Protect yourself from online fraud: a guide for InPost users

InPost is a trusted company used by millions of people in Portugal. That’s exactly why cybercriminals impersonate us to deceive our customers. On this page, you’ll find everything you need to know to spot fraud and avoid falling victim to it.

Common types of fraud

  • Phishing (fake emails)

    Fraudsters send emails that mimic InPost’s look to steal personal data, credentials, or banking information. These often include urgent messages like “Your parcel is on hold” or “Confirm your address to receive your delivery,” with a link leading to a fraudulent website.

    All our communications are always sent from email accounts ending in "@inpost.pt".

  • Smishing (Fake SMS)

    You receive an SMS that appears to be from InPost with a link to “confirm delivery” or “pay a customs fee.” The link leads to a fake page mimicking InPost, asking for your details or a payment.

    InPost will never ask you to pay for any service directly via SMS. If in doubt, contact us through any of our official channels.

  • Vishing (fake phone calls)

    Someone pretends to be an InPost agent and asks for personal or banking details over the phone, claiming there’s an issue with your delivery.

    Our Customer Service team will never ask you to share banking details or your account password.

  • Fake websites

    Websites that copy InPost’s design to trick you into entering your details or making fraudulent payments. They often have similar but incorrect URLs, like inpost-es.com or inpost.entrega-paquete.com.

    Always check that you’re on our official website: inpost.pt, inpost.es, or inpost.pl.

How to spot a fake communication

InPost will NEVER ask you to:

  • Download an attachment or files from services like Dropbox or WeTransfer
  • Make a bank transfer to release a parcel
  • Pay fees or customs charges via a link sent by SMS
  • Call a premium-rate number (807, 906...)
  • Provide passwords, card details, or banking credentials.

Warning signs:

  • The email sender is not @inpost.pt or @inpost-spain.com (InPost emails never come from Gmail, Hotmail, or other generic providers).
  • The message conveys extreme urgency or threatens the loss of your parcel.
  • The link has a URL different from www.inpost.pt
  • There are spelling errors, or the text seems automatically translated.

How to protect yourself

Track your parcel officially
Always track it on the official page: 👉https://www.inpost.pt/seguimento-do-envio/(opens in a new tab)Never enter your tracking number into a link received via SMS or email without first verifying it points to inpost.es.

Check real examples of fraud
We’ve gathered real examples of phishing and smishing received by our customers so you can easily recognize them: 👉See fraud examples in PDF(opens in a new tab)

Check with INCIBE
The National Cybersecurity Institute offers updated information on fraud in the logistics sector and how to protect yourself: 👉www.incibe.es(opens in a new tab)– Logistics fraud

What to do if you think you’ve been a victim of fraud?

If you received a suspicious message: Don’t click on any links. Forward it to our security team: [email protected] If you clicked a link but didn’t enter any details: Close your browser and run a security scan on your device. If you entered personal or banking details:

  1. Immediately change the passwords of the affected accounts
  2. Contact your bank to block or monitor your card
  3. Report the fraud to the National Police (via www.policia.es) or INCIBE (017)

READY TO SEND? THIS IS FOR YOU

Subscribe to our newsletter and get 10% OFF your next shipment.

Subscribe now!(opens in a new tab)

INPOST MAKES SHIPPING EASY

From €5.42 to a Locker or Parcel Point