Pause the request and verify through a separate route
A delivery message can arrive while you are genuinely expecting a parcel. An expected parcel does not authenticate the message. The National Cyber Security Centre (NCSC) recommends contacting an organisation through details on its official website when you are uncertain. Do not use the contact number or address supplied by the questionable message. Good spelling and familiar branding cannot settle the question.
Our practical check is to open Royal Mail’s website yourself and compare the parcel reference with the sender’s order record. Note what the message asks you to do: pay, change an address, collect an item or sign in. Separate that request from the independently checked carrier status. A social-media comment calling something a scam, or a reassuring reply, should not replace this verification.
Separate underpaid postage from a customs fee
Royal Mail’s scam guidance distinguishes two fee situations. It does not seek underpaid-postage payment by email or text and instead leaves a grey Fee to Pay card. Customs is an explicit exception: an SMS or email notification may accompany a grey card when the sender provided your contact details. An electronic fee notice therefore needs checking against its stated purpose; its delivery channel alone does not prove fraud or authenticity.
The official Pay a Fee page accepts details from a card, letter or SMS/email notification and lists UK credit or debit cards and PayPal as payment methods. Reach that service independently. As a practical reconciliation step, compare the notice’s reference and fee category with the item you expect before proceeding. If the details do not fit, use contact information reached through Royal Mail’s website to ask about the notice.
Check redelivery and unusual confirmation details independently
Royal Mail’s redelivery page describes free options, including delivery to your own address and eligible local alternatives. It also sets out service restrictions. A message demanding money merely to rebook a missed delivery deserves particular scrutiny against those official arrangements. Keep that demand distinct from a separately verified customs or postage fee. Use the official redelivery page to check the options offered for your item before making a request.
If a confirmation contains an unexpected date, address or instruction, our recommendation is to preserve the discrepancy and ask the relevant official support team to check it. State what you requested and what the confirmation shows. An inconsistency alone does not authenticate the sender. Avoid testing a questionable link to find out. NCSC also warns about phishing QR codes in emails; scanning one is another way of following a destination.
Report the message without opening its destination
Royal Mail asks customers to forward suspicious emails to reportascam@royalmail.com without opening links or attachments. For suspicious texts, it requests a screenshot sent to that address. GOV.UK also directs suspicious emails to the NCSC at report@phishing.gov.uk. You can report a message without proving it is fraudulent. Do not reply to the questionable sender to seek reassurance or provide further details.
For texts, most UK phone providers support free reporting by forwarding the message to 7726. If it does not work, NCSC says to contact your provider about reporting. If you have visited a suspicious website, use NCSC’s scam-website reporting guidance and stop entering information there. We recommend retaining the message privately and avoiding public posts of live links.
Choose the response that matches what you exposed
If you entered banking details, NCSC advises contacting your bank. Do that promptly through independently obtained contact details. If you disclosed a password, change it on every account that uses the same password. If an account appears compromised, follow the NCSC guidance for recovering a hacked account. These actions address different exposures; forwarding the delivery message to a reporting mailbox does not replace protecting the affected bank account or login.
NCSC says that opening a link on a computer, or following instructions to install software, calls for a full antivirus scan if you have antivirus software, allowing it to address detected problems. For a message received on a work laptop or phone, contact your IT department. Tell them what happened and what you entered or installed. Our practical advice is to avoid revisiting the page while deciding the next step.
Use the current crime-reporting route and a factual record
If you lost money, also tell your bank. If you lost money or were hacked following a phishing message, NCSC directs people in England, Wales and Northern Ireland to Report Fraud online or on 0300 123 2040. In Scotland, the route is Police Scotland on 101. Report Fraud is the current service replacing Action Fraud. Reporting suspicious content to NCSC and reporting a crime have separate purposes; its email reporting guidance explicitly says that mailbox is not a crime-reporting channel.
We recommend privately recording the arrival time, claimed parcel reference, anything opened, the type of information supplied and whom you contacted. Keep passwords and complete payment details out of a seller’s ordinary support ticket. Sellers can help reconcile the real order and dispatch reference without declaring a message authentic. Record the verified carrier information separately so the parcel enquiry can continue alongside the appropriate security response.
Official references
References reviewed on 2026-10-07. Check current product and help terms before booking or making a claim.
- Royal Mail: Scam advice
- Royal Mail: Pay a fee
- Royal Mail: Redelivery
- NCSC: How to spot a scam email, text message or call
- NCSC: Report a scam email
- NCSC: Report a scam text
- NCSC: Report a scam website
- NCSC: If you have shared sensitive information
- GOV.UK / Serious Fraud Office: Report Fraud replaces Action Fraud
- Report Fraud: Current reporting service
- GOV.UK: Report internet scams and phishing