when applicable.
Other countries
Use the official national identity-fraud, cybercrime, police, or consumer-protection service.
Do not rely on one global identity-theft process.
If you replied, called, or texted STOP
The sender may now know that the communication channel is active.
This does not by itself prove:
- account compromise;
- identity theft;
- payment loss;
- device infection.
Stop communicating.
Then:
- block;
- report;
- verify the shipment independently;
- monitor for additional targeted messages.
Canada Post specifically advises users not to reply, unsubscribe, or text STOP to suspicious messages. The general safe principle is not to continue the conversation.
Preserve evidence without exposing yourself
Save, when relevant:
- screenshot;
- visible message text;
- sender number or email;
- date and time;
- visible domain;
- claimed carrier;
- transaction receipt;
- bank or carrier case number;
- fraud-report confirmation.
Redact before sharing
Remove:
- full tracking number;
- address;
- phone;
- email;
- order number;
- card or bank information;
- identity number;
- passport or licence;
- QR code;
- active link tokens;
- one-time codes;
- barcode.
Do not publish a clickable suspicious link.
A redacted screenshot and non-clickable domain text are safer than an active URL, but independent official verification remains the correct method.
Where to report the message
Reporting routes change. Use the current official pages linked below.
United States
Current official routes include:
- forward suspicious texts to 7726;
- report fraud to the FTC;
- use IdentityTheft.gov for exposed identity information;
- report appropriate cyber-enabled financial crime to the FBI Internet Crime Complaint Center.
USPS-specific
Current USPIS guidance asks users to report USPS smishing through its published process, including contact form, and to forward the text to 7726.
Follow the current USPIS page because reporting details can change.
DHL-specific
DHL’s U.S. fraud-awareness page currently lists a phishing reporting route.
The anti-abuse route is not a shipment-support service.
Canada
Current official routes include:
- forward spam texts to 7726;
- report victimization through the Canadian Anti-Fraud Centre or the current national cybercrime reporting process;
- contact financial institutions immediately after payment or credential exposure.
Canada Post states that users do not need to send every suspicious message to Canada Post itself.
United Kingdom comparison
Royal Mail publishes:
- its current scam-reporting route;
- 7726 for spam texts;
- the appropriate national fraud-reporting path for people who interacted or lost information or money.
Check the current Royal Mail page for jurisdiction-specific instructions.
When another guide is the right answer
Use a specialized guide when:
- the official tracking number itself returns Not Found or Invalid;
- the independently verified carrier record shows a real customs document or payment request;
- customs has cleared but no destination-carrier event appears;
- the real issue is a missing package after a Delivered event;
- the user needs a full tracking-number recovery process;
- the user needs a full identity-theft, banking-dispute, malware-removal, or legal workflow;
- an unsolicited physical package requires a complete brushing-scam analysis.
This page owns authenticity verification and immediate exposure response.
Save only independently verified shipments in USTracking
After independently verifying the shipment through the merchant or official carrier, you can save it in USTracking to organize publicly available tracking events.
USTracking cannot:
- certify a sender;
- verify a phone number or caller ID;
- authenticate an email address;
- certify a domain, link, or QR code;
- open or analyze a suspicious attachment;
- certify a payment page or fee request;
- scan a device;
- remove malware;
- block a card or bank account;
- reverse a payment;
- restore an account;
- contact a carrier, bank, authority, or merchant;
- report fraud;
- guarantee recovery.
Related 11Tracking guides
-
What Does “Available for Pickup” Mean? — verify the official ready event and location independently before trusting a pickup or fee message.
-
How to Find and Verify a Tracking Number — verify the exact identifier independently before trusting a delivery message.
-
Package Tracking Help Center — choose the correct tracking, problem, action, international, or safety guide.
-
Why Is My Tracking Number Not Found or Not Working? — troubleshoot a carrier lookup that returns no usable record.
-
Package Stuck in Customs — resolve a verified customs review, document, importer-information, or payment request.
-
Customs Cleared but No Tracking Update — diagnose a real post-clearance carrier-handoff gap.
-
Package Says Delivered but I Did Not Receive It — recover a missing package after a real Delivered event.
-
Sources, Verification, and Editorial Methodology — see how 11Tracking separates official evidence, warning signals, inference, and uncertainty.
-
Who Should I Contact About a Package? — identify the party that controls the next useful action.
-
How to Get Proof of Delivery, a Delivery Photo, or a Signature — retrieve official delivery photo, signature, or Proof of Delivery only through independently verified carrier routes.
-
Official Carrier Support Directory — open verified official carrier support channels.
Additional planned guides cover:
- Wrong Address or Address Information Required;
- Unsolicited Package or Brushing Scam.
Only eligible published pages should render as live links.
Official sources
U.S. Postal Inspection Service
Federal Trade Commission
- Think That Text Message Is From USPS? It Could Be a Scam
- How to Recognize and Report Spam Text Messages
- How to Recognize and Avoid Phishing Scams
- What To Do if You Were Scammed
- New FTC Data Show Top Text Message Scams of 2024
- IdentityTheft.gov
U.S. cybersecurity and law enforcement
Carriers and postal operators
- UPS: Protect Yourself From Fraud and Scams
- FedEx: How to Recognize and Help Prevent Fraud and Scams
- DHL: Fraud Awareness
- Canada Post: Recognizing Spam, Fraudulent Emails and Text Messages
- Canadian Anti-Fraud Centre: What to Do if You Are a Victim of Fraud
- Royal Mail: Help With Online Security
- Royal Mail: Typical Online Scams
Scope and limitations
- This page explains how to verify a suspicious delivery communication and how to respond to common forms of exposure.
- It does not inspect one live URL, attachment, QR code, website, caller, sender, or device.
- It does not guarantee that a message is genuine or fraudulent.
- A valid tracking number, correct name, real order, expected delivery, carrier logo, sender display name, caller ID, HTTPS connection, or professional grammar does not independently authenticate the communication.
- A suspicious clue does not always prove fraud; legitimate carrier notification, customs-payment, and delivery-management rules differ.
- The strongest practical verification is the same shipment-specific action appearing in an independently opened authenticated carrier or merchant system.
- Financial, identity, device, legal, reporting, and recovery procedures vary by institution and jurisdiction.
- Reporting addresses, sender codes, short codes, domains, phone numbers, and carrier processes can change before the next scheduled review.
- This page does not provide malware analysis, legal advice, banking-dispute representation, identity-theft investigation, or a recovery guarantee.
- 11Tracking is independent and is not a carrier, postal operator, customs authority, bank, card issuer, cybersecurity provider, law-enforcement agency, or fraud-reporting service.
Last reviewed: July 22, 2026 Next scheduled review: September 20, 2026 Correction contact: contact form Evidence basis: Current official USPS/USPIS, FTC, CISA, FBI IC3, UPS, FedEx, DHL, Canada Post, Canadian Anti-Fraud Centre, and Royal Mail guidance, supported by the private page-specific research packet