SCAM: YES

Risk:High — A parcel-themed marketplace message can use a tracking code, PDF and mismatched domains to steal credentials, collect payments or deliver malware.

Install the app:Open the app and verify suspicious content in one scan.

Safe Marketplace Transaction Checklist for Families

When this checklist applies

Use this safe marketplace transaction checklist when a buyer, seller or supposed delivery service sends a tracking code, attached PDF or clickable delivery link. Treat the message as high risk when it carries an external-email warning, alters the recipient address or shows different sender and link domains. A typical message in this wave says a parcel is awaiting action, supplies a specific tracking code, attaches a PDF and asks the recipient to follow a delivery link. The visible link may show `www.uschovna.cz` even though the sender uses another domain. Explain it simply to your relative: “A real-looking tracking code does not prove who sent the message. We will check the order inside the marketplace instead of using this link or PDF.”

Decision steps in order

  1. Stop before opening anything. Tell your family member not to click the delivery link, open the PDF, reply or forward the attachment.
  2. Check the actual marketplace account. Open the marketplace from a saved bookmark or type its known address manually, then look for the order, buyer conversation and delivery status.
  3. Compare transaction details. If no matching order or tracking code appears inside the account, treat the message as phishing.
  4. Inspect the sender and destination separately. A sender domain that differs from the visible link domain is an impersonation warning; an external or altered recipient address adds further concern.
  5. Keep payment and delivery inside the platform. Do not enter marketplace credentials, card details or personal information on the linked page, and do not pay a delivery request introduced only by email.
  6. Verify independently. Contact the marketplace or parcel provider through its official website or account—not through details in the message.
  7. Report and remove it. Use the marketplace’s reporting route and your email provider’s phishing control, then delete the message.

If you already responded

Most common warning signals

What to do now

  1. Do not click the delivery link or open the attached PDF.
  2. Open the marketplace independently and verify the order and tracking code.
  3. Compare the sender domain with the visible link domain.
  4. Report the message through the marketplace and email provider.
  5. Change exposed passwords and contact the card issuer if details were submitted.

Install ScamBuster AI

Open the app and verify suspicious content in one scan.

Install ScamBuster AI

Further reading

FAQ

Does a specific tracking code make the delivery email genuine?

No. A tracking code can be copied or invented. Confirm that the same code and order appear inside the marketplace account opened independently.

What should I do if the link shows www.uschovna.cz?

Do not use the link. Open the marketplace and delivery provider independently; a mismatch between the sender domain and visible link domain is a phishing warning.

Is it safe to open the attached parcel PDF?

Do not open it. Verify the order inside the marketplace, report the email as phishing and delete it; if opened, run the device’s built-in security scan.