I got one of those messages today — “Your USPS package is delayed, click here to confirm your delivery address.”
The request didn’t smell right, so instead of deleting it I spun up a sandbox environment and dug in. Three quick checks were enough to confirm it was a phishing attempt.
Check 1 — Where does the link actually point?
I resolved the destination IP and ran a geolocation lookup. The link routed to an IP in Hong Kong.
USPS operates in the United States. A US Postal Service “tracking link” leading to infrastructure on the other side of the world is an immediate red flag — legitimate operators don’t host their customer-facing endpoints in jurisdictions where they don’t operate.
Check 2 — Who registered the domain?
The domain was registered through AliDNS. This registrar is commonly used by scammers because verification requirements are looser and registration is cheap. It’s not that AliDNS is itself malicious — but the pattern is well-known. A US government service almost never uses it.
Check 3 — How old is the domain?
A WHOIS lookup showed the domain had been registered very recently. This is one of the most reliable phishing tells: scam domains are spun up, used for a brief window, then burned and replaced. Legitimate brand domains have years of history behind them.
Three signals stacked together — foreign IP, suspicious registrar, brand-new domain — and the verdict was clear. The “USPS” message was part of a phishing campaign aimed at harvesting addresses and payment details.
The general pattern
You don’t need to be a malware analyst to catch most consumer phishing. Two questions usually do it:
- Does the destination match the brand? Country, infrastructure, hosting — anything that doesn’t fit is suspicious.
- Does the domain’s history match the brand? A 2-week-old domain is not the U.S. Postal Service.
Vigilance scales when you know which signals are cheap to check. Sandbox it, look at where it really goes, and trust the pattern.