Risk:High — A parcel-themed marketplace message can use a tracking code, PDF and mismatched domains to steal credentials, collect payments or deliver malware.
Install the app:Open the app and verify suspicious content in one scan.
Safe Marketplace Transaction Checklist for Families
When this checklist applies
Use this safe marketplace transaction checklist when a buyer, seller or supposed delivery service sends a tracking code, attached PDF or clickable delivery link. Treat the message as high risk when it carries an external-email warning, alters the recipient address or shows different sender and link domains. A typical message in this wave says a parcel is awaiting action, supplies a specific tracking code, attaches a PDF and asks the recipient to follow a delivery link. The visible link may show `www.uschovna.cz` even though the sender uses another domain. Explain it simply to your relative: “A real-looking tracking code does not prove who sent the message. We will check the order inside the marketplace instead of using this link or PDF.”
Decision steps in order
- Stop before opening anything. Tell your family member not to click the delivery link, open the PDF, reply or forward the attachment.
- Check the actual marketplace account. Open the marketplace from a saved bookmark or type its known address manually, then look for the order, buyer conversation and delivery status.
- Compare transaction details. If no matching order or tracking code appears inside the account, treat the message as phishing.
- Inspect the sender and destination separately. A sender domain that differs from the visible link domain is an impersonation warning; an external or altered recipient address adds further concern.
- Keep payment and delivery inside the platform. Do not enter marketplace credentials, card details or personal information on the linked page, and do not pay a delivery request introduced only by email.
- Verify independently. Contact the marketplace or parcel provider through its official website or account—not through details in the message.
- Report and remove it. Use the marketplace’s reporting route and your email provider’s phishing control, then delete the message.
If you already responded
- Change any exposed marketplace or email password from the official site and enable multifactor authentication.
- Contact the card issuer immediately if payment details were entered or a charge was approved.
- If the PDF was opened or downloaded, disconnect the device from sensitive accounts and run its built-in security scan.
- Review marketplace messages, email forwarding rules, recent logins and transactions for unauthorized changes.
Most common warning signals
- The message carries a warning that it came from an external email address.
- A clickable delivery link is used to push parcel-related action.
- The message includes a specific tracking code and an attached PDF.
- The sender domain differs from the domain displayed in the visible link.
- The recipient address appears external, altered or otherwise unusual.
- The visible delivery link uses www.uschovna.cz while the sender uses another domain.
What to do now
- Do not click the delivery link or open the attached PDF.
- Open the marketplace independently and verify the order and tracking code.
- Compare the sender domain with the visible link domain.
- Report the message through the marketplace and email provider.
- Change exposed passwords and contact the card issuer if details were submitted.
Further reading
- Safe Marketplace Transaction Checklist
- Safe Parcel Delivery Verification Guide
- Impersonation Scam Prevention: Verify Before Acting
FAQ
Does a specific tracking code make the delivery email genuine?
No. A tracking code can be copied or invented. Confirm that the same code and order appear inside the marketplace account opened independently.
What should I do if the link shows www.uschovna.cz?
Do not use the link. Open the marketplace and delivery provider independently; a mismatch between the sender domain and visible link domain is a phishing warning.
Is it safe to open the attached parcel PDF?
Do not open it. Verify the order inside the marketplace, report the email as phishing and delete it; if opened, run the device’s built-in security scan.