News

DPD Scam Email: How to Spot Fake Delivery Messages?

Eleanor Vance
Published By Eleanor Vance
Sarah Jenkins
Reviewed By Sarah Jenkins
PUB:
UPD:
dpd scam email

A DPD scam email is a fraudulent message designed to look like a genuine parcel notification. It may claim that a delivery failed, an address is incomplete, a parcel is being held or a small payment is required before delivery can continue.

The message is not necessarily connected to a real parcel.

Criminals frequently send delivery-themed emails in large numbers because many people regularly order products online and may click without checking whether the notification matches an expected purchase.

A fake DPD email may attempt to steal:

  • Debit or credit card information
  • Online banking details
  • Email passwords
  • Personal identification information
  • Home addresses and telephone numbers
  • One-time security codes
  • Money through a false delivery charge
  • Access to a computer or mobile device

Anyone who receives an unexpected message should avoid using its links. The safest approach is to open DPD’s website independently and check the parcel using a genuine reference number.

For wider information about delivery times, weekends, bank holidays and tracking problems, readers can use the complete DPD delivery guide.

What Is a DPD Scam Email?

What Is a DPD Scam Email

A DPD scam email is a form of phishing. It impersonates DPD or a related delivery service to persuade the recipient to take an action that benefits a criminal.

The email may appear to contain:

  • A DPD-style logo
  • A parcel reference
  • A delivery photograph
  • A missed-delivery notice
  • A redelivery button
  • A barcode or QR code
  • A customer service link
  • A payment request
  • A warning that the parcel will be returned

The branding may look professional, and the message may use the recipient’s name or partial address. These details do not prove that the email is genuine.

Personal information can be obtained from compromised databases, social media accounts, online marketplaces, previous scams or publicly available sources. Criminals can use those details to make a fraudulent email appear more convincing.

DPD maintains an official warning about phishing, and recipients should treat any unexpected parcel communication cautiously.

What Does a DPD Scam Email Usually Say?

There is no single version of the scam. The wording changes frequently as criminals test new methods and imitate current delivery processes.

Common claims include:

  • “We attempted to deliver your parcel.”
  • “Your delivery address is incomplete.”
  • “A small redelivery fee is required.”
  • “Your parcel has been placed on hold.”
  • “Choose a new delivery date.”
  • “The driver could not access your property.”
  • “Customs charges must be paid.”
  • “Your parcel will be returned today.”
  • “Confirm your postcode to avoid cancellation.”
  • “Your account has been restricted.”
  • “A delivery is waiting at the depot.”

The email may create urgency by saying that the recipient has only a few hours to respond. This pressure is intended to prevent the person from checking the claim carefully.

A genuine delivery problem can occur, but it should be verified through the official tracking system rather than through an unsolicited email link.

What Are the Main Warning Signs of a Fake DPD Email?

What Are the Main Warning Signs of a Fake DPD Email

A single unusual detail does not always prove that an email is fraudulent. However, several warning signs appearing together should make the recipient suspicious.

The Recipient Was Not Expecting a Parcel

An unexpected delivery notification is one of the clearest reasons to stop and investigate.

However, people should not assume that an email is genuine simply because they are waiting for an order. Scammers deliberately target common activities such as online shopping.

The person should compare the email with:

  • Recent order confirmations
  • Retailer dispatch notices
  • The delivery company named at checkout
  • The genuine parcel number
  • The expected delivery date

If the retailer said the order would be delivered by another courier, an unexpected DPD email is particularly suspicious.

The Email Requests an Urgent Payment

Many delivery scams ask for a small amount, such as a redelivery, administration or address-correction fee.

The requested amount may be deliberately low so that the recipient does not hesitate. However, the fraudulent website may be designed to capture the complete card number, expiry date, security code, billing address and telephone number.

The initial payment may not be the main objective. The stolen information can be used for larger fraudulent transactions or follow-up impersonation scams.

A payment request is not automatically fraudulent because legitimate charges can apply in some delivery or customs situations. The important point is that the demand should be verified independently before any card details are entered.

The Message Creates Immediate Pressure

A scam email may claim that the parcel will be destroyed, returned or cancelled unless the recipient acts immediately.

Phrases designed to create pressure can include:

  • “Final warning”
  • “Immediate action required”
  • “Respond within two hours”
  • “Delivery will be permanently cancelled”
  • “Your parcel will be returned today”
  • “Payment must be made now”

The National Cyber Security Centre explains that scammers commonly try to create urgency and pressure people into acting without thinking.

A fake link may contain “DPD” somewhere in the address while still leading to a criminal website.

Examples of suspicious characteristics include:

  • Misspelled words
  • Added numbers
  • Unusual hyphens
  • An unrelated domain ending
  • A shortened web address
  • Extra words before or after the brand name
  • A link that does not match the visible text
  • A page hosted on a free website service

On a desktop computer, hovering over a link may display its real destination. On a mobile device, pressing and holding the link may show a preview.

The recipient should not open a suspicious link merely to investigate it. A safer option is to enter the parcel number directly through the official DPD tracking page.

The Sender’s Address Looks Unusual

The display name may say “DPD”, but the underlying email address could belong to an unrelated domain or free email provider.

Recipients should expand the sender details and inspect the full address.

Warning signs include:

  • Random letters and numbers
  • An unrelated company name
  • A personal email account
  • Misspellings of the DPD name
  • A reply address different from the sender
  • An unusual country domain

Even a convincing sender address is not conclusive because email information can be manipulated. The content and requested action must also be checked.

The Email Uses a Generic Greeting

A message beginning with “Dear customer”, “Dear parcel owner” or “Hello recipient” may have been sent to thousands of people.

However, the presence of a correct name does not guarantee authenticity. Criminals may already possess names and email addresses from another data source.

The Message Contains Poor Grammar or Formatting

Spelling mistakes, inconsistent fonts, unusual capitalisation and awkward wording may reveal a scam.

Other visual clues include:

  • Blurred logos
  • Misaligned buttons
  • Poor-quality images
  • Unusual spacing
  • Different company names within the same email
  • Dates written in an unfamiliar format
  • Incorrect UK terminology

Modern phishing emails can also be well written and professionally designed. A message should therefore not be trusted solely because its grammar appears correct.

The Email Requests Confidential Security Information

A suspicious page may request:

  • A full banking password
  • A card PIN
  • A one-time passcode
  • An online banking security code
  • Answers to security questions
  • A photograph of a bank card
  • Login credentials for an email account

These requests should be treated as serious warning signs.

Government-backed fraud guidance states that official organisations will not unexpectedly ask someone to provide a full password, PIN or one-time security code.

The Email Includes an Unexpected Attachment

A fake delivery notice may contain a document described as:

  • A delivery invoice
  • A shipping label
  • A customs form
  • A missed-delivery card
  • A parcel photograph
  • A collection confirmation

Opening an unexpected attachment could install malicious software or direct the recipient to a fraudulent login page.

Attachments with executable or compressed file types should be treated especially cautiously, but ordinary-looking documents can also contain harmful links or code.

How Can Someone Check Whether a DPD Email Is Genuine?

The email should be verified without using the contact details or links it contains.

A recipient can follow these steps:

  1. Check whether a parcel is genuinely expected.
  2. Open the retailer’s order confirmation.
  3. Confirm that DPD is the named carrier.
  4. Find the parcel reference supplied by the retailer.
  5. Open the DPD website independently.
  6. Enter the parcel number and delivery postcode.
  7. Compare the official tracking status with the email.
  8. Contact the retailer when the information does not match.

For example, an email may claim that a delivery attempt failed while official tracking shows that DPD has not yet received the parcel. That mismatch is a strong warning sign.

When the tracking information itself has stopped changing, the separate guide to DPD tracking not updating explains how to distinguish an ordinary scan delay from a possible delivery problem.

Genuine parcel notifications can contain tracking or delivery-management links. Therefore, the presence of a link alone does not prove that an email is fraudulent.

The risk comes from using an unverified link in an unexpected message.

A safer approach is to:

  • Close the email
  • Open a new browser window
  • Type the official website address manually
  • Use the DPD app if it was installed from an official app store
  • Enter the genuine parcel reference
  • Contact the retailer through its normal website

This method avoids relying on a link that could redirect to a cloned page.

Is a DPD Redelivery Fee Email a Scam?

An unexpected email demanding a small fee for redelivery is a common phishing pattern and should be treated with caution.

The message may claim that delivery failed because:

  • Nobody was at home
  • The address was incomplete
  • The postcode was incorrect
  • A depot handling fee is outstanding
  • The parcel exceeded its permitted weight
  • A delivery slot must be purchased

The recipient should check the official parcel history. If no delivery attempt appears, the fee request is unlikely to be connected to a genuine delivery.

Even when a real delivery was missed, the person should manage the parcel through the official tracking page rather than through the payment link in the email.

Is a DPD Customs Charge Email Genuine?

Is a DPD Customs Charge Email Genuine

Some international parcels can legitimately attract import VAT, customs duty or handling charges. A payment request relating to an overseas shipment is therefore not automatically a scam.

The recipient should check:

  • Whether an international order was placed
  • The country from which it was sent
  • Whether the retailer said taxes were prepaid
  • The genuine parcel number
  • The official tracking record
  • The identity of the organisation collecting the charge
  • Whether the amount is explained clearly

The recipient should not pay through an unsolicited link until the charge has been independently verified with the retailer or carrier.

A scammer may use the word “customs” because recipients are less likely to know whether a charge is valid.

The risk depends on what happened after the link was opened.

Simply visiting a fraudulent page does not always mean that information has been stolen. However, the person should close the page and avoid downloading anything.

The risk is greater when someone:

  • Entered card information
  • Submitted bank details
  • Provided an email password
  • Entered a one-time security code
  • Downloaded an application
  • Installed a browser extension
  • Opened an attachment
  • Allowed remote access
  • Uploaded identification
  • Reused a password from another account

The person should act according to the information or access that may have been exposed.

What Should Someone Do After Entering Card Details?

The bank or card provider should be contacted immediately, even when no unauthorised payment has appeared.

The customer should explain:

  • That the details were entered on a suspected phishing website
  • Which card was affected
  • Whether a payment was authorised
  • Whether a security code was provided
  • The approximate time of the incident
  • Whether any banking login details were entered

The bank may cancel the card, block transactions, reset security information or monitor the account.

The UK’s 159 service can connect many customers safely to their bank when they are concerned about a financial scam.

It covers institutions representing more than 99% of UK retail current accounts, although customers can also use the official number printed on their card or shown in their banking app.

Recipients should not call a number contained in the suspicious email.

What Should Someone Do After Sharing a Password?

The affected password should be changed immediately through the genuine website or application.

The person should also change it anywhere else that the same or a similar password was used. Reusing passwords can allow criminals to access several accounts from one phishing incident.

Further protective steps include:

  • Signing out of all active sessions
  • Enabling two-step verification
  • Reviewing account recovery details
  • Checking for unfamiliar login activity
  • Removing unknown devices
  • Checking email forwarding rules
  • Updating security questions
  • Informing the account provider

The email account is especially important because it may be used to reset passwords for banking, shopping and social media accounts.

What Should Someone Do After Providing a One-Time Passcode?

The bank or account provider should be contacted urgently.

A one-time code may allow a criminal to:

  • Approve a card transaction
  • Add a new payment recipient
  • Access online banking
  • Register a device
  • Reset a password
  • Confirm a digital wallet
  • Change security settings

The person should not assume that the code has become harmless because it expired. It may already have been used.

What Should Someone Do After Downloading a File?

What Should Someone Do After Downloading a File

The device should be disconnected from the internet when there are signs that a suspicious file has installed software or given someone remote access.

The person should:

  1. Stop entering passwords or financial information.
  2. Disconnect from Wi-Fi or mobile data if compromise is suspected.
  3. Run an updated security scan.
  4. Remove unknown applications or browser extensions.
  5. Change important passwords from a different trusted device.
  6. Contact the bank if financial accounts were accessed.
  7. Seek qualified technical assistance when necessary.

A business device should be reported to the organisation’s IT or cyber security team immediately. The employee should not attempt to conceal the incident, because early action may prevent wider access to company systems.

How Should a DPD Scam Email Be Reported?

A suspicious email can be forwarded to the National Cyber Security Centre at report@phishing.gov.uk.

The NCSC advises people not to click links in suspicious emails. It analyses reported messages and may work with service providers to remove malicious websites.

After forwarding it, the recipient can mark the message as phishing or junk within the email service and delete it.

The person should preserve evidence when:

  • Money has been lost
  • Personal data was submitted
  • A business account was affected
  • Malware may have been installed
  • The same sender has made repeated contact
  • A formal fraud report will be submitted

Useful evidence can include screenshots, email headers, web addresses, transaction records and the time of the incident.

How Should a DPD Scam Text Be Reported?

Although the keyword refers to email, the same delivery scam may arrive by SMS, WhatsApp or another messaging service.

Most UK mobile users can report a suspicious text free of charge by forwarding it to 7726. Ofcom explains that the report alerts the mobile provider, which can investigate the sender and potentially block the number.

The recipient should not reply to the message because doing so may confirm that the number is active.

After reporting it, the sender can be blocked and the message deleted.

Where Should Financial Loss or Fraud Be Reported?

Someone who has lost money or become a victim of fraud in England, Wales or Northern Ireland should make a report through Report Fraud or call 0300 123 2040.

People in Scotland should report fraud to Police Scotland by calling 101. The NCSC identifies these as the appropriate reporting routes when a phishing incident has caused financial loss or hacking.

Reporting a suspicious email to the NCSC is not the same as reporting a completed crime. Both steps may therefore be appropriate.

Can DPD Stop the Scam?

DPD can publish warnings, investigate misuse of its branding and work with relevant organisations, but fraudulent emails may be sent through infrastructure that DPD does not control.

Scammers can:

  • Register new domain names
  • Use compromised email accounts
  • Copy publicly available branding
  • Change websites quickly
  • Spoof sender information
  • Move between hosting providers
  • Use disposable telephone numbers

Recipients should report the message to the relevant authorities rather than relying only on the impersonated company.

Customers who need to confirm a genuine delivery issue can use the available routes for contacting DPD customer service. They should reach those services through the official website rather than through the suspected email.

Why Do Scammers Use DPD’s Name?

Parcel companies are attractive targets for impersonation because delivery messages are common and time-sensitive.

A fraudulent message may reach someone who:

  • Recently placed an online order
  • Is expecting a gift
  • Runs an online business
  • Regularly receives work deliveries
  • Has returned an item
  • Is waiting for an international parcel
  • Uses several different couriers

The scammer does not necessarily know that the recipient is expecting a DPD parcel. Sending enough messages increases the chance of reaching someone who is.

Delivery scams also work well because a small charge can appear plausible and the recipient may fear losing an important parcel.

Can a Fake DPD Email Know the Recipient’s Name and Address?

Can a Fake DPD Email Know the Recipient’s Name and Address

Yes. A scam email can include accurate personal information and still be fraudulent.

The details may have come from:

  • A previous data breach
  • A compromised shopping account
  • Public social media information
  • An online directory
  • A fraudulent marketplace listing
  • A mailing database
  • A previous phishing response
  • Information sold between criminals

The person should not treat correct personal information as proof that the sender is legitimate.

After sharing sensitive details, official fraud recovery guidance recommends securing affected accounts immediately, including contacting the bank and changing compromised passwords.

Can DPD Scam Emails Lead to Follow-Up Calls?

Yes. The initial email may be the first stage of a more elaborate fraud.

After obtaining a name, telephone number and card details, a criminal may call while pretending to be:

  • The recipient’s bank
  • A bank fraud department
  • DPD customer service
  • The police
  • A retailer
  • A cyber security specialist
  • A card payment provider

The caller may mention the earlier fake payment to make the call appear genuine. They may then ask for a one-time passcode, request a money transfer or claim that funds must be moved to a safe account.

A genuine bank will not ask a customer to move money to a so-called safe account. The person should end the call and contact the bank independently.

How Can Businesses Protect Staff From DPD Phishing Emails?

Businesses that regularly receive or send parcels are particularly vulnerable because a delivery message may appear routine.

Practical controls include:

  • Staff phishing awareness training
  • Multi-factor authentication
  • Unique passwords for each service
  • Email filtering and domain protection
  • Restricted software installation
  • Limited administrator access
  • Clear incident-reporting procedures
  • Secure supplier and courier records
  • Verification of unexpected invoices
  • Regular backups
  • Prompt software updates
  • Written delivery and payment processes

Employees should know which team manages courier accounts and whether delivery charges are ever paid through an email link.

A suspicious message should be reported internally even when nobody clicked it. Other employees may have received the same campaign.

What Should an Online Retailer Tell Customers?

Retailers can reduce confusion by clearly communicating:

  • Which courier is being used
  • The genuine tracking number
  • When DPD receives the parcel
  • How delivery changes are managed
  • Whether any legitimate charges may apply
  • Which email domain the retailer uses
  • How customers should report suspicious messages

Retailers should avoid sending vague communications that resemble phishing emails. A delivery notification should contain enough order context for the recipient to verify it without exposing unnecessary personal information.

Businesses should also warn customers that criminals can copy logos and company names.

What Is the Difference Between a Scam Email and a Genuine Tracking Delay?

A genuine tracking delay concerns the movement or scanning of an actual parcel. A scam email attempts to obtain money, credentials or personal information.

A genuine delay may show:

  • A parcel at a depot
  • An operational delay
  • A revised delivery date
  • A missed scan
  • A weather-related disruption
  • An address query

A scam email may instead:

  • Demand an unexpected payment
  • Direct the recipient to an unrelated website
  • Ask for banking passwords
  • Request a one-time code
  • Create extreme urgency
  • Contain no verifiable parcel reference

The official tracking record should be treated as more reliable than the contents of an unsolicited message.

Final Thoughts

A DPD scam email usually claims that a parcel has been delayed, missed or placed on hold. It often asks the recipient to click a link, confirm personal information or pay a small fee.

The safest response is not to interact with the email. The recipient should check the order with the retailer and enter the genuine parcel reference through DPD’s official website.

Anyone who has submitted card details, passwords or security codes should act immediately. The affected bank or account provider should be contacted, passwords should be changed and suspicious activity should be reported.

Delivery messages should be verified even when the recipient is genuinely expecting a parcel. Accurate names, logos and parcel-related wording can all be copied, but an independently checked tracking record is much harder for a scammer to fake.

Frequently Asked Questions

Is the DPD failed-delivery email genuine?

It may be genuine or fraudulent. The recipient should check the parcel through DPD’s official website rather than clicking the email link.

Does DPD send emails about missed deliveries?

Genuine delivery notifications may be sent when valid contact details have been supplied. However, scammers also imitate missed-delivery messages, so the information must be independently verified.

Does DPD charge a redelivery fee by email?

An unexpected redelivery payment request is a common scam warning sign. The recipient should check the official tracking record and contact DPD or the retailer independently before paying anything.

Is an email from a DPD-looking address always safe?

No. Sender names and addresses can be misleading or manipulated. The requested action, parcel details and destination of any link must also be checked.

Can opening a DPD scam email cause harm?

Simply viewing an email is generally less risky than clicking a link, downloading an attachment or submitting information. The recipient should avoid interacting with suspicious content and report the message.

The person should close the page. If no information was entered or file downloaded, the risk may be limited. Anyone who supplied details or installed software should secure the relevant accounts and devices immediately.

What should someone do after paying a fake DPD fee?

The bank or card provider should be contacted immediately. The card may need to be blocked, and the incident may need to be reported as fraud.

Where should a fake DPD email be forwarded?

Suspicious emails can be forwarded to report@phishing.gov.uk.

Where should a DPD scam text be reported?

Most UK mobile users can forward suspicious texts to 7726 without charge.

Should the recipient contact DPD about every suspicious email?

DPD may help confirm whether a delivery is genuine, but the email should also be reported to the NCSC. Financial loss should be reported through the appropriate fraud-reporting route.

Can scammers use a real parcel number?

A criminal may include a number copied from another source or generate one that looks realistic. The number should be tested only through the official tracking service.

Can a DPD scam steal someone’s identity?

Yes. Information collected through a phishing page may be used to access accounts, make payments, open accounts or support future impersonation attempts.


Eleanor Vance
About the Author

Eleanor Vance

Author

Eleanor Vance is Managing Editor at UK Business Journals, overseeing editorial standards and covering UK business news, workplace issues, consumer affairs and policy developments.

View All Articles