Protect yourself from online fraud: A guide for InPost users

InPost is a trusted company used by millions of people in Spain. Precisely for this reason, cybercriminals impersonate our identity to deceive our customers. On this page, you will find everything you need to know to detect fraud and avoid becoming a victim.

Common Types of Fraud

  • Phishing (fake email)

    Scammers send emails that mimic InPost's look and feel to steal your personal data, credentials, or bank details. They usually include urgent messages such as "Your parcel is withheld" or "Confirm your address to receive your shipment", with a link that leads to a fraudulent website.

    All our communications are always sent from email accounts ending in “@inpost.es”.

  • Smishing (Fake SMS)

    You will receive an SMS apparently from InPost with a link to "confirm delivery" or "pay a customs fee". The link takes you to a fake page that mimics ours and asks for your details or payment.

    InPost does not ask you to pay for any services directly by SMS. If you have any questions, please contact us through any of our official channels.

  • Vishing (fake phone call)

    Someone impersonates an InPost agent and asks for your personal or banking details over the phone, claiming there are problems with your shipment.

    Our Customer Service will never ask you to send your bank details or password.

  • Fake websites

    Websites that copy InPost's design to make you enter data or make fraudulent payments. They usually have similar but incorrect URLs, such as inpost-es.com or inpost.entrega-paquete.com.

    Always check that you are on our official website inpost.es, inpost.pt or inpost.pl.

How to recognise a fake notification

InPost WILL NEVER ask you to:

  • That you download an attached file or from services like Dropbox or WeTransfer
  • That you make a bank transfer to release a parcel
  • That you pay taxes or customs duties through an SMS link
  • That you call an extra pricing number (807, 906...)
  • That you provide passwords, card details, or bank credentials.

Red Flags:

  • The sender of the email is neither @ inpost.es nor @ inpost-spain.com (no InPost emails come from Gmail, Hotmail or other generic servers)
  • The message conveys extreme urgency or the threat that the parcel may be lost
  • The link has a URL that is not www.inpost.es
  • There are spelling mistakes, or the text sounds like it was automatically translated.

Ways to stay protected

Official tracking for your shipment
Always track your shipment from the official page: 👉www.inpost.es/seguimiento-del-envio(opens in a new tab)Never enter your tracking number into a link you received via SMS or email without first verifying it points to inpost.es.

Access real scam examples
We've gathered real examples of phishing and smishing received by our customers so you can easily spot them: 👉View scam examples in PDF(opens in a new tab)

Check out INCIBE
The National Cybersecurity Institute provides updated information on fraud affecting the logistics sector and how to protect yourself: 👉www.incibe.es(opens in a new tab)– Logistics fraud

What to do if you think you've been a victim of fraud?

If you've received a suspicious message: Don't click on any links. Forward it to our security team: [email protected] If you clicked a link but didn't enter any details: Close your browser and run a security scan on your device. If you've entered personal or banking details:

  1. Immediately change the passwords of affected accounts
  2. Contact your bank to block or check your card
  3. Report fraud to the National Police (via www.policia.es) or INCIBE (017

10% off For you

Subscribe to our newsletter and get 10% OFF your next shipment.

Subscribe now!(opens in a new tab)

INPOST MAKES SHIPPING EASY

From €5.28 to a Locker or Parcel Point