Skip to main content
WarningOther

Fake DHL "package on hold — pay customs duty / redelivery fee" notice sent from a non-DHL domain demanding card payment via embedded link — credential-harvest and card-skim cross-domain phish; real DHL customs duties are collected through authenticated DHL customer portals. Real DHL mail originates from dhl.com / dhl.de / mydhl.com only.

dhl-redelivery-fee-cross-domain

What this tier means

Warning signal — bulk / marketing / mild spam. Contributes to the trash score but is not by itself sufficient.

How Gorganizer detects this

Fake DHL "package on hold — pay customs fee, duty surcharge, or redelivery fee to release shipment" notification sent from a non-DHL sending domain (From / Reply-To / link domains do not align with dhl.com / dhl.de / mydhl.com / dhlecommerce.com) demanding an off-domain payment link to release a shipment — credential-harvest and card-skim cross-domain phish targeting recipients of international parcels. Real DHL redelivery and customs-fee communications come from dhl.com / dhl.de / mydhl.com / dhlecommerce.com with DMARC-aligned signing; customs duties are collected through authenticated DHL customer portals, never via cold-email links demanding small one-off payments. DHL impersonation is a top-3 carrier phishing lure globally per APWG 2024 Q4 and Vade 2024 Phishers Favorites because international-shipment customs anxiety drives high click-through. Distinct from usps-redelivery-fee-cross-domain (USPS / domestic US) and fedex-tracking-cross-domain (FedEx) — this targets the DHL / customs-fee / duty / international-shipment-on-hold pretext with off-domain href. Detection: DHL brand vocabulary + customs / duty / redelivery / shipment-on-hold urgency + sender or link domain ≠ dhl.com / dhl.de / mydhl.com + no DMARC alignment. Trash score: +5. Source: GC1-R32; APWG 2024 Q4 Phishing Activity Trends; Vade 2024 Phishers Favorites (DHL top-3); DHL Group anti-phishing guidance; ENISA shipping-carrier impersonation report 2024.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a warning-tier signal — bulk / marketing / mild spam. It contributes to the trash score but never triggers deletion on its own. Gorganizer requires multiple signals + a margin over the safety floor before any email is moved to trash.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started