The sender label is not identity proof
A text appearing under a bank or delivery-company name can still be fraudulent. Messages can be crafted to resemble an existing conversation. Scammers may know your name or quote a realistic small delivery fee to make the request feel routine.
Check without opening the supplied link
- Stop before replying, calling the included number or tapping the link.
- Open the genuine bank or delivery app yourself. Check for the alert or parcel there.
- If you need support, use contact details from the app, your card or an independently verified official website.
- Ask whether the requested action fits the genuine service. A message directing you to move money to a safe account deserves immediate independent verification.
Never read out a one-time code, PIN or password to an unexpected caller. A second phone call repeating the text's story does not provide independent verification if it could come from the same scammer.
Practise with a harmless scenario
Suppose a message says a parcel cannot be delivered until you pay $2.95. Do not decide on the small amount alone. Check whether you expect a parcel and whether its tracking status in the official app matches. A phishing page may ask for much more than the stated fee, including card and identity information.
If you interacted
If you only viewed a page, close it and check for downloads or permissions. If you entered credentials or a code, recover the account through the genuine service and review access. If you supplied card details or transferred money, contact the bank promptly. Tell it exactly what happened so it can choose the appropriate protective action.
Preserve and report
Keep a screenshot and the message details without forwarding a clickable scam to others. Report through Scamwatch and your provider's available spam-reporting route. Reporting helps but is not a replacement for urgent steps to stop financial loss.
Common mistakes
HTTPS and a padlock only describe an encrypted connection. A familiar sender name is not authentication. Good spelling is not a safety signal, and receiving the message while waiting for a parcel can be coincidence.
Free protection you can use today
Use the official apps already available, restrict unnecessary account access and turn on supported MFA. These habits do not require a paid SMS-filter subscription. The strongest first action is an independent check before sharing information or approving a transaction.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.