A text says your parcel is stuck at customs and wants a small payment, and you really are waiting for a delivery. You do not need to read the whole message: look at the name immediately before the last dot in the link, because everything to its left is decoration. If you already tapped, start with step one: close the page and call your bank on the number printed on your card, not the one in the text.

The samples below are invented. The number and the address in them belong to nobody.
From 0555 000 00 00: Your shipment is held at customs. Pay the 2.90 clearance fee to release delivery: ornek-kargo.example.com/tr
From 0555 000 00 00: Your parcel could not be delivered because your address is incomplete. Update it here: ornek-kargo.example.com/address
From 0555 000 00 00: You have 1 new official notice waiting. Sign in to view it: notice.gov.example-parcel.com
All three share one shape: a reason to hurry, a small fee or a sign-in request, and one link. A real courier never ties payment to a link in a text. If an international parcel genuinely owes duty, you pay it in the courier's own app or on its own site.
The vocabulary is surprisingly narrow too. Once you have seen one, you recognise the rest:
You can often decide without reading the message at all. A web address belongs to the part immediately before the last dot. Whatever sits to the left of that changes nothing about who owns the page.
| Address in the text | Why it is suspicious | What the real one looks like |
|---|---|---|
| notice.gov.example-parcel.com | The real domain at the end is example-parcel.com. The official-looking name is only pasted on the left. | A government site's address ends with the government domain itself. |
| Shortened links such as bit.ly addresses | The real destination is hidden until you tap it. | Companies write their own address in full. |
| An address made only of numbers, like 185.0.0.0 | No domain name was ever registered, you connect straight to a server. | Every corporate page has a name. |
Add the cheap, freely handed out endings to the list: be careful when an address finishes in icu, cfd, tk or sbs. And addresses written with foreign letters that imitate Latin ones, or beginning with xn--, cannot be told apart by eye. Turkcaller treats these endings, shortened links and lookalike addresses as structural evidence, independent of what the message says.
Couriers, banks and public services almost always send from a registered short code or brand name rather than a personal-looking mobile number. An official sounding notice from a plain mobile number is worth treating as an impersonation, however correct the wording is.
A brand name in the header is no guarantee either, because whoever sends the text writes that name. So the order is: read the domain immediately before the last dot first, then check whether the sender is a number or a name. If both look wrong, delete it.
Tapping a link does not empty your account by itself. The damage depends on what you do on the page that opens.
Opening the page and closing it without typing anything leaves you in a far better position. If you typed something, the section below is for you.
Panic does not help, order does. Start from whatever you handed over.
Then report it. In the United States the Federal Trade Commission advises forwarding the message to 7726 (SPAM) so your carrier sees it, and reporting it at ReportFraud.ftc.gov. Elsewhere, send it to your national cybercrime or consumer protection agency. Keep the screenshot either way, the report will ask for it.
Make Turkcaller your default messaging app and the same signals, the shape of the link, whether the sender is a number or a name, and the corporate wording of the text, are checked before the message ever reaches you. A fake delivery text lands in its own folder: no notification, nothing in your inbox.
No single word decides anything. The link shape, whether the sender is a number or a name, words disguised with lookalike letters and the same text arriving from several different numbers in a short window are weighed together.
On a fresh install classification runs on the phone, which the Protect screen calls Basic protection, and Advanced protection is off until you choose. If you arrived by updating the app, Advanced protection is switched on once for you, and in that mode incoming message content is classified by AI on our server, which catches finer patterns. Either way the Protect screen shows which one is active and you can change it at any time.
How many people a sender reached in the last 24 hours is shown separately, as an informational warning above the conversation. That count uses only the sender's address, never the content of your messages.
The message was not aimed at you. The same text goes to hundreds of thousands of numbers in a day. All the sender needs is the share of people waiting for a parcel right then, and because most of us have something in transit most weeks, that share is not small.
What makes it work is not fear, it is how ordinary it looks. Big sums make people suspicious, so the fee is kept low on purpose. The technique has a name: smishing, phishing by text. Parcel delivery is the most common costume, but the same skeleton appears as a government notice, a bank alert or a court summons.
The spam folder, the link warning and caller identification all work in the free version; the free version shows ads and comes with a daily search allowance. Seeing who is calling when your phone rings does not come out of that allowance. Premium removes the ads, raises the daily allowance and tells you when someone searches your number.
If you entered no card details, no password and no code, and installed nothing, you are almost certainly fine. Watch your card activity for a few days and report the number.
Call your bank straight away, using the number on the back of your card or in the bank's own app, never the one in the text. Ask them to freeze the card and check recent transactions. If you also typed a verification code into the page, say so in the same call.
Do not use the link or the number in the message. Open the courier's own app, or the order page of the shop you bought from, and read the tracking status there. A real delivery problem shows up in both places.
Yes. The sender name is written by whoever sends the text, so it can be imitated. Judge the link instead: read the domain immediately before the last dot, and never accept a delivery notice that ties payment to a link.
In the United States, forward the message to 7726 (SPAM) so your carrier can act on it, then file a report at ReportFraud.ftc.gov. Elsewhere, report it to your national cybercrime or consumer protection agency. Screenshot the message before you delete it, the report will ask for the details.
The same campaign arrives from a new number every time, so blocking one at a time always lags behind. Classification that reads the link shape and the sender type catches the pattern even when the number changes.
On a fresh install classification runs on the phone, which the app calls Basic protection. If you arrived by updating the app, Advanced protection is switched on once for you, and in that mode incoming message content is classified by AI on our server. The Protect screen shows which one is active and you can change it at any time.
No. Verification codes are exempt from every automatic filter, because missing a code you are waiting for is the most expensive mistake. Your own decisions still apply: if you block a sender or add your own blocked word, its codes are hidden too, and the app warns you before you block.
Make Turkcaller your default messaging app: suspicious texts land in their own folder, links get checked before they open, and the number calling you shows up with a name.
App StoreGoogle Play