• 3 mins read
  • Published

Mobile operators to block unregistered business SMS in Spain

Lara Carter RUSSPAIN.com

Post by Lara Carter

Mobile operators to block unregistered business SMS in Spain RUSSPAIN.com © russpain.com
Mobile operators to block unregistered business SMS in Spain © russpain.com

From September 2026, Spanish mobile operators will block SMS, MMS and RCS messages from businesses that use unregistered brand names as sender. The move aims to curb fraud and protect consumers, with no action required from the public.

Starting 15 September 2026, any business sending SMS, MMS, or RCS messages to Spanish numbers with a brand name as the sender must have that alias officially registered. If not, mobile operators will block the messages. The CNMC confirmed the measure, which is meant to cut down on brand impersonation scams.

This rule covers more than just banks and insurers. Retailers, delivery companies, transport services, and public agencies are all included if they use a brand name instead of a phone number in the sender field. It applies to any message sent to a Spanish number, no matter where the company is based.

Spain is among the first EU countries to implement a nationwide mandatory registration system for SMS sender aliases, aiming to set a new standard for anti-fraud measures in telecommunications.

The key change is the requirement to register every alias—the alphanumeric name that appears as the sender. Fraudsters have used this feature to send fake notifications or codes that look like they come from trusted brands. By forcing registration and linking each alias to an authorised business and provider, authorities hope to make impersonation much harder.

According to the CNMC, more than 75,000 registration requests were submitted in the first two months after the system opened. Businesses that miss the deadline will have their branded messages blocked at the network level. Even registered companies will see their messages stopped if they use unauthorised providers.

According to a recent report by the European Union Agency for Cybersecurity (ENISA), SMS phishing (smishing) attacks have increased by over 30% across Europe in the past year, prompting regulators in several countries to consider stricter controls on business messaging.
European Union Agency for Cybersecurity (ENISA)

For consumers, nothing changes in terms of registration or payment. No action is needed from the public. If a message arrives asking you to register or click a link to comply with the new rules, treat it as suspicious. The only visible difference may be that some messages show a phone number or technical ID instead of a brand name if the sender is not properly registered.

This system will make brand impersonation via SMS aliases much harder, but it is not a complete solution. Criminals can still use regular numbers, malicious links, or other channels to target people. The CNMC advises never to share passwords, codes, or banking details in response to unexpected messages, and to use official apps or websites for sensitive transactions.

The legal basis for the change is set out in Order TDF/558/2026 and Circular 2/2026, which explain the registration process and allow companies to regain their alias if they register after the deadline. If a familiar notification stops arriving, it is up to the business and its providers to fix the issue and restore authorised messaging.

With the deadline approaching, Spanish businesses need to register their aliases or risk losing a key way to reach customers. For consumers, the change adds a layer of protection, but staying alert remains important. Whether these technical barriers can keep up with new fraud tactics remains to be seen.

Also read