Blog

Fake package delivery texts and what happens if you tap

A text says your parcel is stuck at customs and wants a small payment, and you really are waiting for a delivery. You do not need to read the whole message: look at the name immediately before the last dot in the link, because everything to its left is decoration. If you already tapped, start with step one: close the page and call your bank on the number printed on your card, not the one in the text.

Phone screen showing a fake parcel delivery text message with a warning sign next to it
TürkCallerBlog › Fake package delivery texts and what happens if you tap

What a fake delivery text actually looks like

The samples below are invented. The number and the address in them belong to nobody.

From 0555 000 00 00: Your shipment is held at customs. Pay the 2.90 clearance fee to release delivery: ornek-kargo.example.com/tr

From 0555 000 00 00: Your parcel could not be delivered because your address is incomplete. Update it here: ornek-kargo.example.com/address

From 0555 000 00 00: You have 1 new official notice waiting. Sign in to view it: notice.gov.example-parcel.com

All three share one shape: a reason to hurry, a small fee or a sign-in request, and one link. A real courier never ties payment to a link in a text. If an international parcel genuinely owes duty, you pay it in the courier's own app or on its own site.

The vocabulary is surprisingly narrow too. Once you have seen one, you recognise the rest:

The fastest clue is the shape of the link

You can often decide without reading the message at all. A web address belongs to the part immediately before the last dot. Whatever sits to the left of that changes nothing about who owns the page.

Address in the textWhy it is suspiciousWhat the real one looks like
notice.gov.example-parcel.comThe real domain at the end is example-parcel.com. The official-looking name is only pasted on the left.A government site's address ends with the government domain itself.
Shortened links such as bit.ly addressesThe real destination is hidden until you tap it.Companies write their own address in full.
An address made only of numbers, like 185.0.0.0No domain name was ever registered, you connect straight to a server.Every corporate page has a name.

Add the cheap, freely handed out endings to the list: be careful when an address finishes in icu, cfd, tk or sbs. And addresses written with foreign letters that imitate Latin ones, or beginning with xn--, cannot be told apart by eye. Turkcaller treats these endings, shortened links and lookalike addresses as structural evidence, independent of what the message says.

Looking at the sender usually settles it

Couriers, banks and public services almost always send from a registered short code or brand name rather than a personal-looking mobile number. An official sounding notice from a plain mobile number is worth treating as an impersonation, however correct the wording is.

A brand name in the header is no guarantee either, because whoever sends the text writes that name. So the order is: read the domain immediately before the last dot first, then check whether the sender is a number or a name. If both look wrong, delete it.

What happens after the link opens

Tapping a link does not empty your account by itself. The damage depends on what you do on the page that opens.

  1. A page opens that copies the courier or the institution exactly, down to the logo and the typeface.
  2. To pay the small fee it asks for your card number, expiry date and the three digits on the back.
  3. Then it asks for the verification code your bank just texted you. Type that code in and you have approved a transaction on the scammer's behalf.
  4. Some pages offer a tracking app and push an install file from outside the store. Once installed it can read incoming messages, so it sees the next codes too.
  5. With the card details and one code in hand, the spending starts. Not the small fee, but whatever the card allows.

Opening the page and closing it without typing anything leaves you in a far better position. If you typed something, the section below is for you.

What to do if you already tapped

Panic does not help, order does. Start from whatever you handed over.

  1. Close the page, do not tap the link again, and screenshot the message before deleting it.
  2. If you entered card details, call your bank on its official line. Take that number from the back of your card or the bank's own app, never from the text.
  3. If you typed a verification code into the page, call the bank the same way. The code is single use, but another one can be requested.
  4. If you installed an app the page offered, take the phone off the internet and uninstall it.
  5. If you entered a password, change it from the service's own address, typed into the address bar yourself.
  6. Report the number as spam in Turkcaller so the same message is flagged for others receiving it.

Then report it. In the United States the Federal Trade Commission advises forwarding the message to 7726 (SPAM) so your carrier sees it, and reporting it at ReportFraud.ftc.gov. Elsewhere, send it to your national cybercrime or consumer protection agency. Keep the screenshot either way, the report will ask for it.

You do not have to run these checks by hand

Make Turkcaller your default messaging app and the same signals, the shape of the link, whether the sender is a number or a name, and the corporate wording of the text, are checked before the message ever reaches you. A fake delivery text lands in its own folder: no notification, nothing in your inbox.

No single word decides anything. The link shape, whether the sender is a number or a name, words disguised with lookalike letters and the same text arriving from several different numbers in a short window are weighed together.

On a fresh install classification runs on the phone, which the Protect screen calls Basic protection, and Advanced protection is off until you choose. If you arrived by updating the app, Advanced protection is switched on once for you, and in that mode incoming message content is classified by AI on our server, which catches finer patterns. Either way the Protect screen shows which one is active and you can change it at any time.

How many people a sender reached in the last 24 hours is shown separately, as an informational warning above the conversation. That count uses only the sender's address, never the content of your messages.

Why the text arrived at exactly the right moment

The message was not aimed at you. The same text goes to hundreds of thousands of numbers in a day. All the sender needs is the share of people waiting for a parcel right then, and because most of us have something in transit most weeks, that share is not small.

What makes it work is not fear, it is how ordinary it looks. Big sums make people suspicious, so the fee is kept low on purpose. The technique has a name: smishing, phishing by text. Parcel delivery is the most common costume, but the same skeleton appears as a government notice, a bank alert or a court summons.

Free version and Premium

The spam folder, the link warning and caller identification all work in the free version; the free version shows ads and comes with a daily search allowance. Seeing who is calling when your phone rings does not come out of that allowance. Premium removes the ads, raises the daily allowance and tells you when someone searches your number.

Frequently asked questions

I tapped a fake delivery link, what happens now?

If you entered no card details, no password and no code, and installed nothing, you are almost certainly fine. Watch your card activity for a few days and report the number.

I entered my card details in a fake text. What should I do?

Call your bank straight away, using the number on the back of your card or in the bank's own app, never the one in the text. Ask them to freeze the card and check recent transactions. If you also typed a verification code into the page, say so in the same call.

How do I check if a delivery text is real?

Do not use the link or the number in the message. Open the courier's own app, or the order page of the shop you bought from, and read the tracking status there. A real delivery problem shows up in both places.

Can a text showing the courier's name still be fake?

Yes. The sender name is written by whoever sends the text, so it can be imitated. Judge the link instead: read the domain immediately before the last dot, and never accept a delivery notice that ties payment to a link.

Where do I report a fake delivery text?

In the United States, forward the message to 7726 (SPAM) so your carrier can act on it, then file a report at ReportFraud.ftc.gov. Elsewhere, report it to your national cybercrime or consumer protection agency. Screenshot the message before you delete it, the report will ask for the details.

Does blocking the number stop fake delivery texts?

The same campaign arrives from a new number every time, so blocking one at a time always lags behind. Classification that reads the link shape and the sender type catches the pattern even when the number changes.

Does Turkcaller read my messages?

On a fresh install classification runs on the phone, which the app calls Basic protection. If you arrived by updating the app, Advanced protection is switched on once for you, and in that mode incoming message content is classified by AI on our server. The Protect screen shows which one is active and you can change it at any time.

Are bank verification codes treated as spam?

No. Verification codes are exempt from every automatic filter, because missing a code you are waiting for is the most expensive mistake. Your own decisions still apply: if you block a sender or add your own blocked word, its codes are hidden too, and the app warns you before you block.

Keep fake texts out of your inbox

Make Turkcaller your default messaging app: suspicious texts land in their own folder, links get checked before they open, and the number calling you shows up with a name.

App StoreGoogle Play

Related articles