FRAUDJune 3, 2026 · 10 min read·0

Fake Courier & Delivery Scam Sites: The 2026 Playbook (India Post, DHL, FedEx Lookalikes)

Inside the ₹25 redelivery scam: how fraudsters impersonate India Post, DHL, FedEx, and Blue Dart, the SMS hooks they use, the tracking pages they clone, and how to verify a courier URL in under a minute.

S
DomainScan
𝕏 Share
Fraud

If you live in India and own a phone, you’ve received one. It usually arrives between 10am and 2pm. “Your India Post package could not be delivered due to incomplete address. Please update details and pay ₹25 redelivery fee: indi4post.com/tr/XXXX.”

The link looks plausible. The fee is small enough to feel routine. You’re probably actually expecting a package. Three out of three boxes ticked. This is one of the most successful smishing (SMS phishing) campaigns currently running anywhere in the world, and it’s tuned specifically for the Indian market.

Here’s the full playbook — how it works, why it works, and how to stop it from working on you or anyone you know.

How the scam works, end to end

The campaign has four moving parts. Each part is independently cheap, and the operation as a whole runs at industrial scale.

  1. SMS gateway. Bulk SMS providers, often based outside India, blast millions of messages per day. The targeting is loose — phone number ranges, leaked from data breaches.
  2. Lookalike domain. Registered through a discount registrar, valid for one year, hosted on shared infrastructure. Throwaway. The domain dies as soon as it gets reported.
  3. Cloned tracking page. A pixel-perfect copy of India Post (or DHL, or FedEx). The HTML is often just a save-page-as of the real site, with the payment form swapped.
  4. Payment endpoint. A fake gateway page that collects card details, OTP, and CVV. The card is then used immediately — usually within an hour — for a large unrelated transaction.
What the ₹25 is really for
The ₹25 isn’t the scam. The ₹25 is the excuse to get you to enter a card number on a page they control. The actual loss happens after.

The SMS hook

Scammers test SMS copy the way real marketers do. The current top-performing variants in India look like this (modified to not work as a copy-paste template):

  • “[India Post] Your package XXX-XXX-XXX is held due to incomplete address. Update here: [URL]. Redelivery fee ₹25.”
  • “DHL: Your parcel could not be delivered today. Reschedule: [URL]. Fee: ₹40.”
  • “Blue Dart - Package #BD12345 awaits confirmation. Update KYC: [URL]”

What every variant has in common:

  1. A brand you recognize in square brackets at the start — your eye treats it as the sender.
  2. A reason that fits your life — incomplete address, KYC update, redelivery. All plausible for any user.
  3. A small fee — ₹25, ₹40, ₹49. Small enough not to feel risky, large enough to require a card.
  4. A short URL on a domain that almost — but doesn’t quite — match the courier.

The fake tracking page

Click the link and the page that loads is convincing. It has the courier’s logo, color scheme, a fake tracking number, an animated “Your package is here” status, and a polite request to confirm your delivery address and pay the small fee.

Three details, if you look, give it away every time:

  • The URL. The actual courier’s domain is well-known — indiapost.gov.in, dhl.com, fedex.com, bluedart.com. The scam URL is a lookalike: indi4post.com, dhl-india.shop, fedex-redelivery.online.
  • The certificate. Real couriers have OV or EV certificates issued years ago. The scam page has a Let’s Encrypt cert issued in the last few days. One SSL inspection ends the deception.
  • The infrastructure neighborhood. A reverse-IP lookup shows the page sharing an IP with dozens of other lookalike domains targeting other brands — the same scammer running ten campaigns in parallel.

The ₹25 trap

The payment form looks like a stripped-down version of Razorpay or PayU. It accepts card number, expiry, CVV, and an OTP. The pretense is the small redelivery fee.

What actually happens behind the scenes:

  1. You enter card details. The page captures them in plain text on the scammer’s server.
  2. The page initiates a real transaction — but not for ₹25. Often for ₹50,000–₹2,00,000, to a merchant the scammer controls or has compromised.
  3. Your bank sends an OTP for the real transaction amount. The scam page shows a fake OTP entry field labeled “Confirm ₹25 redelivery.”
  4. You enter the OTP. The card is charged the real amount. By the time you see your bank’s SMS, the money is gone.
OTP rule
Banks never reuse an OTP across amounts. If your bank’s OTP message says ₹50,000 but the page says ₹25 — the page is lying. Close it. Don’t enter the OTP. Don’t enter anything else on that page.

India Post: the most-cloned brand

India Post sees more impersonation traffic than any other Indian courier, for a few reasons:

  • Vast user base. Almost every Indian household has received a parcel from India Post at some point. The brand has near-universal name recognition.
  • Less digital savvy on average. India Post’s user base skews older and more rural than private couriers. Scammers correctly assume lower URL literacy.
  • Plausible reason for fees. India Post genuinely does charge for some services, including redelivery in some cases — so a fee request doesn’t immediately feel wrong.

The real India Post domain is indiapost.gov.in. Note the .gov.in — Indian government domains are restricted to verified government entities. No scammer can register one. If the URL in your SMS doesn’t end in .gov.in, it isn’t India Post.

DHL, FedEx, Blue Dart variants

The same playbook runs against private couriers, with small adjustments:

  • DHL. Real domain: dhl.com or country-specific subdomains like mydhl.express.dhl. Scam variants: dhl-india.shop, dhI-tracking.top (capital I), dhl-redelivery.online.
  • FedEx. Real domain: fedex.com. Scam variants: fedex-redelivery.shop, fed-ex.online, fedex-india.top.
  • Blue Dart. Real domain: bluedart.com. Scam variants: bluedart-track.shop, bluedart-india.online, blue-dart.top.
  • Delhivery. Real domain: delhivery.com. Scam variants: delhivery-track.online, delhivery-fee.shop.

How to verify a courier URL in 60 seconds

Whenever a courier SMS arrives, before clicking anything:

  1. Open the courier’s app or official site directly. Don’t click the SMS link. Type the URL yourself or use the app. Real packages will show up in the real tracker.
  2. If you want to check the link anyway, run a domain lookup. A real courier’s domain is years old. The scam URL was registered in the last few weeks. WHOIS exposes this in seconds.
  3. Check the SSL certificate. A real courier has an OV/EV certificate from a paid CA. The scam page has a free Let’s Encrypt cert issued days ago.
  4. Reverse-lookup the IP. If the page shares an IP with dozens of unrelated brand-clone domains, the scammer has been running the same play across multiple targets.
Check a courier URL right now
WHOIS, SSL, blacklist, and reverse IP — one Trust Score, one verdict.
Try it
One-line rule
If the SMS says India Post and the URL doesn’t end in .gov.in, it’s a scam. If the SMS says DHL/FedEx/Blue Dart and the URL has a dash, an extra word, or a strange TLD — it’s a scam.

FAQ

Does India Post charge a redelivery fee?

In most cases, no — and never via an SMS link to a website. If a redelivery has to happen, India Post arranges it through the local post office, not through a payment portal. Treat any SMS asking for a fee as a scam.

I clicked the link but didn’t pay. Am I safe?

Mostly yes. Modern mobile browsers sandbox sites well, so a click alone usually doesn’t compromise your phone. The risk is if you entered any information — phone number, address, card details, OTP. If you did, change relevant passwords and monitor your card statement.

I entered my card details. What do I do?

Immediately: call your bank’s fraud line and block the card. Then file a complaint on cybercrime.gov.in with the SMS, the URL, and the time. Speed matters — recovery is possible within the first 24 hours and becomes much harder after.

How do scammers get my phone number?

Almost always from data breaches. Indian phone numbers leak constantly — from e-commerce databases, food delivery apps, telecom subscriber lists. Scammers buy these in bulk. The fact that they have your number means nothing about whether they know anything else about you.

#fake courier site#delivery scam#india post scam#dhl scam#fedex scam#package redelivery#sms phishing#smishing
S
Tracks scam infrastructure across registrars and writes about what the data shows.
RELATED POSTS
NEW POSTS, NO SPAM

One short email when we publish.

~2 posts a month, no marketing, unsubscribe in one click.