MalwareZero

The delivery driver text asking you to confirm your address is a scam

Updated August 6, 2026

Amazon drivers really do message customers, and that's the thing this scam is standing behind. The difference is where the message lands: a real driver's note appears inside the Amazon app, from a masked number, and it stays there. The text sitting in your SMS inbox saying the driver couldn't complete your address and needs you to confirm it at a link is not that. It's phishing. When an address is genuinely bad, the parcel goes back to the depot and the shipper gets billed for the correction, and nobody sends you a link about it.

USPSText message
SCAM, NOT REALThe USPS package has arrived at the warehouse and cannot be delivered due to incomplete address information. Please confirm your address in the link within 12 hours.
Recreated example of the wording used in this scam. Not a real captured message; built to match the pattern described on this page.

This version spreads well because it doesn't ask for money. It asks for something you'd tell a stranger on the phone without blinking. Your own address. That feels harmless right up until the third screen.

The wording you're probably staring at

Documented versions read close to this: "The USPS package has arrived at the warehouse and cannot be delivered due to incomplete address information. Please confirm your address in the link within 12 hours." A UPS-branded variant runs "Our driver can't find your address, and your package is still pending," then points at a link to provide your complete address and schedule redelivery.

Same bones every time. A stalled parcel, a problem that sounds fixable in ten seconds, a short deadline, one link. That 12-hour window exists so you deal with it on your phone right now instead of checking properly in the morning.

Watch for the reply prompt as well. Because iMessage disables links from senders who aren't in your contacts, many of these now include "Please reply Y, then exit the text message, reopen the text message activation link." Replying turns the link back on. That's the entire trick, and it works because replying feels like less of a commitment than clicking.

What real couriers do with a bad address

USPS leaves paper. PS Form 3849, the peach slip headed "We ReDeliver for You!" (yellow on Sundays), goes in your box, and redelivery is free through usps.com. If the address really is undeliverable, the item goes back to the sender with a reason printed on it. Nothing about that process involves texting you a form.

UPS and FedEx settle it on the invoice, and not with you. Address correction is a standard billed charge that lands on the shipper: FedEx published a rate around $25.50 per package for 2026, and UPS charges up to roughly $25. Sit with that for a second. The company supposedly begging you to fix an address already runs a paid, industrialized process for fixing addresses, and it bills the sender per package. It isn't going to chase you for $1.99 by SMS instead.

Amazon deserves its own note, because the "driver" framing borrows from something real. Amazon drivers can message customers, but that conversation lives inside the Amazon app, with the driver's number masked. If a driver actually needs something, open the app and the message is sitting there waiting. Not in the app? Not from a driver.

The rule that holds across all of them: a genuine delivery exception appears in the tracking record on the carrier's own site. Not only in your messages.

How it knows your name and your order

Usually it doesn't. Numbers get worked through in blocks, and if you buy anything online, a vague "your package" text will eventually land in a week when you really do have a parcel moving. Coincidence does most of the heavy lifting, and I think people overrate how targeted these are.

Sometimes it is real data, though. UPS disclosed in 2023 that a package lookup tool in Canada allowed someone to pull recipient details including phone numbers, and Krebs on Security reported that the resulting scam texts named recipients, referenced their actual recent orders, and in some cases arrived almost immediately after an order was placed at a major retailer. Retailer breaches feed the same pipeline. So a text knowing your last name isn't proof of anything in either direction.

Your address circulating is not, by itself, an emergency. It's the same worry people have when a package they never ordered turns up on the step, which has a duller explanation than most people expect and is covered in why unordered packages arrive.

What the form is actually collecting

These pages run in stages, and each stage is a separate saleable product.

That last one gets underrated. A courier account controls where your parcels physically go. An Amazon account holds stored cards, saved addresses and gift card balances, and the first move after a takeover is usually changing the contact email so recovery notices never reach you. FBI figures put reported account takeover losses in the hundreds of millions of dollars for 2025, though I couldn't verify a clean breakdown of how much of that starts with a delivery text specifically.

These kits are industrial, not homemade. The large majority of smishing links seen over the past two years trace back to a handful of phishing-as-a-service platforms sold out of China, with names like Darcula and Lucid, between them impersonating hundreds of brands. Many of their pages refuse to render on a desktop browser at all, which is why the link you forwarded to your laptop to inspect showed you a blank page.

The check that takes half a minute

Don't tap the link. Open the carrier's own app, or type usps.com, ups.com, fedex.com or amazon.com yourself, and look at the order or tracking record. Anything real is there. If what you're holding is a printed QR code on a card or a door tag rather than a text link, you can read where a QR code points without scanning it and decide from that.

Don't reply either, not "Y" and not "STOP". Forward the message to 7726, report it at ReportFraud.ftc.gov, and if it wore USPS branding, email it to spam@uspis.gov along with a screenshot showing the sender's number and the date sent. FedEx asks for phishing samples at abuse@fedex.com. UPS runs a fraud reporting page on ups.com, and I couldn't confirm a single current reporting mailbox for them, so use the page rather than guessing at an address.

If you already filled it in

Call your bank on the number printed on your card and ask two questions: cancel and reissue this card, and has it been added to any mobile wallet recently. That second question is the one most people don't think to ask, and it's the one that matters.

Entered a password? Change it on the courier account and everywhere else that password lives, then switch on two-factor authentication for the courier and retail accounts. While you're in the Amazon or UPS account, check the contact email and the saved delivery addresses, because those get quietly edited.

Then brace for a phone call. The follow-up is routine now: someone presenting as fraud prevention, quoting details only your real bank should know, because they took those details from you an hour earlier. Voice cloning lets that caller sound like whoever it needs to sound like, which is the part covered in how AI voice cloning scams work.

If the message you got asked for a small fee rather than an address, the mechanics differ a little, and that version is broken down separately in the USPS redelivery fee text. If you want my opinion, the address version is the nastier of the two. Nothing about it looks like a transaction, so people hand over the first screen with their guard fully down, and by the time a card field appears they're already three steps in and committed.