Back to The Local Vocal
The Local VocalMedium
PhishingNZ Post
Email
Medium risk PhishingEncountered ViaEMAIL 4 August 2026
RegionOtago

If you want your parcel, you better pay the redelivery fee.

A high-fidelity phishing campaign impersonating NZ Post is targeting New Zealand organisations with fraudulent 'Redelivery Fee' invoices via mass-hosting infrastructure.

A sophisticated phishing campaign has been detected impersonating NZ Post, specifically utilizing 'Redelivery Fee Invoice' lures. The messages originate from the infrastructure of a global mass-hosting platform (nxcli.io), which allows the campaign to bypass many traditional reputation-based security filters. Technical analysis indicates that the messages failed SPF, DKIM, and DMARC authentication, yet they are systematically reaching New Zealand inboxes due to the high reputation of the underlying hosting nodes.

The email body employs extremely high-fidelity NZ Post branding, including accurate color palettes, official logos, and a professional layout. The lure is designed to create a sense of operational urgency by notifying users of a pending NZD 8.50 fee for a second delivery attempt. This 'Micro-Transaction' technique is a deliberate social engineering tactic to bypass financial skepticism, as users are more likely to interact with low-value charges in the hope of resolving a simple delivery issue.

Attackers are using this wave to harvest both organisational login credentials and sensitive payment card data. The campaign specifically targets the common business workflow of managing international and domestic courier deliveries, relying on the high volume of legitimate logistics mail received by New Zealand organisations to remain undetected.

Organisations are advised to treat any unsolicited logistics notifications with clinical skepticism. Legitimate NZ Post tracking and payment updates should be verified strictly through the official nzpost.co.nz portal or the mobile application. Enforcing strict 'First Contact' safety tips and encouraging users to utilize the 'Report Phishing' mechanism remain the most effective methods for refining tenant-level security against these mass-hosting infrastructure abuses.

Email authorisation
SPF
fail
DKIM
fail
DMARC
fail
COMPAUTH
pass
Domain authentication
Sender / From domain
91a9ae6505.nxcli.io
Domain age
3165 days old
Email Sample
Email Sample screenshot
Domain Reputation
Abuse score
75/ 100High abuse
ISP (Internet Service Provider)
Nexcess / Liquid Web
Function:Automated Retail Lures
Reputation:Flagged / Mass Hosting
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Do not interact with links in unsolicited logistics or redelivery notifications.
  • Verify parcel status strictly via the official NZ Post tracking portal or mobile application.
  • Apply tenant-wide domain blocking for the *.nxcli.io infrastructure to prevent further delivery.
  • Educate staff on the risks of 'Micro-Transaction' social engineering lures.
NZ Post logo
Is it real?
Got an email from NZ Post?

See what a genuine NZ Post message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing