
read receipts
The $1.99 Customs Fee Is the Cheapest Way to Steal Your Whole Card
Nobody files a police report over two bucks. That's the entire business model.
Two dollars. That's the price of your trust, and the scammers know it's a bargain.
Here's the text you've probably gotten: your package is stuck at customs, or a redelivery failed, and there's a tiny fee to release it — $1.99, £2.99, some pocket-lint number. Tap the link, pop in your card, and the parcel is back on its way. Except there is no parcel. There is no fee. There is only the form, and the form is the whole heist.
The genius of the small number is that it disarms the part of your brain that smells a con. Nobody imagines a criminal enterprise built around collecting $1.99. It feels too petty to bother faking. That instinct is exactly the vulnerability being exploited. The two dollars is theater. What the crooks actually want is what you type on the next screen: full card number, expiry, CVV, and increasingly a name, address, and a one-time passcode you'll helpfully forward when your bank texts to "verify."
The scale here is not small. The FTC's Consumer Sentinel data shows text-based fraud reports have exploded, with consumers reporting roughly $470 million lost to scam texts in a single year — and fake package and delivery notices are consistently among the most-reported openers. That's not $1.99 at a time. That's cards drained, resold on carding forums, and run through gift-card laundromats before you've finished your coffee.
The tell is in who's asking, and how
USPS put out a plain-spoken consumer alert about this exact playbook, and it says the quiet part loudly: the Postal Service does not send text messages asking for personal information or payment to redeliver a package. Royal Mail says the same. UPS, FedEx, DHL — same. None of them collect a delivery or customs fee through a link in a text.
That last point is the one to tattoo somewhere. Real customs charges, when they exist, are handled by the carrier at the door, through their official app you already installed, or on a payment page you reached by typing the address yourself. They are not collected by a stranger's SMS at 9 p.m. with a shortened link and a countdown vibe.
Look at the link and the clues pile up. The domain is never usps.com or royalmail.com. It's a look-alike stuffed with the brand name as a subdomain — something like usps-trackfee.help or a raw .top/.xyz address. Real carriers use their own domain. If the sender is a random Gmail address or a phone number from a country you've never ordered from, that's the sound of the mask slipping.
Why email teaches the same lesson
The smishing wave rhymes with the phishing email you already know. In email we get to check the plumbing — whether a message passed SPF, DKIM, and DMARC, the three checks that prove a sender is actually who they claim. A note that says it's from FedEx but fails DMARC is wearing a borrowed jacket. SMS strips all of that away. There's no header to inspect, no authentication to fail, just a sentence and a link. That's precisely why criminals love it — the medium hides the evidence.
So treat every unexpected delivery text as fiction until proven otherwise. Don't tap. Open the carrier's real app or type the address by hand. If you're genuinely expecting something, you'll find the truth there in ten seconds.
And if you already typed your card into one of these? Call your bank now, not tomorrow. The one thing that scam got right was your money — and the crooks are counting on you being too embarrassed over $1.99 to move fast.
Sources
- USPS — Consumer alert on package smishing texts
- FTC Consumer Protection — Scam text reports and fake delivery notices
- Royal Mail — Fee/redelivery text scam guidance