Problem
“Your parcel is being held because the address is incomplete. Please confirm your address.” One link. You did order something, and the courier name looks familiar.
Delivery texts are the oldest and most common smishing lure. Everyone gets parcels, so everyone thinks “maybe it is mine”, and real notices also arrive with links, so appearance alone does not settle it.
Symptoms
- Words like “address unknown”, “held”, “delivery failed” or “request redelivery”.
- A short link (han.gl, bit.ly) or an unfamiliar address with the courier’s name mixed in.
- The page asks you to re-enter your address, pay a small redelivery fee or install a “tracking app”.
- No tracking number, or one that the courier’s website cannot find.
Three checks against a real notice
1. The link’s final address. Real notices go to the courier’s official domain (in Korea, for example, CJ Logistics cjlogistics.com or Korea Post epost.go.kr) or to the shop you ordered from. Addresses that borrow a name — cj-deliver.xyz, epost-kr.top — or were registered days ago are fake. A short link hides the final address, so it has to be expanded.
2. The tracking number. A real one shows up when you type it into the courier’s official app or website yourself — not through the link.
3. What it asks for. Confirming an address can happen in a genuine notice. Card payment (especially a tiny redelivery fee) or installing an app (APK) means scam. On Android, if you see “allow installs from unknown sources”, stop.
Diagnose with DechoNet
- Paste the whole message into the phishing link check. It follows short links to the final address and shows, with reasons, how old that domain is, whether it imitates a courier and whether it pushes an APK download.
- Lookalike domain detection finds registered domains spelled like the courier’s official one.
- Domain registration lookup shows the link domain’s registration date and registrar.
Resolution Checklist
- If you did not order anything, do not tap.
- If you did, look up the tracking number in the courier’s or shop’s official app instead of using the link.
- Check with the link checker whether the final address is an official domain.
- Close the page if it asks for a redelivery fee or an app install.
- Screenshot the text, report it (Korea: 118) and delete it.
- On Android, keep “install unknown apps” switched off.
When to Escalate
- If you already paid or installed an app, follow what to do after clicking a smishing link.
- If you entered card details, ask your card company to suspend the card now.
Paste the message and check it now
Paste the whole message or just the link. The text is not stored; each link is followed to where it really goes.