← All posts

That delivery SMS is not from the courier

Phishing6 min read
A fake delivery text message with a phishing link drawn as a fishing hook

Delivery phishing does not work because it is clever. It works because it is boring , and because at any given moment, a surprising number of us are genuinely waiting for a parcel.

The message is short. A shipment could not be delivered. An address needs confirming. A small customs or redelivery fee is outstanding. There is a link. The amount is deliberately trivial , small enough that paying it feels easier than thinking about it.

Why the small amount is the whole trick

A message demanding ₹40,000 triggers suspicion. A message asking for ₹25 triggers irritation, and irritation makes people move fast.

But the fee is not the point. The payment page is. What the scammer actually wants is the card number, expiry, CVV, and the OTP you are about to be sent , all of which you hand over willingly, because you believe you are paying twenty-five rupees for a parcel.

The fee is bait, not the theftThe real loss usually happens hours or days later, on a card the scammer now has full details for. Some victims never connect the two events.

Reading the link before you tap it

This is the single most useful skill here, and it takes about three seconds once you know where to look.

In any web address, the part that matters is what sits immediately before the first single slash. Read it backwards from there:

Scammers rely on you reading left to right and stopping as soon as you recognise a brand name. The brand name is almost always there. It is the part after it that tells you the truth.

Shortened links

A legitimate courier does not need to hide its own domain behind a bit.ly link in an official notification. If the address is shortened and the message wants money, treat that as the answer.

Red flags

What to do instead

  1. Do not use the link. Ever. Not even to “check”. Some pages harvest data on load.
  2. Go to the retailer, not the courier. Open the app you actually ordered from , Amazon, Flipkart, Myntra , and look at your orders. If a parcel genuinely has a problem, it will say so there.
  3. If you must check with the courier, type their address yourself or search for it. Do not trust the link, and do not trust a phone number given in the message either.
  4. Remember that genuine customs charges are rare for ordinary domestic orders, and are normally collected by the retailer at checkout or by the courier at your door , not by SMS.

If you already entered your card details

  1. Block the card immediately in your banking app. Freezing takes seconds; a replacement card is a minor inconvenience against the alternative.
  2. Do not approve any OTP that arrives afterwards, even if a caller claims it is needed to “cancel” or “reverse” the transaction. That call is the same scammer.
  3. Check your statement for small unfamiliar charges , cards are often tested with a tiny amount before a large one.
  4. In India, report it at cybercrime.gov.in or on 1930, as soon as you can.

Where TruvAI fits

Checking a domain properly means noticing subdomains, lookalike spellings, and characters that are not quite the letters they appear to be. That is genuinely hard to do on a phone screen, in a hurry, on a message that looks routine.

Paste the message into TruvAI, or send it a screenshot, and it does that inspection for you , then explains in plain language what it found, rather than just flagging a colour. If the link is fine, it says so. That matters too: the goal is not to make you afraid of every parcel notification.

Not sure about a message?

TruvAI is coming to iOS and Android. Join the waitlist for early access.

Join the Waitlist