It’s pretty common to receive a delivery notification these days. Sadly, it’s becoming just as common to realise that notification was fake and someone is just trying to steal your money rather than deliver your parcel.
By impersonating trusted delivery companies, cybercriminals are able to catch people off guard, especially when they’re already expecting a package. In this piece, we’ll break down a real scam message, explain the red flags to look out for, and explore why delivery notification scams continue to be so effective.
Real Scam Break Down
Take this text message we received as an example.
At first glance, it looks like a routine delivery notification. It claims to be from Australia Post, says a parcel cannot be delivered, and asks for an unpaid customs fee to be paid through the link provided. But there are several clear warning signs.
The message came from an unfamiliar mobile number rather than an official sender ID. It also creates urgency by suggesting the parcel cannot be delivered until payment is made, encouraging the recipient to act quickly without checking whether the request is genuine.
The message is also intentionally vague. It doesn’t include a parcel number, recipient name, tracking information or any details that would confirm a legitimate delivery. Instead, it relies on the assumption that many people are already expecting a parcel and won’t think twice before clicking.
The biggest red flag is the link:
aus-post.cyou
Australia Post’s official website uses auspost.com.au. The scam domain adds a hyphen and uses an unfamiliar domain extension to create something that looks close enough to be believable at a quick glance.
The message also claims that customs fees haven’t been paid. Scammers will often ask for a relatively small payment because it feels believable and encourages people to act quickly rather than question whether the request is legitimate.
This scam does not need to be perfect. It only needs to reach someone who is already expecting a parcel and convince them to click before they stop to check the details.
It's Not Just Australia Post
These scam messages claiming to be from a toll provider were all received over the space of a few months.
What’s immediately noticeable is that every message is slightly different. The wording changes, the phone number changes, and the domain changes, but the tactic remains exactly the same. Each message claims there’s an outstanding toll payment, warns about penalties for not acting quickly, and includes a link to a website that appears legitimate at first glance.
In reality, these messages were never relevant to the recipient. They were simply sent in bulk, hoping to reach someone who had recently travelled on a toll road and would click without questioning it.
This approach isn’t limited to delivery services or toll operators either. Australia Post, courier companies, toll providers and other well-known organisations are regularly impersonated because people are familiar with them and are less likely to question messages that appear to come from a trusted brand.
Research commissioned by Australia Post found that 73% of Australians have received a fake delivery or parcel scam, while 49% have received fake toll payment messages. More than half (54%) initially believed a fake delivery notification was legitimate before realising it was fraudulent.
The broader phishing landscape tells a similar story. Scamwatch has already recorded more than 6,000 phishing scams delivered by text message in 2026, resulting in reported losses of over $1.3 million.
The Domain Usually Gives It Away
The text message is only the first part of the scam. The link is where the real risk begins.
Every example shown above uses a different domain, including addresses such as aus-post.cyou, tollsauo.info, linkrcn.info, and tollsnew.ltd. None of these belong to the organisations they claim to represent.
Attackers register new domains that resemble trusted brands closely enough to look convincing on a phone screen. They may add hyphens, include words such as “track”, “parcel”, “toll” or “delivery”, slightly misspell the company name, or use an unfamiliar domain extension.
This allows the message to appear relevant without directing the recipient to the organisation’s real website.
Before clicking a delivery or toll notification, check the full domain carefully. Compare it with the official website, rather than relying on the brand name used in the message. If the link looks unfamiliar, contains unusual spelling, or uses a domain extension you would not expect, avoid opening it.
Other warning signs include messages sent from random mobile numbers, unexpected payment requests, vague delivery details, threats of penalties, and pressure to act immediately.
The safest option is to avoid the link altogether. Open the delivery company’s official website or app yourself and enter the tracking number there. For toll notices, log in through the provider’s official website rather than using the link in the message.
A message may use the right company name and sound convincing, but the domain often reveals where it is really trying to take you.
Why This Matters for Delivery Services
Every fake delivery notification damages trust in the brand being impersonated.
For delivery providers, every phishing campaign that impersonates their brand creates additional work and uncertainty. Customers may contact support to verify suspicious messages, report scams, or question whether legitimate delivery notifications can be trusted.
The challenge is that these scams rarely involve a single fake website. Threat actors often register multiple lookalike domains, rotate infrastructure, and launch coordinated phishing campaigns that can continue even after individual domains are taken down.
This is where proactive monitoring becomes essential. By identifying newly registered impersonation domains, uncovering related campaign infrastructure, and using threat intelligence to connect malicious activity, delivery providers can detect emerging threats earlier and disrupt them before more customers are affected.
At unphish, we help organisations detect, investigate, and disrupt brand impersonation across domains, websites, social media, mobile applications, and other online channels. By combining domain monitoring, campaign clustering, and enforcement, organisations gain greater visibility into coordinated phishing campaigns and can respond before they have the opportunity to scale.