Skip to main content

Business communications - SMS and telephone best practice

How to ensure your organisation's SMS and telephone messages are effective and trustworthy.

istock.com/marchmeena29

This guidance will help you protect your customers from fraud by ensuring that your SMS and telephone messages are consistent, trustworthy, and reach your target audience without being blocked or deleted as suspicious.

Implementing this guidance will also make it harder for criminals to exploit telecoms channels. By minimising the complexity of any given service, it will help authorities to be more focussed and efficient in detecting and preventing fraud across telecoms networks.

Note

This guidance covers SMS and telephone messaging only. System administrators who want to secure their organisation’s email systems should refer to the NCSC’s guidance on email security and anti-spoofing. Information for consumers about spotting fraudulent messages can be found on the NCSC’s report a scam call page.




Due diligence regarding SMS suppliers

You should familiarise yourself with the NCSC’s guidance on Protecting SMS messages used in critical business processes.

Before you start putting SMS services in place, ensure you know the answers to the following questions:

  1. Do you plan to use SMS at all? If so, who is the SMS supplier, and what other organisations are in their supply chain?
  2. Does the service need two-way communication?
  3. What SenderID, if any, do you propose to use? 
    Note: SenderID does not support two-way SMS, and is not supported in every country.
  4. Are you planning to include links?
    Note: some countries are now preventing the use of links in messages.
  5. Are you planning a bulk SMS campaign?
  6. Finally, is the message price lower than market rates or too low to be true? If it is, the supplier may be using 'grey routes' or other routing techniques which can result in a customer data compromise and/or poor customer experience.

You should ensure your suppliers:

  • follow the principles of the A2P Code of Conduct and ensure this is included in your contracts
  • are transparent and willing to share all of their downstream providers
  • take an active part in the MEF Registry (a cross-sector trade body initiative that combats smishing and spoofing)
  • provide data on the routing of the SMS (without this it is impossible to distinguish between legitimate and fraudulent SMS)

You should also make sure that suppliers are required to tell you when they change provider and give you adequate notice of this change. When using a shortcode, you should make sure that it is only used for your messaging purposes, and that you can port that number to another operator.

You should try to find a service provider who is as close to the mobile operators as possible. The more suppliers between you and the mobile operator, the more that can go wrong, including the loss or manipulation of customer data. It also becomes harder to investigate any problems.

If you cannot find details on the supplier's website which answer these questions, ask them directly. If they won't answer, these are grounds for concern.

SenderID considerations

Take care when selecting your SenderID. Ideally you should choose a SenderID that reflects your brand and avoid generic SenderIDs such as 'Alert’ or 'NoReply’.

Note that it’s difficult to differentiate between certain characters (for example the letter ‘o' can look like the number zero ‘0'), especially on a small screen. This is often exploited by criminals who use 'similar looking' SenderIDs. It is worth noting that special characters (ie non-alphanumeric characters such as ! and *) can often result in strange behaviours, so you should avoid using them.

Unicode can be useful if you are communicating in other languages or when using emojis, but it can inflate the number of messages being sent.

SMS guidance

To summarise the key messages from this section:

  • Understand your communications supply chain. Using fewer providers makes the whole process easier to manage.
  • Audit your messages. Validate that the messages are received exactly as you sent them. Any changes to the content or message sender are indicators that your message provider is using grey routes, putting your messages at risk of fraud, delay, or even regulatory breach. The MEF Registry can also help you with auditing your supply chain.
  • Include clauses in your contracts to cover full transparency of the supply chain and clauses enabling you to withhold money if fraud is suspected.
  • Avoid using links in messages. Where this is absolutely necessary, we recommend using simple, human-readable links, such as gov.uk/coronavirus. You should not use URL shortening services. Note that some countries are now blocking links in messages.
  • Ensure links are consistent in ALL messaging, making it easier for people to check them independently.
  • Be careful when choosing a SenderID. Keep the number of SenderIDs to a minimum. Avoid special characters, and ensure the SenderID is added to the MEF Registry.





Published

Reviewed

Version

2.0