I barely drive toll roads, and one of these still found me. The text sounds official and slightly panicked: you have an unpaid toll, a late fee is stacking up, and your vehicle registration will be suspended unless you pay in the next 12 hours. There's a tidy link to settle it. Almost every part of that message is designed to make you tap before you think. The one part that gives it away is the part you're least likely to look at: the web address.
Why this scam, why now?
This isn't a fringe scam. In its May 2026 consumer alert, the U.S. Federal Trade Commission reported that imposter scams were the number-one fraud category for the ninth year in a row, with reported losses in 2025 climbing nearly 20% to about $3.5 billion. Buried in that total is a sharp move: reports of government-imposter scams were up 40%, and the FTC points directly at overdue-toll messages that spoof real toll programs, naming EZ-Pass, SunPass, FasTrak, and TxTag, and threaten late fees or a suspended registration.
The mechanics are cheap and enormous in scale. An analysis by New Jersey's cybersecurity agency, the NJCCIC, identified more than 20,000 scam domains built for this one campaign type, and noted that fraud groups may register 60,000 or more domains in a single push to stay ahead of blocklists. The same report tallied roughly $470 million in U.S. losses from text-initiated scams in 2024, about five times the 2020 figure.
What are the scammers actually counting on?
They are counting on you looking at the message and never at the domain. A security write-up of the FBI's smishing warning ("Unpaid Toll Text? FBI Warns It's Likely a Smishing Scam") notes that scammers registered thousands of fake domains for this campaign and typically request small, plausible sums, often up to around $25, precisely because a small number doesn't trigger suspicion the way a big one would. You pay to make the annoyance go away, and in doing so you hand over your card details on a page you never inspected.
The scale is confirmed in the FBI's own numbers: the Bureau's IC3 2024 annual report counted 59,271 complaints tied to toll scams in 2024. (You'll see some coverage say "thousands"; that phrasing traces to the FBI's earlier April 2024 public alert, which cited 2,000-plus complaints from at least three states in the first weeks. The 59,271 figure is the full-year total.)
The tell is the domain after the slash
Here is the single most useful habit. In a toll text, ignore the friendly words and find the actual web address the link points to. Then ask one question: does the domain match the real toll agency? It almost never does.
Real toll agencies use plain, official domains. The scam versions dress up a lookalike so it reads right at a glance while pointing somewhere else entirely.
ezpassny.coman official E-ZPass agency siteezpass-toll-pay.info"ezpass" is only a prefix; the real domain is the toll-pay.info partThe NJCCIC found that fraudulent domains deliberately borrow official-sounding words (ezpass, fastrak, sunpass, paturnpike, driveezmd, txtag) and glue them onto a domain the agency never owned. It also found that 82% of these fraudulent domains were registered through a single Hong Kong registrar, Dominet (HK) Limited, which is a strong hint of an industrial-scale operation rather than a real government office. 🤓
ezpass.toll-pay.info, the domain is toll-pay.info; "ezpass" is just a label bolted on the front to reassure you. Read a web address from the right: the true owner is the last two parts before the first single slash.How do you check a toll text by hand?
- Don't tap the link. Long-press it (phone) or hover over it (computer) to reveal the actual destination address without opening it.
- Read the domain from right to left. Find the first single "/" after the address. The two words just before it are the real owner. If that isn't the toll agency's known site, stop.
- Compare against the agency's real domain. Look it up separately, from a search engine or a bill you already have, never from the text. E-ZPass, SunPass, FasTrak, and TxTag all have their own official sites.
- Watch for the giveaways. Odd endings like
.info,.top,.xin, or.vip; extra words like-toll-payor-violation; a brand name used as a prefix rather than the domain itself. - If in doubt, go direct. Type the toll agency's real address yourself, or call the number on a real statement. Don't use any contact detail from the text.
- Or paste the domain into IP Tracker and let the comparison run in seconds.
How does IP Tracker read a toll domain for you?
IP Tracker is a free Chrome extension. Paste a domain, a link, or a full email address into the popup; the free tier gives you 25 checks a day, with no account and no tracking. Only the value you paste is looked up.
For a toll text, it does the boring version of the manual check above, every time. It compares the domain against the official domains of roughly 100 widely impersonated brands and services, and normalizes look-alike characters so a swapped letter can't slip past. It also checks whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged the address, how many security vendors flag it on VirusTotal, community abuse reports, and the domain's creation date. Since these campaigns run on freshly registered throwaway domains, a "registered a few days ago" note is a useful supporting clue, never a verdict on its own.
If you paste the sender's full email or a link, it extracts the domain first, then runs the same checks. So the "ezpass" prefix trick gets stripped down to the real owner before anything is judged.
What can't it do?
Honesty matters more than comfort here, so a few limits worth knowing:
- Brand-new scam domains may not be listed yet. Fraud groups register tens of thousands of domains at a time (the NJCCIC saw campaigns of 60,000-plus) specifically to stay ahead of blocklists. Google Safe Browsing is strong on known bad sites, but the newest domain in a batch may not be flagged for hours or days.
- The brand list is about 100 brands. The most impersonated ones, not every regional toll authority on earth. A lookalike of a small local turnpike may not be on it, though the freshness and Safe Browsing signals still apply.
- It reads the domain, not the payment page. IP Tracker can tell you the address doesn't match your toll agency; it can't watch what a page does after you land on it. The point is to check before you tap, not after.
- It won't decide for you. Every result is a signal for your judgment. The tool surfaces what it can see and names it plainly.
The toll-text scam is built to beat your patience, not your knowledge. When a message arrives with a countdown attached, that's the moment to slow down and look at the domain, because the domain is the one thing the scammer couldn't fake into matching the real agency.
To summarize:
- ✓ Never tap the link; reveal the address and read it right to left.
- ✓ The real owner is the two words before the first single slash, not the "ezpass" prefix.
- ✓ Confirm the agency's real site separately, never from the text.
- ✓ Or paste the domain into IP Tracker and let it name the mismatch for you.
Stay sharp out there! 😎