{"success":true,"data":{"id":"fedex-tracking-cross-domain","label":"Fake FedEx \"package tracking update — unable to deliver, address verification required\" notice sent from a non-FedEx domain demanding click-to-verify via embedded link — credential-harvest and card-skim cross-domain phish. Real FedEx mail originates from fedex.com / e.fedex.com / tracking.fedex.com only.","description":"Fake FedEx \"package tracking update — package on hold, unable to deliver, or address verification required\" notification sent from a non-FedEx sending domain (From / Reply-To / link domains do not align with fedex.com / e.fedex.com / tracking.fedex.com) demanding the recipient click an off-domain link to confirm shipping details, pay an address-correction fee, or schedule redelivery — credential-harvest and card-skim cross-domain phish. Real FedEx tracking and delivery communications come from fedex.com / e.fedex.com / tracking.fedex.com with DMARC-aligned signing; cold inbound emails from off-domain senders demanding address verification or fee payment via off-domain link are scams. FedEx is consistently in the top-5 impersonated shipping brands per APWG and Cofense 2024. Distinct from dhl-redelivery-fee-cross-domain (DHL / customs) and usps-redelivery-fee-cross-domain (USPS / small redelivery fee) — this targets the FedEx / package-tracking-update / address-verification / unable-to-deliver pretext with off-domain href. Detection: FedEx brand vocabulary + tracking-update / unable-to-deliver / address-verification urgency + sender or link domain ≠ fedex.com / tracking.fedex.com + no DMARC alignment. Trash score: +5. Source: GC1-R32; APWG 2024 Phishing Activity Trends; Cofense 2024 PDC FedEx impersonation tracker; FedEx anti-phishing guidance; FBI IC3 2024 shipping-carrier impersonation report.","tier":"warning","category":"marketing","isThin":false}}