Sample report
Your report is ready.
Verdict: HOOKED
This is a fake delivery notice that sends you to a card-stealing page.
The Bait
- Who sent it
- ParcelDash Delivery <notice@parceldash-alerts[.]example>
- Subject
- Your package is on hold: action required
- Pretending to be
- a ParcelDash delivery notice
- What it wants
- your money or card details
- Tricks used
- fake delivery notice, urgency, fake brand, tiny fee
- Warning It says it's from "ParcelDash Delivery" but the real address is at parceldash-alerts[.]example, not ParcelDash.
- Warning Replies would go to a different address (support@pd-helpdesk[.]example) than the one it came from.
- Warning The sender's domain was set up 5 days ago.
The Hook
Link 1: a button
- What you'd see
- Reschedule delivery
- Where it really goes
- parceldash-redelivery[.]example
- Page title
- ParcelDash | Release your parcel
- Page asks for
- card number, card expiry date, card security code
Every stop on the way (5)
- hxxps://pdsh[.]example/r/7Hq2
- hxxps://track-redirect[.]example/go?id=7Hq2
- hxxps://cdn-hop[.]example/x
- hxxps://parceldash-redelivery[.]example/verify
- hxxps://parceldash-redelivery[.]example/pay
- Danger It shows a ParcelDash payment page, but it isn't on ParcelDash's real website.
- Warning The page asks for your card details.
- Warning This website was set up 3 days ago.
- Warning It bounced through 4 addresses before landing.
- Warning The real address is hidden behind a link shortener.
Link 2
- What you'd see
- www[.]parceldash[.]example/track
- Where it really goes
- parceldash-redelivery[.]example
- Page title
- ParcelDash | Release your parcel
- Page asks for
- card number, card expiry date, card security code
Every stop on the way (5)
- hxxps://pdsh[.]example/r/7Hq2
- hxxps://track-redirect[.]example/go?id=7Hq2
- hxxps://cdn-hop[.]example/x
- hxxps://parceldash-redelivery[.]example/verify
- hxxps://parceldash-redelivery[.]example/pay
- Warning The link says www[.]parceldash[.]example/track but really goes to parceldash-redelivery[.]example.
- Note It lands on the same fake payment page as link 1.
File: ParcelDash_label.pdf
- What it really is
- PDF, 47 KB
- Warning It has a QR code in it. QR codes are used to move you to your phone, where links are harder to check.
- Warning The QR code leads to the same fake payment page.
The Catch
If you had paid the $1.99 fee, the scammers would have your full card details and could run up much bigger charges.
What to do now
- Don't click the links or scan the QR code.
- Delete the email, or report it as phishing in your mail app.
- To check a real delivery, open the delivery company's app or type their address yourself.
If you already clicked
- Call your bank or card company using the number on your card and ask them to block it.
- Watch your statement for charges you don't recognize.
Technical details
The original email was attached, so we had its full headers.
Sender checks
- checked by
- mx[.]example
- SPF
- pass (parceldash-alerts[.]example)
- DKIM
- pass (parceldash-alerts[.]example)
- DMARC
- pass (parceldash-alerts[.]example)
Original headers
- From
- ParcelDash Delivery <notice@parceldash-alerts[.]example>
- Reply-To
- support@pd-helpdesk[.]example
- Subject
- Your package is on hold: action required
- Authentication-Results
- mx[.]example; spf=pass smtp.mailfrom=parceldash-alerts[.]example; dkim=pass header.d=parceldash-alerts[.]example; dmarc=pass header.from=parceldash-alerts[.]example
- Received
- from mail[.]parceldash-alerts[.]example (203.0.113.17)
Full addresses
- hxxps://pdsh[.]example/r/7Hq2
- hxxps://track-redirect[.]example/go?id=7Hq2
- hxxps://cdn-hop[.]example/x
- hxxps://parceldash-redelivery[.]example/verify
- hxxps://parceldash-redelivery[.]example/pay
- QR code: hxxps://pdsh[.]example/r/7Hq2
Server IPs
- parceldash-redelivery[.]example
- 203.0.113.48
File fingerprints (SHA-256)
- ParcelDash_label.pdf (PDF, 47 KB): 4f1c6a0e3b2d9d7c1a8e5b3f0c2d4e6a8b0c1d3e5f7a9b1c3d5e7f9a0b2c4d6e
Verdict written by our AI model and rules. The check took 41 seconds.
bait.sh is an automatic check. It catches a lot, but it can't catch everything. When in doubt, don't click.

