Fake delivery notices and package QR codes
Updated October 11, 2026
Parcel scams moved from text messages into the letterbox. A card that looks like a real "we missed you" notice asks you to scan a QR code to rebook delivery, and the page charges a small fee to steal your card details. A related scam sends a package you never ordered, with a QR code inside and no sender.
Fake collection notices
In June 2026 the Swiss National Cyber Security Centre described fake Swiss Post collection notes ("Avis de passage") left in letterboxes. They copy the colours and logo of the real yellow note and give plausible details of a failed delivery. The QR code opens a site that is almost identical to Swiss Post’s and asks for more information before the parcel can be delivered. The same playbook targets USPS, Royal Mail, DHL, La Poste and other carriers.
Packages you never ordered
In July 2025 the FBI warned about unsolicited packages with no sender information and a QR code inside. Scanning it leads to pages that ask for personal and financial details, or to apps that steal data from the phone. The FTC issued a similar alert in January 2025.
Red flags
- A small "redelivery" or "customs" fee. Carriers rarely charge to rebook a delivery, and never through a sticker or a card in your letterbox.
- The site is not the carrier’s own domain: usps.com, royalmail.com, dhl.com, laposte.fr, post.ch, postnl.nl and so on. Names like usps-redelivery-track.com or royalmail.parcel-reschedule.help are not the carrier.
- No tracking number you recognise, or a tracking number that does not work on the carrier’s real site.
- The page asks for card details, an ID photo or a code sent to your phone.
- A package with no sender and a QR code “to find out who sent it” or “to claim a gift”.
Check a delivery safely
- Type the carrier’s address yourself, or open its official app, and enter the tracking number from the notice.
- If the number does not exist there, the notice is fake.
- Scan suspicious codes with QR Snap: it shows which site the code really opens and whether that site is new or a known scam.
What QR Snap checks before you open a link
QR Snap shows you the link first and does not open it until you tap. Before you do, it runs these checks:
- Where it really goes. Short links and redirects are followed to the page they end on, and QR Snap shows that site ("Opens example.com, after 2 redirects").
- Known threats. The link and its destination are checked against Google Web Risk and a public list of active phishing sites.
- Look-alike names. A company name on a site it does not own, misspellings like paypa1 or rnicrosoft, letters from other alphabets, and an "@" that hides the real address.
- Free website builders and file hosts. A payment or sign-in page hosted on a free site builder, a dynamic-DNS name or a storage bucket is a common scam setup.
- Brand-new websites. Most scam sites are days or weeks old, so QR Snap shows when the site was registered.
What no checker can promise
New scam sites appear every day, and some hide behind bot checks so automated tools only see a harmless page. A clean result means none of the checks found a known threat, not that the page is guaranteed safe. If a page asks for card details or a password you did not expect to give, close it and go to the company yourself: type its address or open its official app.
Sources
More guides
- How to spot a QR code scamQR code scams (quishing) send you to fake payment and login pages. Where they show up, the warning signs in the link, and what to do if you already scanned one.
- Fake QR codes on parking metersFake QR stickers on parking meters and pay stations lead to copycat payment sites. How the scam works, how to spot it, and the safe way to pay.