BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 09 August 2026

"Your parcel could not be delivered": how to spot delivery fraud at the office

"Your parcel could not be delivered" — one of the most effective phishing tricks around right now. Why delivery fraud works so well and how to spot it in a matter of seconds.

You get an email: "Your parcel could not be delivered — click here to schedule a new delivery date." Or a WhatsApp message: "Hi, we tried to deliver your order but no one was home." Sound familiar? During the summer months we order more online — gifts, holiday shopping, supplies for the office — and scammers know it. Delivery fraud is one of the fastest-growing forms of phishing in the Netherlands. Time for a short, practical breakdown — especially for office managers who regularly receive parcels on behalf of the business.

Why delivery fraud works so well

With a standard phishing email, the recipient has to happen to have an account with the bank or service being impersonated. But almost everyone is expecting a parcel at some point. In an office setting, deliveries arrive every week: stationery, printer cartridges, a new keyboard, a birthday cake. So when an email lands from "PostNL", "DHL" or "DPD" with a minor snag — insufficient postage, wrong postcode, second delivery attempt — the temptation to click is real.

The trick: you don't have to transfer a large sum. The fake page typically asks for €1 or €2 in "additional charges". That feels harmless. But what you're actually handing over are your credit card details or authorisation for a recurring direct debit.

Five signs a delivery message isn't genuine

  1. You're being asked to pay. A courier asking for money via a link — for postage, import duties or a "redelivery fee" — is almost always fake. Genuine import duties are arranged in advance through the webshop or paid to the courier at the door.
  2. The sender address doesn't add up. Don't look at the display name — look at the actual email address behind it. "PostNL <info@postnl-track-nl.com>" is not PostNL. Real addresses end in the official domain (postnl.nl, dhl.com, dpd.nl).
  3. The link goes to a strange domain. Hover your mouse over the button (on your phone: hold your finger on it) and read where the link actually leads. If you spot something like ".ru", ".top", or a string of random characters, don't click it.
  4. You're not expecting a parcel at all. Obvious, but in the rush of the day people click anyway. Always take a second to ask yourself: did I actually order something?
  5. There's pressure to act fast. "Respond within 24 hours or your parcel will be returned." Real couriers give you at least a week, or simply leave the parcel at a pick-up point.

What you can agree on at the office

When several people handle incoming post and parcels, a few simple ground rules go a long way. Without them, someone will eventually click something they shouldn't.

  • Keep track of orders in one place. A shared overview — an Excel sheet, a Teams list, whatever works — showing who ordered what and when it's due to arrive. If someone gets a delivery email for an order that isn't on the list, something's off.
  • Never pay extra charges via a link in an email. If there genuinely is something outstanding with customs or a courier, go directly to the website (postnl.nl, dhl.com) and log in there with the tracking code. No shortcuts through email links.
  • Not sure? Ask. Spending one minute checking with a colleague costs far less than a day of hassle with your bank trying to reverse a payment.

What to do if someone does click

Mistakes happen. What matters is acting quickly:

  1. Clicked the link but didn't fill anything in? The risk of damage is low. Close the tab and report it internally so a colleague doesn't make the same mistake.
  2. Entered personal details (address, phone number)? Stay extra alert over the coming weeks for suspicious calls or messages. Scammers often follow up with another trick ("hello, this is the fraud department of your bank...").
  3. Entered bank or credit card details? Call your bank or credit card provider immediately. Block the card. Most banks have a 24/7 fraud reporting number on the back of your card.
  4. Did this happen on a work device? Report it to whoever normally handles IT. Changing passwords is usually wise — especially if you entered a password on the fake page.

Quickly checking a suspicious link

If you're unsure about a link in a delivery message: copy the domain (the part between https:// and the first /) and look up who's behind it. A genuine courier domain has been around for years and is registered in the company's name. A freshly registered domain in the name of a private individual abroad is a clear red flag.

We've previously written about how to check a suspicious link in an email in under a minute — that same approach works just as well for delivery messages.

In short

Delivery fraud thrives on urgency and familiarity. Take a moment to check the sender, the link, and whether you're actually expecting a parcel. Keep a simple overview at the office of what's been ordered. And never click "pay the difference" via an email link — no matter how small the amount looks.

Want to take things a step further and control who can log in to your mail environment — and when — so that an accidental click has less impact? Take a look at our help with 2FA implementation or run an access check. Two small steps that can prevent a lot of summer headaches.

Onderwerpen

#mkb #security #phishing #E Mail #Fraude Herkennen

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →