The text feels almost boring, which is exactly why it works. "Your package is being held at customs. A tariff of $3.99 is due before delivery." A small amount, a real-sounding reason, and a link to pay. Nothing about it screams scam. That's the new twist on an old trick, and the tell is hiding in plain sight.
Why this version feels so believable
Delivery scam texts (the polite name is "smishing," a mash-up of SMS and phishing) have been around for years. The classic ones say your package is "on hold" or you "missed a delivery," and their close cousin is the unpaid-toll text. Plenty of people learned to shrug those off.
The tariff-and-customs version is harder to shrug off, and it's timed to the moment. Talk of tariffs and import fees is everywhere, so a message claiming you owe a small customs charge on something you actually ordered from overseas lands as plausible rather than absurd. The amount is deliberately tiny; a few dollars doesn't trigger the "this is too good to be true" alarm the way a fake lottery win does. You're not being promised anything. You're just being asked to clear a modest fee so your real package can move.
And the warnings are fresh. On March 30, 2026, Arizona Attorney General Kris Mayes warned that scammers are impersonating UPS, FedEx, and USPS with texts about package problems that carry links leading to malware, identity theft, and financial fraud. Her framing is the whole scam in one sentence: "By creating just enough urgency, they get people to click before they think. If you get an unexpected text or email about a package, slow down and don't react — it's almost certainly a scam." And the hook keeps renewing itself: since July 1, 2026, the EU applies a new handling fee to low-value parcels, and Ireland's consumer watchdog has warned of scam texts using exactly this "pay the customs fee" angle, as RTÉ reported.
The one rule that cuts through all of it
Here is the single most useful fact in this whole article, straight from the people who investigate mail fraud. The U.S. Postal Inspection Service states plainly that USPS will not send you a text or email about a package unless you first requested that tracking service yourself, "and it will NOT contain a link."
There's a second rule sitting right next to it. USPS does not charge a redelivery fee — its own redelivery FAQ calls redelivery a free service. So any text demanding a fee, a "customs charge," a "tariff," or a "small handling cost" before your package can move is waving a second flag at you.
The Federal Trade Commission's consumer alert, dated April 23, 2025, backs this up and widens it: texts claiming to be from USPS, FedEx, or DHL about a package, whether an order confirmation, an out-for-delivery note, "unpaid postage," or a missed delivery, are often scams built to get you to tap a look-alike link and hand over personal or financial details. Its advice is blunt: don't click links in unexpected delivery messages, and check with the carrier yourself instead.
What the link is really after
The $3.99 isn't the prize. It's the doorway. The page the link opens is built to look like a carrier's payment form, and once you're there it wants far more than a few dollars:
- Your card number. Not for the tiny fee, but to charge later or sell.
- Your name, address, and phone. Enough to make the next scam sound like it knows you.
- Sometimes a "verification" login. A fake sign-in that harvests a password you may reuse elsewhere.
Some links don't even wait for you to type. A hostile page can try to push malware onto your phone the moment it loads, which is exactly the risk the Arizona AG's office named.
How to check the link before you touch it
You don't have to guess. Here's the slow-down move, step by step.
- Don't tap the link. Not even to "see where it goes." The point of the check is to look at the address without loading it.
- Look at the domain, not the words. Long-press the link (phone) or hover over it (computer) to preview the real address without opening it, or copy the link instead. The words might say "USPS," but the domain after the
https://and before the first single slash is what actually matters. - Compare it to the carrier's real domain. The genuine sites are short:
usps.com,ups.com,fedex.com. Scam links pile on extra words, likeusps-customs-fee.helportrack-usps.delivery-pay.com, so the real brand is buried in a longer address the brand doesn't own. - Go to the source yourself. If you're genuinely expecting a package, open a browser and type the carrier's address by hand, or use the tracking number in the app you already trust. Never let the text be your route in.
- Or paste the domain into IP Tracker and let it run the comparison in seconds.
usps.comthe carrier's actual domainusps-customs-fee.help"usps" is just a word bolted to a domain someone else registeredHow does IP Tracker help here?
IP Tracker is a free Chrome extension. Copy the link's domain (or paste a suspicious sender's full email address) into the popup; the free tier gives you 25 checks a day, with no account and no tracking. Only the value you paste is looked up.
For a delivery-scam link, it does a few boring checks at once so you don't have to. It compares the domain against the official domains of more than 120 widely impersonated brands, including shipping companies, and flags it if the address is a letter-swap or near-miss of a real carrier. It shows whether Google Safe Browsing (Google's list of reported dangerous sites) has already flagged the address, how many security vendors flag it on VirusTotal, and any community abuse reports. It also surfaces the domain's creation date: brand-new phishing sites are often registered days before the texts go out, so a domain that's only a few days old is a supporting clue.
What can't it do?
Honesty matters more than comfort here, so a few limits worth knowing:
- It reads the address, not the page. IP Tracker checks the domain you paste. It doesn't open the link, click the "pay" button, or complete anything for you.
- The brand list is about 120 brands. The most impersonated ones, not every possible sender. A scam wearing a smaller carrier's name may not trip the lookalike check.
- Blocklists lag. Google Safe Browsing is strong on known bad sites, but a domain registered this morning may not be reported yet. That's why the creation-date clue exists.
- It can't read the text's tone for you. The urgency, the tiny fee, the "before delivery" pressure: those are signals you still have to weigh yourself.
If you already got one
Reporting takes under a minute and helps the carriers and investigators track the campaigns.
- Forward the text to 7726 (it spells SPAM on the keypad). This reports it to your mobile carrier, and both the Postal Inspection Service and the FTC point here.
- Report phishing emails to
[email protected]if the scam arrived by email claiming to be USPS. - Then delete it. Don't reply, don't tap "STOP," don't tap the link. Any interaction confirms your number is live.
If you already tapped and entered a card number, treat it like a lost card: contact your bank, watch the statement, and change any password you may have typed into the page.
To summarize:
- ✓ A real USPS package text never contains a link, and USPS charges no redelivery fee.
- ✓ Preview the link's domain without tapping it; read the domain, not the words.
- ✓ Reach the carrier yourself by typing the address or using the tracking number in a trusted app.
- ✓ Paste the domain into IP Tracker for a fast second opinion, and report the text to 7726.
When a small fee and a big rush arrive in the same message, that's the moment to slow down. The package can wait; so can you. 😉