Receiving a voicemail or text saying that your package cannot be delivered can be concerning, especially when the message claims there is a problem with your address and gives you a short deadline to fix it. Recently, messages have been directing recipients to unfamiliar websites including Fedexfy, Fedexpy, Fedexmp, and Fedexgw.
So, are these websites and the related FedEx voicemail messages legitimate? FedEx is a legitimate delivery company, but these particular websites and notifications raise significant phishing and security concerns. If you receive one, do not assume that the message is really from FedEx simply because it uses the FedEx name.
The reported messages follow a fairly simple pattern. You receive an automated call or text saying that a package is currently being held because something is wrong with the delivery.
The explanation may involve:
The website mentioned in the message may be one of these:
At first glance, this may sound like a normal delivery problem. However, several details deserve closer attention.
One example of the voicemail is:
"Hi there, Celine speaking... Because there may be an issue with the delivery address of your package.
Hello, this is a delivery notification.
We are contacting you because there may be an issue with the delivery address of your package. Please visit the website, Fedexfy [Fedexpy, Fedexmp, or Fedexgw] before [date] to verify your order or delivery information.
If not processed by the deadline, the package will be returned to the sender."
The official FedEx website is fedex.com. The domains listed above are different domains. They are not simply pages located under fedex.com. This is important because a website can include the name of a legitimate company without being operated by that company.
FedEx itself warns consumers about suspicious websites and altered website addresses. Its fraud guidance specifically identifies misspelled or slightly changed addresses as warning signs and advises people to verify information through legitimate FedEx channels.
For example, a criminal does not necessarily need to create a website called "totally-fake-delivery.com." A much more convincing approach is to create a domain containing a recognizable brand name and then use it in a message that looks like a genuine delivery notification.
That is why the presence of FedEx in a domain should never be considered proof that the site belongs to FedEx.
Large logistics companies generally have established web infrastructure for tracking shipments and providing customer services. When recipients are instead sent to several unfamiliar domains such as Fedexfy, Fedexpy, Fedexmp, or Fedexgw, that creates an important verification issue.
The domains are also visually designed to make the FedEx name appear familiar while adding different letter combinations. This kind of domain variation can be particularly effective in phishing because someone reading a voicemail quickly may hear "Fedexfy" and mentally register only "FedEx."
The safest rule is simple: Do not judge a delivery website by how closely its name resembles FedEx. Check the actual domain.
Delivery problems can happen for genuine reasons, but legitimate carriers generally provide shipment updates through their official tracking systems.
In comparison, messages linked to unfamiliar URLs may create unnecessary pressure by claiming you have only a short time to act or risk having your package returned or lost. This sense of urgency can push people to respond quickly without taking the time to verify whether the message is genuine.
Another warning sign associated with these types of delivery campaigns is a request for a small payment. For example, the website might claim that you need to pay:
A small amount can make the request feel harmless. Someone might think, "It is only two dollars, so why not pay it?" But the amount is not the main issue. The important question is where you are entering your payment information and why you were directed there in the first place.
A suspicious page may request your card number, expiration date, CVV, name, address, email address, or phone number.
A request for a small payment through an unsolicited message or unfamiliar third-party website is a major warning sign. If legitimate fees, duties, or other charges are involved, verify them independently through the carrier's official website, account portal, or verified invoice rather than paying through a link provided in an unexpected message.
Publicly available WHOIS data reveals that many of these alternative "FedEx" variations are registered very recently, often just days or weeks before the voicemail campaigns begin.
A recently registered, short lived domain would be unusual for a major logistics company's established tracking and customer service infrastructure. When that is combined with brand impersonation and unsolicited delivery messages, it becomes an important warning sign.
If you really are expecting a package, there is no need to use the link provided in the voicemail.
Instead:
Go directly to FedEx:
Close the message and open your browser yourself. Type fedex.com into the address bar and check the shipment using your tracking information. Do not copy and paste the suspicious website address into your browser.
Check Where You Bought the Product:
If you recently purchased something online, log in directly to the retailer or marketplace where you placed the order. Check your order history and shipment status there.
Use the Official FedEx App:
If you use FedEx services regularly, use the official FedEx mobile application obtained through an authorized app store. This gives you another way to check shipment information without relying on the suspicious message.
Never Enter Card Details on an Unverified Website:
If Fedexfy, Fedexpy, Fedexmp, Fedexgw, or another unfamiliar website asks for your card number, expiration date, and CVV code to process a "delivery adjustment", do not enter it.
Although these alternative websites may look similar to legitimate corporate pages, their unusual URLs, questionable behavior, and unexpected payment requests raise serious security concerns. The safest approach is to remain cautious, avoid clicking unverified links, and use only the official and trusted channels provided by the company.
The biggest mistake is assuming that a message is legitimate because it mentions a real company.
Other mistakes include:
Remember, a convincing logo or familiar brand name can be copied.
Based on the publicly available information and the warning signs identified in these messages, the overall pattern is consistent with a phishing campaign designed to make recipients act quickly. The unfamiliar domains, urgent delivery claims, and requests for immediate action or payment are all reasons to exercise extreme caution.
FedEx's official website is fedex.com, so external domains such as Fedexfy, Fedexpy, Fedexmp, or Fedexgw should not be assumed to be connected with the legitimate company. If a message directs you to one of these websites and asks you to verify information or make a payment, do not use the provided link. Instead, verify your shipment directly through fedex.com or another official FedEx channel. This is the safest way to determine whether there is a genuine delivery issue without exposing your personal or financial information.
The information in this article is provided for educational and awareness purposes. Company names, phone numbers, sender names, and other details referenced may have been impersonated, spoofed, or otherwise misused by scammers. Their appearance in this article does not necessarily identify the legitimate company, owner of a phone number or account as being involved in fraudulent activity.
This article has been written by a Scam Fighter Contributor, De-Reviews.com Team. If you believe the article above contains inaccuracies or needs to include relevant information, please contact ScamAdviser.com using this form.
De-Reviews.com Team is a group of scam researchers, editors, and online safety advocates dedicated to exposing online fraud and helping consumers stay safe online. The team has been investigating scams, fraudulent websites, phishing campaigns, and other online threats since 2014. Read the Full Author Profile.