TwitterLinkedInFacebook skip to content

SECTION 04

Spam, Phishing, and What We See at the Network Layer

This section is the one I want every CSP support engineer, brand marketing director, and messaging compliance officer to read at least once. The 10DLC ecosystem spends an enormous amount of energy on spam and phishing prevention, and most of that energy is invisible to the people whose campaigns are affected by it. Understanding what is happening behind the scenes, what gets caught, what does not, and what triggers what, is the difference between a campaign that delivers reliably and one that mysteriously underperforms.

This section covers the categories of unwanted messaging, how detection works, what your campaign can do to stay clear of filters, and what to do when legitimate traffic gets caught.

The categories of unwanted messaging

Not all unwanted messaging is the same. The 10DLC framework, the carriers, and the broader anti-abuse industry think about several distinct categories:

Unsolicited commercial messaging (UCM)

Messages sent to consumers who did not opt in. The clearest definition of "spam" in the messaging context. This is what happens when a sender uses a list they did not collect, scrapes phone numbers from a directory, or sends to numbers that opted in to a different sender.

UCM is the easiest category to detect because it has clear behavioral signatures: messages going to numbers that have no prior engagement with the sender, recipients who report messages as unwanted, traffic patterns that look like blasts to large lists.

Phishing and smishing

Phishing is the deceptive practice of trying to get a consumer to take an action, like clicking a malicious link, calling a fraud number, or providing credentials, by impersonating a trusted entity. "Smishing" is the SMS-specific version.

Phishing patterns are well-known: fake bank fraud alerts, fake delivery notifications with "click here to track," fake account suspension warnings, fake IRS or CRA notices. The carriers and DCAs have signature databases that catch many of these in real time.

What makes phishing detection hard is that legitimate messages can look like phishing if they are poorly written. A real bank fraud alert and a fake bank fraud alert can both contain the words "unusual activity" and a link. The filter has to differentiate, and it sometimes gets it wrong in both directions.

SHAFT-C violations

Content prohibited under the carrier-wide rules: sexually explicit content, hateful content, alcohol, firearms, tobacco, and cannabis. Some categories are flatly prohibited, others are restricted with age-gating requirements, and the rules are consistent across the carriers.

Snowshoe messaging

Snowshoeing is when a sender spreads their traffic across many phone numbers to evade per-number rate limits or reputation systems. Each number sends a small amount of traffic, but the aggregate is enormous. The pattern is named after snowshoes, which spread weight across a large surface area.

Carrier and DCA monitoring tools specifically look for snowshoeing patterns. Many numbers, low volume per number, similar content, similar destinations, similar timing. When the pattern is detected, the entire group gets flagged together.

Grey route attempts

Grey routing refers to attempts to send A2P traffic over routes that are not sanctioned for A2P. Historically, this meant trying to push business messaging through P2P channels to avoid registration requirements or carrier termination fees. As mentioned earlier, the U.S. ecosystem has substantially shut these paths down. Detection looks for high-volume programmatic traffic on numbers that should not be carrying it, and for sudden patterns of A2P-style content emerging on numbers with P2P traffic profiles.

Number spoofing and impersonation

Number spoofing is sending messages that claim to come from a number other than the actual sending number. Within the regulated 10DLC system, true spoofing is increasingly rare because the framework establishes accountability through registered numbers. Spoofing attempts get caught at the network layer.

Brand impersonation is a related issue: messages that claim to be from a well-known brand without authorization. Detection is harder than for technical spoofing, but pattern-based and content-based detection catches a substantial portion.

How detection works

Detection happens in layers. Each layer has its own techniques and its own visibility.

CSP-level filtering

CSPs apply the first layer of filtering. They look at the content of messages being submitted by their customers, scan for obvious red flags, and reject messages that fail. They also enforce their customers' campaign registrations. If a customer registered for Account Notifications and starts submitting marketing content, the CSP can flag the drift.

DCA-level filtering and rule-making

DCAs (us, in the case of Syniverse) apply the next layer. We see the actual traffic flowing toward the carriers. We can correlate patterns across multiple CSPs and Brands. We have visibility into what gets accepted and rejected at the carrier layer, and we use that visibility to inform our own pre-filtering.

We do more than monitor. We actively help create and operationalize the rules that block spam. Working with the carriers and the broader industry, we develop detection patterns, content rules, and behavioral signals that catch unwanted messaging before it reaches consumers. When the industry identifies a new spam pattern, that pattern gets translated into detection logic that runs at the DCA layer and propagates upstream.

DCA filtering catches patterns that individual CSPs may not see because they do not have the cross-CSP view: snowshoeing across multiple CSPs, grey route attempts, content drift across many campaigns, repeat offenders re-registering under different Brand names.

Carrier network filtering

The carriers run the most sophisticated and opaque filtering layer. They have visibility into every message attempting to enter their networks, signature databases of known abuse patterns, machine learning systems trained on years of consumer complaint data, and behavioral models of what legitimate traffic looks like.

The carriers do not publish exactly what they filter on. This is by design. Adversaries who knew exactly what triggered detection could optimize around it. The result is that some legitimate campaigns get caught by filters in ways that are hard to predict, and "diagnostic" requests to figure out exactly what triggered a filter are usually unanswered.

Consumer reporting

The final detection layer is consumers themselves. Every major carrier has a mechanism for consumers to report unwanted messages, including reporting to 7726 (which spells "SPAM" on a keypad). Mobile operating systems also have built-in spam reporting that flows back to the carriers.

When consumers report messages, those reports inform carrier filtering models. A campaign that generates spam reports, even legitimate-but-perceived-as-unwanted campaigns, accumulates a negative reputation that affects future delivery.

This is one of the most important things to internalize about the system: even legitimate campaigns can be hurt by consumer perception. A consumer who signed up for marketing texts and then forgot they signed up reports the next message as spam. The system does not know the consumer forgot. It just sees a spam report. Enough of those add up to filtering.

What makes a campaign vulnerable to spam filtering

Beyond the obvious (do not send actual spam), there are specific patterns that increase the risk of legitimate campaigns being caught by filters:

Generic, brand-less sample messages. "Your appointment is at 2pm" is harder to distinguish from a phishing attempt than "[Acme Plumbing] Your appointment is at 2pm." Always include the Brand name in the message.

Public URL shorteners. Always use branded short domains. Detection systems have entire databases of public shortener domains and treat them as risk signals.

Vague calls to action. "Click here for more info" is a phishing pattern. "Click here to view your shipping update at acme.com/track/[id]" is contextual and lower-risk.

Suspicious-looking URLs. Domains that resemble legitimate brands, URLs with lots of subdomains and query parameters, URLs to IP addresses instead of domains. All are filter triggers.

Inconsistent sending patterns. Bursting traffic to many recipients in a short window, then silence, then more bursts. Looks like blasts to a list.

Content that closely matches known phishing templates. Generic fraud alerts, generic delivery notifications, generic account verification messages. Even if your version is legitimate, the template is what the filter recognizes.

Cross-campaign content overlap. If multiple campaigns from different Brands are sending nearly identical content, that pattern looks like coordinated abuse to detection systems.

Frequency mismatches. Sending more messages per consumer per day than the registration claimed.

Recipient patterns. Messages going to numbers that have no prior engagement with the Brand, going to large numbers of recently-ported numbers, going to numbers in patterns that suggest list-buying.

The fix for all of these is the same: be the legitimate sender you say you are, send the content you registered, send to the audience you collected opt-ins from, and do not try to game the system.

What to do when legitimate traffic is filtered

This happens to good campaigns. Filtering is not perfect. Legitimate messages get caught. The diagnostic process:

Confirm the issue is filtering, not provisioning. First, make sure the campaign is properly registered, the numbers are properly associated, and the basic delivery infrastructure is healthy. A campaign that "is not delivering" might just have a number-association problem that has not been fixed.

Look at delivery patterns by carrier. If delivery is fine on three carriers and bad on one, the issue is carrier-specific filtering on that one carrier. If it is bad on all four, the issue is more upstream.

Look at delivery patterns by recipient. If certain recipients consistently do not receive messages, those numbers may have personally blocked the sender, may be on do-not-message lists, or may be on networks that have suspended your campaign.

Check for content patterns. Did the message content change recently? Was a new URL added? Did the campaign start including a phone number, an embedded link, or other attribute that was not there before?

Review consumer complaint indicators. Has the campaign generated more consumer reports than usual? Has the opt-in flow changed? Are consumers receiving messages they do not remember signing up for?

Escalate through your CSP. If the issue persists, your CSP can escalate to the upstream CNP/DCA. The DCA can sometimes provide more visibility into what is being filtered and why. We can sometimes engage with the carrier on the customer's behalf.

What is important to know: there is not always a satisfying answer. Some filtering decisions happen at the carrier level for reasons that even DCAs cannot fully see. The right move is usually to clean up the campaign on the things you can control, like content, opt-ins, and frequency, and let the campaign rebuild reputation over time.

The honest summary

Anti-abuse infrastructure is a major part of what makes 10DLC work as a sanctioned channel. Without it, the channel would be overrun with spam and phishing in months, and the carriers would shut it down. With it, the channel is increasingly clean and increasingly reliable for legitimate senders.

The cost of that infrastructure is that legitimate senders sometimes get caught in filters. The benefit is that the senders who follow the rules get a high-quality, high-reputation channel to reach their customers.

The way to win in this environment is to be the sender that the system is designed to reward: clean opt-ins, accurate registrations, content that matches what was registered, branded URLs, real contact information, fast STOP processing, and engagement frequencies that match what consumers expected when they signed up.

Do those things and the anti-abuse machinery is your friend. It is keeping the bad actors out of the channel you are trying to use, and it is helping the carriers maintain trust in the messages they deliver. Skip those things and the same machinery becomes an adversary.

RELATED SECTIONS