The delivery driver text asking you to confirm your address is a scam
Updated August 6, 2026
Amazon drivers really do message customers, and that's the thing this scam is standing behind. The difference is where the message lands: a real driver's note appears inside the Amazon app, from a masked number, and it stays there. The text sitting in your SMS inbox saying the driver couldn't complete your address and needs you to confirm it at a link is not that. It's phishing. When an address is genuinely bad, the parcel goes back to the depot and the shipper gets billed for the correction, and nobody sends you a link about it.
- 1USPS never texts a link, a bad address gets a paper PS Form 3849 slip instead
- 2The 12-hour deadline is pressure to act now instead of checking calmly
- 3Real USPS redelivery is free at usps.com, no link, no fee, no rush
- 4A genuine delivery issue shows up in the carrier tracking record, not a text
This version spreads well because it doesn't ask for money. It asks for something you'd tell a stranger on the phone without blinking. Your own address. That feels harmless right up until the third screen.
The wording you're probably staring at
Documented versions read close to this: "The USPS package has arrived at the warehouse and cannot be delivered due to incomplete address information. Please confirm your address in the link within 12 hours." A UPS-branded variant runs "Our driver can't find your address, and your package is still pending," then points at a link to provide your complete address and schedule redelivery.
Same bones every time. A stalled parcel, a problem that sounds fixable in ten seconds, a short deadline, one link. That 12-hour window exists so you deal with it on your phone right now instead of checking properly in the morning.
Watch for the reply prompt as well. Because iMessage disables links from senders who aren't in your contacts, many of these now include "Please reply Y, then exit the text message, reopen the text message activation link." Replying turns the link back on. That's the entire trick, and it works because replying feels like less of a commitment than clicking.
What real couriers do with a bad address
USPS leaves paper. PS Form 3849, the peach slip headed "We ReDeliver for You!" (yellow on Sundays), goes in your box, and redelivery is free through usps.com. If the address really is undeliverable, the item goes back to the sender with a reason printed on it. Nothing about that process involves texting you a form.
UPS and FedEx settle it on the invoice, and not with you. Address correction is a standard billed charge that lands on the shipper: FedEx published a rate around $25.50 per package for 2026, and UPS charges up to roughly $25. Sit with that for a second. The company supposedly begging you to fix an address already runs a paid, industrialized process for fixing addresses, and it bills the sender per package. It isn't going to chase you for $1.99 by SMS instead.
Amazon deserves its own note, because the "driver" framing borrows from something real. Amazon drivers can message customers, but that conversation lives inside the Amazon app, with the driver's number masked. If a driver actually needs something, open the app and the message is sitting there waiting. Not in the app? Not from a driver.
The rule that holds across all of them: a genuine delivery exception appears in the tracking record on the carrier's own site. Not only in your messages.
How it knows your name and your order
Usually it doesn't. Numbers get worked through in blocks, and if you buy anything online, a vague "your package" text will eventually land in a week when you really do have a parcel moving. Coincidence does most of the heavy lifting, and I think people overrate how targeted these are.
Sometimes it is real data, though. UPS disclosed in 2023 that a package lookup tool in Canada allowed someone to pull recipient details including phone numbers, and Krebs on Security reported that the resulting scam texts named recipients, referenced their actual recent orders, and in some cases arrived almost immediately after an order was placed at a major retailer. Retailer breaches feed the same pipeline. So a text knowing your last name isn't proof of anything in either direction.
Your address circulating is not, by itself, an emergency. It's the same worry people have when a package they never ordered turns up on the step, which has a duller explanation than most people expect and is covered in why unordered packages arrive.
What the form is actually collecting
These pages run in stages, and each stage is a separate saleable product.
- Name, address, phone number. Cheap on its own. Submitting it flags your number as one that responds to bait, which is why the texts multiply after you engage.
- Card details. A small "address correction" or "redelivery" fee is the pretext for collecting the number, expiry, CVV and billing zip.
- The one-time code. This is the screen that hurts. The page claims your bank is confirming the small charge. In the pattern Krebs on Security documented in February 2025, that code is really authorizing your card being loaded into Apple Pay or Google Wallet on a handset the fraudsters are holding.
- Or a login instead. Some versions skip payment entirely and present a UPS My Choice, FedEx Delivery Manager or Amazon sign-in page.
That last one gets underrated. A courier account controls where your parcels physically go. An Amazon account holds stored cards, saved addresses and gift card balances, and the first move after a takeover is usually changing the contact email so recovery notices never reach you. FBI figures put reported account takeover losses in the hundreds of millions of dollars for 2025, though I couldn't verify a clean breakdown of how much of that starts with a delivery text specifically.
These kits are industrial, not homemade. The large majority of smishing links seen over the past two years trace back to a handful of phishing-as-a-service platforms sold out of China, with names like Darcula and Lucid, between them impersonating hundreds of brands. Many of their pages refuse to render on a desktop browser at all, which is why the link you forwarded to your laptop to inspect showed you a blank page.
The check that takes half a minute
Don't tap the link. Open the carrier's own app, or type usps.com, ups.com, fedex.com or amazon.com yourself, and look at the order or tracking record. Anything real is there. If what you're holding is a printed QR code on a card or a door tag rather than a text link, you can read where a QR code points without scanning it and decide from that.
Don't reply either, not "Y" and not "STOP". Forward the message to 7726, report it at ReportFraud.ftc.gov, and if it wore USPS branding, email it to spam@uspis.gov along with a screenshot showing the sender's number and the date sent. FedEx asks for phishing samples at abuse@fedex.com. UPS runs a fraud reporting page on ups.com, and I couldn't confirm a single current reporting mailbox for them, so use the page rather than guessing at an address.
If you already filled it in
Call your bank on the number printed on your card and ask two questions: cancel and reissue this card, and has it been added to any mobile wallet recently. That second question is the one most people don't think to ask, and it's the one that matters.
Entered a password? Change it on the courier account and everywhere else that password lives, then switch on two-factor authentication for the courier and retail accounts. While you're in the Amazon or UPS account, check the contact email and the saved delivery addresses, because those get quietly edited.
Then brace for a phone call. The follow-up is routine now: someone presenting as fraud prevention, quoting details only your real bank should know, because they took those details from you an hour earlier. Voice cloning lets that caller sound like whoever it needs to sound like, which is the part covered in how AI voice cloning scams work.
If the message you got asked for a small fee rather than an address, the mechanics differ a little, and that version is broken down separately in the USPS redelivery fee text. If you want my opinion, the address version is the nastier of the two. Nothing about it looks like a transaction, so people hand over the first screen with their guard fully down, and by the time a card field appears they're already three steps in and committed.