Share
CONSUMER ALERT - SMS PHISHING

Got a missed-delivery text from Australia Post? If it carries a link, treat it as a scam

Straight answer first: a text saying Australia Post could not deliver your parcel, with a link to sort it out, is a scam in almost every case. Australia Post is stripping links out of its own tracking texts precisely because of this campaign, and its scam-alerts page flagged this exact "redelivery fee" text on 10 July 2026. Here is the 10-second check, and what to do if you already tapped.

SafeBrowz Threat Research Security ResearchJuly 27, 20268 min read

The 10-Second Check

Does the text contain a link at all? Australia Post is removing links from its tracking SMS notifications, so a link is itself the first red flag. Does the link's actual domain read exactly auspost.com.au? Anything else, including random strings that never mention the brand, is a fake. Did the message ask for a card number or a small fee? Australia Post says it will never send an SMS or email asking for credit card details or personal information. Fail any one of the three and you delete the text, then check the tracking number yourself in the AusPost app or by typing auspost.com.au into the browser.

Not sure about a link? SafeBrowz checks it before the page can load. Add to Chrome, free Get the free Android app or scan a URL now →

The wave running this weekend

On 26 July 2026, a fresh batch of these texts was reported publicly on X. The message follows the standard script: Australia Post attempted delivery, nobody was home, tap the link to rebook. The link in the reported campaign leads to postgitrabqs[.]com, a page dressed up as an Australia Post parcel form that walks you through "address confirmation" and ends at a credit card field. That domain is written here with brackets on purpose, so nobody can tap it by accident.

Two details about that domain are worth knowing, because they describe the whole class. First, the WHOIS record shows a creation date of 27 July 2026 (UTC), through a Hong Kong registrar. The domain was hours old when we checked it for this article, in the same weekend the texts were reported. These domains are burned and replaced in days, which is why blocklists alone always run behind. Second, the name contains no brand word at all. Older fakes looked like auspost-redelivery.top or auspost-track.live (both illustrative shapes we use for testing, not domains from this campaign; click either to see a live scan verdict). The current kits prefer random consonant soup precisely because keyword filters look for "auspost". The branding lives on the page, not in the address, and the address is the one thing the page cannot fake.

This is not an isolated blast. Australia Post's own scam-alerts page published a "redelivery fee" SMS scam alert on 10 July 2026, describing texts that link to fake Australia Post websites built to take personal information and card details, alongside a companion "attempted delivery" alert on 1 July 2026 covering the email version of the same lure. Parcel smishing in Australia is a year-round wave with holiday-season spikes, the same playbook we have documented for USPS in the United States, Evri in the UK, and DHL worldwide. Only the logo changes.

What the real Australia Post does, in its own words

You do not need to take our word for any of this. Australia Post's official security page at auspost.com.au publishes a "we'll never" list, and it reads like a checklist against this exact scam. Australia Post says it will never ask for your password, never ask you to enter information on a web page that is not part of Australia Post, never send you an email or SMS asking for credit card details or personal information, and never call you out of the blue to request payment.

The same page describes the structural change that makes 2026 fakes easier to spot than ever: Australia Post is removing links from its tracking SMS notifications. Instead of a tappable URL, genuine messages now tell you to open the AusPost app or visit the website yourself and enter your tracking number. Their recommended setup is to install the official AusPost app, turn on push notifications, and optionally switch off SMS notifications entirely in MyPost, at which point any "Australia Post" text with a link identifies itself as fraud on arrival.

One more thing the real organisation does: it reads reports. Suspicious texts and emails go to [email protected]. It is a reporting-only mailbox, so you will not get a personal reply, but forwarded messages feed the takedown pipeline.

The 10-second check, step by step

  1. Look for a link. (3 seconds.) Real Australia Post tracking texts are going link-free. A tappable URL inside a delivery text is the scam's own signature, before you read a single word of it.
  2. Read the domain, right to left. (4 seconds.) The only address that counts is the registrable domain just before the first standalone slash: auspost.com.au and nothing else. auspost.com.au.parcel-fix[.]top (an illustrative shape) is not Australia Post, and neither is a string like postgitrabqs[.]com that skips the brand entirely.
  3. Check the sender and the ask. (3 seconds.) Since 1 July 2026, Australia's SMS Sender ID Register requires alphanumeric sender names like "AusPost" to be registered with the regulator, ACMA, and messages using an unregistered sender name must be labelled "Unverified". An "Unverified" tag on a delivery text settles the question. Scammers respond by sending from plain mobile numbers instead, so also weigh the ask: any request for a card number, a fee, or personal details by text fails Australia Post's published policy on its own.

Whatever the text says, the verification move is the same one: close it, open the AusPost app or type auspost.com.au into the browser yourself, and look up the tracking number from your order confirmation. If a real parcel genuinely missed you, it will be sitting right there in your account. The same manual-lookup habit defuses the myGov "account locked" wave and the ATO tax-refund texts that hit the same Australian phones, often from the same kits.

Check the link before your thumb does

The 10-second check works when you are awake to run it. The texts are engineered for the moment you are not, waiting on a real parcel at 7am. SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus a free Android app, and it checks every link you open against a live detection stack before the page can load, so a fake parcel form gets a full-screen warning instead of your card number. Free forever; Premium at $14.99 a year lifts the AI deep-scan limit.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

Why your number keeps getting these texts

Because the economics are absurdly good. The texts are blasted to number lists in the millions; the senders need only the tiny fraction of recipients who happen to be expecting a parcel that morning. In a country where most households order online, that fraction is never zero. The card details harvested on the fake form are not used to steal your $2.99 "redelivery fee" - they are tested with small charges and then run for whatever the card will bear, or sold on in bulk. The mechanics are the same as every smishing operation we have taken apart.

The scale shows up in the national numbers. The ACCC's National Anti-Scam Centre reported in March 2026 that Australians filed 481,523 scam reports in 2025 with $2.18 billion in reported losses, and phishing was the single most-reported scam type to Scamwatch at 65,361 reports. One genuinely encouraging line in the same data: reports of scam contact by text message fell from 77,365 in 2024 to 29,058 in 2025, as sender-ID rules and carrier filtering started to bite. The wave is being squeezed. It is not gone, and the postgitrabqs campaign shows what the remainder looks like: fresher domains, faster rotation, no brand keywords.

If you already tapped, or already paid

  1. Tapped the link but typed nothing? You are almost certainly fine. These pages harvest what is typed into them. Close the tab and run the reporting steps below.
  2. Entered card details? Call your bank now or freeze the card in the banking app. Ask for a replacement number. Watch the statement for small test charges over the next 48 hours - under $5 is the classic probe - and dispute anything you did not make as fraud.
  3. Entered your address, date of birth or licence details? Treat it as identity exposure, not just card fraud. IDCARE, Australia's national identity and cyber support service, exists for exactly this situation and is free to use.
  4. Report it twice. Forward the text to [email protected], then file a report at scamwatch.gov.au/report-a-scam. Scamwatch reports are what the National Anti-Scam Centre uses to trigger takedowns and warnings.
  5. Then delete the text. If money already left your account, our step-by-step recovery guide covers the chargeback and escalation path in order.

Check the parcel link before you tap it

SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. Here is what each layer does with a fake Australia Post text, specifically.

  • Layer 1 - Local detection: URL-shape checks run inside the extension before anything renders: pages served without HTTPS, raw-IP hosts, and homograph tricks such as Cyrillic characters standing in for Latin ones in a lookalike address.
  • Layer 2 - API checks: the domain is checked server-side against our 550+ brand database and community blocklists, plus Google Safe Browsing, PhishTank, URLhaus, ScamAdviser feeds and a 30+ scam-TLD watchlist. Australia Post is a tracked brand in that database: we scanned the illustrative lookalikes above while writing this piece and each came back danger for brand impersonation, while the genuine auspost.com.au comes back safe. The reported campaign domain postgitrabqs[.]com is on our blocklist and returns a danger verdict as of publication.
  • Layer 3 - AI deep scan (Premium): AI content analysis via our proxy reads the rendered page the way you would if you were suspicious: parcel-tracking layout, Australia Post branding, an address form feeding a card form, on a domain registered this week. That combination earns a danger verdict even on a random-string domain no keyword rule and no blocklist has ever seen, which is exactly the gap the postgitrabqs pattern is built to slip through.

The honest limit: SafeBrowz does not read or filter your SMS inbox, so the text itself will still arrive, and it cannot claw back money already sent. What it does is stand between the tap and the card form, in the browser where the harvest actually happens, on desktop and on Android.

Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

🛡 LIVE CHECK

Check a delivery link without opening it

Copy the link out of the text (press and hold, copy, do not tap) and paste it here, or click a red-dotted example above. Our 3-layer engine (Local + APIs + AI) returns a verdict in about three seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Does Australia Post send text messages at all?

Yes, if you have opted in to tracking notifications, Australia Post does send genuine delivery texts. The difference is what they contain. Australia Post is removing links from its tracking SMS notifications, so genuine messages direct you to check the AusPost app or website yourself with your tracking number. Its published policy says it will never send an SMS or email asking for credit card details or personal information, never ask for your password, and never ask you to enter information on a web page that is not part of Australia Post.

How can I tell if an Australia Post text is real in seconds?

Three checks. A link inside the text is the first red flag, because genuine AusPost tracking texts are going link-free. If a link is present, the registrable domain must read exactly auspost.com.au, not a lookalike and not a random string. And any request for payment, card details or personal information fails Australia Post's own published policy outright. When in doubt, close the text, open the AusPost app or type auspost.com.au manually, and look the tracking number up there.

Why did the scam text appear in the same thread as real AusPost messages?

Because the sender name on an SMS could historically be set to any alphanumeric string, phones grouped fake "AusPost" texts into the same conversation thread as genuine ones. That is changing: since 1 July 2026, Australia's SMS Sender ID Register requires alphanumeric sender names to be registered with ACMA, and messages using unregistered sender names must be labelled "Unverified". An "Unverified" tag on a delivery text is a scam signal on its own. Texts from plain mobile numbers are still possible, so the link and payment checks still apply.

Does Australia Post ever charge a redelivery fee by text?

No. Australia Post's own scam-alerts page published a warning on 10 July 2026 about exactly this message, a text asking a small fee to rearrange a failed delivery, which leads to a fake site that takes card details. Its published policy is that it never sends an SMS or email asking for credit card details or personal information. If you want to rearrange a real delivery, do it inside the AusPost app or on auspost.com.au after typing the address yourself.

I entered my card details on the fake page. What should I do first?

Freeze the card in your banking app or call the bank immediately, and ask for a replacement card number. Watch for small test charges, typically under $5, in the next 48 hours and dispute anything unfamiliar as fraud. If you also gave your address, date of birth or licence details, contact IDCARE, Australia's free national identity support service. Then forward the text to [email protected] and report it at scamwatch.gov.au/report-a-scam so the National Anti-Scam Centre can act on the domain.

Last updated 2026-07-27

Related SafeBrowz coverage