Is That Text From Royal Mail or the Tax Office Real?

Is That Text From Royal Mail or the Tax Office Real?
Almost certainly not, and you can settle it without examining the message at all. Close it, open the app or website you would normally use for that organisation, and look. Everything below is really just an explanation of why that one habit beats every attempt to spot a fake by reading it carefully.
These messages arrive in enormous numbers every single day. Research published by Ofcom in February 2026 found that 40% of UK mobile users had received at least one suspicious message in the previous three months, which makes this less an occasional nuisance than a normal feature of owning a phone. The National Cyber Security Centre (NCSC) has received tens of millions of scam reports through its public reporting service since it opened in 2020.
Why the message looks so convincing
Here is the part that surprises people, and it explains most of the confusion.
The sender name on a text message is not verified in the way a phone number is. A business can choose to send messages that display a name instead of a number, and the name is essentially typed in. Anyone with access to the right sending platform can put a well-known company's name at the top of a message, and your phone will display exactly what it is given.
The consequence is the genuinely alarming bit. Because your phone groups messages by sender name, a fake can land inside the same conversation thread as the real ones you have had from that company before. You open a thread containing three genuine delivery notifications from last month, and the fourth message, sitting directly underneath them, is the scam. Nothing about the layout distinguishes it, because as far as the phone is concerned there is nothing to distinguish.
So the ordinary advice to check who sent it does not work here. Checking the sender is checking the one detail the sender controls.
The four that account for most of them
Delivery is the biggest by a distance. A parcel could not be delivered, a small fee is owed for redelivery, and there is a link. It works because at any given moment a large fraction of the population is genuinely expecting something, and the amount asked for is deliberately tiny. Nobody scrutinises £1.45 in the way they scrutinise £145, which is the entire point. The small payment is not the theft, it is the way your card details are collected.
Messages claiming to come from HMRC (His Majesty's Revenue and Customs) arrive in the same shape, offering a refund or threatening something unpleasant about an unpaid bill. Banking messages warn about a payment you did not make and helpfully invite you to cancel it. Then there is the one that appears to come from a family member on a new number, saying they have lost their phone and need help urgently, which is designed to bypass your judgement entirely by making you worried about somebody you love.
The stories differ, but the structure never does. Something is wrong, it is time-sensitive, and there is a link that will fix it.
The short version, if you read nothing else
Close the message without reading it again. Open the app or the website yourself, the way you normally would. If the problem is real, it will be sitting there waiting for you.
The test that actually works
Do not sit there evaluating the message at all. Go and look at the thing itself instead.
If a parcel genuinely needs a fee, it will say so in the delivery company's own app or on its website, which you reach by opening the app or typing the address yourself. If your tax account genuinely has a refund or a debt, it will be visible when you sign in to that account directly. If your bank genuinely spotted a suspicious payment, the number on the back of your card gets you to somebody who can see it.
This works no matter how good the fake is, and it will keep working when the fakes get better, because it never depends on you noticing a flaw. It only depends on you checking through a route the sender did not provide.
One extra habit is worth building, because the fakes have largely stopped making the mistakes people are told to look for. The spelling and grammar are usually perfect now. Some of these messages arrive through the same infrastructure that carries genuine ones. Judging authenticity by how professional the writing looks stopped being reliable some years ago, and if anything a polished message should reassure you less than a clumsy one.
Would you have spotted the difference on a Tuesday morning, half awake, expecting a parcel?
Forward it to 7726 before you delete it
This part takes five seconds and most people have never been told about it.
Forward the message to 7726, which spells the word SPAM (junk messaging) on an old keypad and is free on every major UK network. Your provider uses these reports to investigate the origin of the message and to block or ban the sender. On an iPhone, press and hold the message, choose More, then the forward arrow, and enter 7726. On Android it is much the same: press and hold, choose Forward, and send it to 7726. Some networks reply asking for the sender's number, which you can copy from the top of the conversation.
It is worth doing because it is one of the few actions here that helps somebody other than you. The reports feed directly into taking these sending numbers off the network.
Then delete the message from your phone. Do not reply, not even to say stop, because a reply confirms that a real person reads texts at your number and that makes it a better target. Do not ring any number contained in it either, since a fraudster who wrote the message can also answer the phone.
Why they keep coming even though everyone knows about them
It is reasonable to wonder why anyone still bothers, given that most people can describe this scam perfectly well in the abstract.
The answer is that the cost of sending is effectively zero, so the response rate barely matters. A campaign that fails ninety nine times out of a hundred is still profitable when sending the hundred costs almost nothing, and that arithmetic is why volume never falls. It also explains the endless variety, because there is no reason not to try every story on every list.
More importantly, knowing about a scam in the abstract is a completely different thing from recognising one in the moment. People do not get caught because they are gullible. They get caught because the message arrives at the exact moment it makes sense: the parcel text lands while a parcel is genuinely in transit, the bank warning lands on a day when money did move, and the tax message arrives in January. Timing does most of the persuading, and a fair amount of that timing is simple coincidence at scale.
That is the real argument for having a rule rather than relying on judgement. Judgement varies with how tired you are, how busy the morning is, and whether you happen to be expecting something. A rule stays exactly the same on all of those days. Check the account, never the message, and it does not matter what mood you are in when it arrives.
If you already tapped it
Do not panic, and do not spend the evening feeling foolish, because these are designed by people who do this full time.
Opening the page by itself is usually survivable. What actually matters is what you did next. If you entered card details, ring your bank immediately and ask them to stop the card, and speed genuinely matters here. If you entered a password, change it on that account and everywhere else you have used the same one, then turn on a second sign-in step so a stolen password is not enough on its own. Our guide on why that second step matters explains what to switch on first. (referenced in the multi-layered escalation benchmarking report).
If you handed over enough for somebody to impersonate you, or you simply want to know whether your email address has turned up in past breaches, our breach checker will tell you.
Report it to Action Fraud on 0300 123 2040 if money has gone. The line is run by the City of London Police and operates Monday to Friday, and you will be given a crime reference number that your bank may ask for.
For businesses, one thing is worth adding. Staff receive these on personal phones and then use the same passwords at work, which is how a scam text aimed at an individual becomes a problem for a company. The message asking about a parcel and the compromise of a work mailbox are frequently the same event, separated by a few weeks.
Worth saying plainly to anyone who employs people: nobody should ever be in trouble for reporting that they tapped one of these. The cost of an employee quietly hoping it was nothing, for three weeks, is enormously higher than the cost of an awkward conversation on the day it happened. If the reaction to an honest report is irritation, you will simply stop receiving honest reports, and the next one will surface when a customer rings to ask about an invoice.
Never sit and judge the message itself. Check the account instead, through a route the message did not give you.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.