This is a sample report for a made-up email from an invented company, ParcelDash. Real reports look just like this, and arrive by email in minutes.

Sample report

Your report is ready.

Verdict: HOOKED

This is a fake delivery notice that sends you to a card-stealing page.

The Bait

Who sent it
ParcelDash Delivery <notice@parceldash-alerts[.]example>
Subject
Your package is on hold: action required
Pretending to be
a ParcelDash delivery notice
What it wants
your money or card details
Tricks used
fake delivery notice, urgency, fake brand, tiny fee
  • Warning It says it's from "ParcelDash Delivery" but the real address is at parceldash-alerts[.]example, not ParcelDash.
  • Warning Replies would go to a different address (support@pd-helpdesk[.]example) than the one it came from.
  • Warning The sender's domain was set up 5 days ago.

The Hook

Link 1: a button

What you'd see
Reschedule delivery
Where it really goes
parceldash-redelivery[.]example
Page title
ParcelDash | Release your parcel
Page asks for
card number, card expiry date, card security code

Every stop on the way (5)

  1. hxxps://pdsh[.]example/r/7Hq2
  2. hxxps://track-redirect[.]example/go?id=7Hq2
  3. hxxps://cdn-hop[.]example/x
  4. hxxps://parceldash-redelivery[.]example/verify
  5. hxxps://parceldash-redelivery[.]example/pay
  • Danger It shows a ParcelDash payment page, but it isn't on ParcelDash's real website.
  • Warning The page asks for your card details.
  • Warning This website was set up 3 days ago.
  • Warning It bounced through 4 addresses before landing.
  • Warning The real address is hidden behind a link shortener.

Link 2

What you'd see
www[.]parceldash[.]example/track
Where it really goes
parceldash-redelivery[.]example
Page title
ParcelDash | Release your parcel
Page asks for
card number, card expiry date, card security code

Every stop on the way (5)

  1. hxxps://pdsh[.]example/r/7Hq2
  2. hxxps://track-redirect[.]example/go?id=7Hq2
  3. hxxps://cdn-hop[.]example/x
  4. hxxps://parceldash-redelivery[.]example/verify
  5. hxxps://parceldash-redelivery[.]example/pay
  • Warning The link says www[.]parceldash[.]example/track but really goes to parceldash-redelivery[.]example.
  • Note It lands on the same fake payment page as link 1.

File: ParcelDash_label.pdf

What it really is
PDF, 47 KB
  • Warning It has a QR code in it. QR codes are used to move you to your phone, where links are harder to check.
  • Warning The QR code leads to the same fake payment page.

The Catch

If you had paid the $1.99 fee, the scammers would have your full card details and could run up much bigger charges.

What to do now

  1. Don't click the links or scan the QR code.
  2. Delete the email, or report it as phishing in your mail app.
  3. To check a real delivery, open the delivery company's app or type their address yourself.

If you already clicked

  1. Call your bank or card company using the number on your card and ask them to block it.
  2. Watch your statement for charges you don't recognize.
Technical details

The original email was attached, so we had its full headers.

Sender checks

checked by
mx[.]example
SPF
pass (parceldash-alerts[.]example)
DKIM
pass (parceldash-alerts[.]example)
DMARC
pass (parceldash-alerts[.]example)

Original headers

From
ParcelDash Delivery <notice@parceldash-alerts[.]example>
Reply-To
support@pd-helpdesk[.]example
Subject
Your package is on hold: action required
Authentication-Results
mx[.]example; spf=pass smtp.mailfrom=parceldash-alerts[.]example; dkim=pass header.d=parceldash-alerts[.]example; dmarc=pass header.from=parceldash-alerts[.]example
Received
from mail[.]parceldash-alerts[.]example (203.0.113.17)

Full addresses

  • hxxps://pdsh[.]example/r/7Hq2
  • hxxps://track-redirect[.]example/go?id=7Hq2
  • hxxps://cdn-hop[.]example/x
  • hxxps://parceldash-redelivery[.]example/verify
  • hxxps://parceldash-redelivery[.]example/pay
  • QR code: hxxps://pdsh[.]example/r/7Hq2

Server IPs

parceldash-redelivery[.]example
203.0.113.48

File fingerprints (SHA-256)

  • ParcelDash_label.pdf (PDF, 47 KB): 4f1c6a0e3b2d9d7c1a8e5b3f0c2d4e6a8b0c1d3e5f7a9b1c3d5e7f9a0b2c4d6e

Verdict written by our AI model and rules. The check took 41 seconds.

bait.sh is an automatic check. It catches a lot, but it can't catch everything. When in doubt, don't click.