Country-specific SMS Sender Verification Requirements
Before you can start sending SMS through Sender to certain destinations, your sender must be verified with the relevant provider and, in some countries, approved under the local framework. Requirements differ depending on where you are sending and what type of sender you use.
This guide covers the four areas with the specific requirements:
- United States & Canada – Toll-free number verification (via our provider, Telnyx)
- Australia – Alphanumeric Sender ID registration (via our provider, Twilio)
- France – Alphanumeric Sender ID authorization (via our provider, Twilio)
- Spain – Alphanumeric Sender ID registration under the CNMC Alias Registry (via our provider, Twilio)
For all of these, the fastest route to getting verified is to prepare the required information and documents in advance, then get in touch with our support team so we can submit your request. These requirements come from the mobile carriers and regulators, and incomplete submissions are commonly rejected — so accuracy matters more than speed.
Please note: Rules in this area change frequently and are set by carriers and regulators, not by Sender. The details below were accurate at the time of writing (effective dates are included where known). If anything has changed by the time you apply, our support team will guide you through the current process.
United States & Canada – Toll-Free Verification
To send SMS to US and Canadian phone numbers using a toll-free number, that number must be verified before messaging is allowed. We use Telnyx as our provider for toll-free numbers, and Telnyx applies strict carrier requirements to the entire verification process.
Everything below is submitted through the dedicated toll-free verification form in your Sender dashboard. Complete every field accurately and consistently — the majority of rejections come down to a small number of avoidable issues, listed next.
The most common reasons submissions are rejected
Focus your attention here first. In roughly the order they cause problems:
- The business can’t be verified. Carriers must be able to confirm you’re a real, identifiable business. This is the single most common cause of “Waiting for Customer” and rejections. It happens when the website is inaccessible or thin, a free email (e.g. Gmail) is used instead of a business-domain address, the contact is a department name rather than a real person, or the business name / website domain / email domain / account domain don’t match each other.
- The content isn’t eligible. Some content is permanently barred (see the prohibited list below). This is critical: a bad opt-in or a typo can be fixed and resubmitted, but an ineligible-content rejection is usually final and cannot be appealed. Check your use case is allowed before you invest time in the application.
- The submission isn’t internally consistent. The use cases you select, your sample messages, and your opt-in form must all align. Every use case that appears on your opt-in form must also be declared in the verification request, and your sample messages must match those use cases.
- Consent (opt-in) is missing, insufficient, or shares data with third parties. Covered in detail below — this is where the opt-in form, disclaimer, and checkbox structure matter.
- URL hygiene. Public URL shorteners (e.g. bit.ly) and non-secure (HTTP) links are flagged. Use a branded, HTTPS URL.
Fixable vs. final: Most rejections (business info, opt-in, URLs, missing justification) are eligible for resubmission once corrected. A handful — SHAFT/prohibited content, known spam/phishing, fraud, deceptive marketing — are not eligible. Knowing which is which saves wasted effort.
1. Business identification (get this right first)
- Legal business name — your business name, website domain, and email domain should match. If they differ, explain why in the additional information field.
- Business website (or social media page) — it should clearly show your business name, contact information, products/services, an About page, a Contact page, and links to your Privacy and Terms pages. The site must be live and accessible when carriers review it.
- Business email address — on the same domain as your website. Free email addresses (e.g. Gmail) can cause a decline.
- Business address — a valid business address
- Business contact — a real person’s first and last name (not a department), plus a contact number for the business (not the toll-free number being verified)
2. Business Registration information (mandatory)
As of February 17, 2026, three Business Registration Number (BRN) fields are required for all new toll-free submissions. Requests missing them are rejected, so have these ready:
- Business Registration Number — a government-issued identifier. Examples: EIN in the US (
12-3456789), CRA Business Number in Canada. - Business Registration Type — e.g.
EIN,CRA,Companies House,ABN,VAT. (US sole proprietors without an EIN can use their SSN with typeSSN.) - Business Registration Country — the ISO two-letter country code of the issuing authority (e.g.
US,CA,GB).
3. Messaging details (keep these consistent with your opt-in)
- Use case — the purpose of your messaging (examples: 2FA, account notifications, appointments, billing, order notifications, general marketing, fraud alerts, conversational). If mixed, choose “Mixed” and describe each. Every use case on your opt-in form must appear here.
- Use-case summary — the message types, the intended audience, and your compliance measures
- Sample message(s) — a realistic example for each use case you selected; samples must match your stated use cases and opt-in
- Estimated monthly message volume
4. Content eligibility — prohibited content
Certain content is not eligible for toll-free messaging and generally cannot be appealed: SHAFT content (Sex, Hate, Alcohol, Firearms, Tobacco/Vape, Marijuana/CBD), loan soliciting/promotion, third-party debt collection, gambling/sweepstakes, stock/crypto/high-risk investment alerts, debt reduction or credit repair, third-party lead generation, and any federally illegal substances. Confirm your use case is allowed before applying.
5. Opt-in — how consent is collected
You must clearly document how recipients consent. There are four accepted opt-in methods, each needing its own evidence:
- Digital (web form) — provide the URL, or a screenshot showing as much of the branded opt-in form as possible, and explain how subscribers reach it
- Paper — provide a link to the uploaded branded form and explain how subscribers receive it
- Verbal — provide the exact script subscribers hear, and explain where/how they opt in (e.g. the phone number they call)
- Inbound message — provide the phone number subscribers text and explain how they learn it
If you don’t have a link (for example, verbal consent), point to a publicly accessible Google Doc or Dropbox file that diagrams the opt-in.
Required disclaimer. With every method, subscribers must see the following before the first message (for inbound-text opt-ins, it can appear in the first message):
You are subscribing to [brand name] for [transactional or marketing] messages. Reply STOP to opt out. Reply HELP for help. Standard message and data rates may apply. Message frequency may vary. View our Terms and Conditions [link]. View our Privacy Policy [link].
Checkbox rules (strict — common rejection causes):
- The opt-in form must be branded with the same business name being registered, and the business name must appear in the message content.
- Checkboxes must be unchecked by default and optional — consent to messaging cannot be a condition of receiving your service.
- SMS opt-in and Privacy Policy acceptance must be two separate checkboxes. (Combining them is no longer allowed.)
- SMS consent must be separate from email consent — distinct checkboxes.
- If marketing is a use case, marketing consent must have its own checkbox, separate from transactional consent.
Example of compliant separate checkboxes:
[Checkbox 1 – transactional] By checking this box and submitting this form, you consent to receive transactional text messages for [use case] from [Company]. Reply STOP to opt out. Reply HELP for help. Standard message and data rates may apply. Message frequency may vary. View our Terms and Conditions [link]. View our Privacy Policy [link].
[Checkbox 2 – marketing] By checking this box and submitting this form, you consent to receive marketing text messages from [Company]. Reply STOP to opt out. Reply HELP for help. Message and data rates may apply. Message frequency may vary. View our Terms and Conditions [link]. View our Privacy Policy [link].
6. Opt-out
Recipients must be able to unsubscribe by replying STOP at any time, stated in your disclaimer and messages (alongside HELP for assistance). For Telnyx toll-free numbers, the opt-out keyword is STOP, and the resume keywords are START and UNSTOP. Honor opt-outs promptly.
7. Privacy Policy — required wording
Your published Privacy Policy must be linked from the opt-in form and must include a statement to the effect of:
We will not share or sell your mobile information with third parties for promotional or marketing purposes.
Opt-in language that shares consent data with third parties is an explicit rejection reason. Link your Terms and Conditions from the opt-in form as well.
Special cases
- Marketing age-gated content — if you market anything not legal to consume under a certain age in any US state (e.g. alcohol), your opt-in form or website needs an age gate that asks for date of birth (not a Yes/No), blocking anyone underage. If you won’t promote such content over SMS, state that in the submission instead.
- Political use case — political consent needs its own separate checkbox (if mixed), you must state whether donations will be solicited, and the Privacy Policy must explicitly state that no mobile information will be sold or shared for promotional/marketing purposes.
- Charity / fundraising — use the Fundraising use case, add a separate fundraising checkbox mentioning that donations will be solicited, and note the same in your use-case summary.
Canadian toll-free numbers require double opt-in
Canadian toll-free numbers must meet all of the above plus collect double opt-in: after the initial opt-in, a confirmation message is sent and the subscriber must reply to affirm they are subscribing.
Timeline
Toll-free verification approvals are typically around 5 business days, though this varies with the carrier review queue and how complete your submission is. Unverified toll-free numbers have limited throughput and may be filtered, so verify before you rely on the number. Most rejections can be corrected and resubmitted.
What to do
Complete the toll-free verification form in your Sender dashboard with all of the above. If you’re unsure about any field — especially business verifiability or whether your use case is eligible — contact our support team before submitting so we can help you avoid a rejection-and-resubmit delay.
Australia – Alphanumeric Sender ID Registration
For countries outside the US and Canada, we use Twilio as our alphanumeric Sender ID provider. Australia has some of the most demanding requirements, because of a new regulatory framework.
What’s changing
Australia has introduced the SMS Sender ID Register, overseen by the ACMA (Australian Communications and Media Authority) under the Telecommunications Act 1997. From July 1, 2026, Sender IDs used in messages to Australian recipients need to be approved on this register. Messages sent with a Sender ID that hasn’t been approved may be labelled “Unverified” to recipients.
Because of this, registering an Australian Sender ID requires more documentation than most countries. Please get in touch with us and have the following prepared so we can guide you through Twilio’s registration and submit on your behalf.
Step 1 – Download and complete the Letter of Authorization (LOA)
Download the LOA form and fill out the highlighted (yellow) sections completely — replace each highlighted field with your own information — then send it back to us as a PDF attachment, along with the other documents below.
Download the LOA form here: LOA form
Step 2 – Provide a business registration number
Send us one of the following, matching the entity that owns the Sender ID brand:
- Australian Business Number (ABN)
- Australian Company Number (ACN)
- Australian Registered Body Number (ARBN)
- Indigenous Corporation Number (ICN)
- Corporate registration in the country in which you are incorporated (if you are not an Australian entity)
Tip: If you have an ABN, make sure your details on the Australian Business Register (ABR) are up to date — including your authorized representative’s details — as this helps the registration go through faster.
Step 3 – Provide your use-case details
We also need the following for the verification:
- Average SMS messages per month
- Description of how you’ll use the alphanumeric Sender ID for SMS (your use case)
- A sample SMS message
Sender ID format requirements
The ACMA won’t approve a Sender ID that doesn’t meet its format rules. Your Sender ID must:
- Only contain characters A–Z, a–z, 0–9, and supported special characters
- Be at least 2 and no more than 11 characters long
- Not consist only of numbers
- Not begin or end with a space or underscore
- Not contain the word “Unverified”
- Not contain offensive, deceptive, or misleading words
- Not consist solely of a term restricted by the ACMA
Your Sender ID must also match your entity name as it appears on an official business/company name register or trademark register — either exactly, or as a recognizable contraction, abbreviation, acronym, or initialism of that name.
What to do
Gather the completed LOA (PDF), your business registration number, and your use-case details, then contact our support team so we can begin the registration and submit it to Twilio for approval on the ACMA register.
France – Alphanumeric Sender ID Authorization (Twilio)
France has recently updated its SMS rules, and additional requirements now apply to any SMS traffic delivered to French mobile networks — regardless of where the sender is located. The updated framework (AF2M’s Charte Business Messaging) took effect on March 1, 2026. We use Twilio for alphanumeric Sender IDs in France.
AF2M (Association Française pour le développement des services et usages Multimédias multi-opérateurs) coordinates messaging across French operators. It is an industry co-regulatory body rather than a government authority, but its rules are contractually binding across operators and aggregators — so compliance is effectively mandatory.
Sender ID rules
Under the updated French requirements, your Sender ID must:
- Contain only Latin alphanumeric characters (A–Z, a–z, 0–9); as of March 1, 2026, special characters are not allowed
- Not resemble a phone number (it cannot be numeric only)
- Clearly identify the advertiser, brand, or product
- Not consist of generic terms (for example “alert”, “appointment”, “shop”) unless the term corresponds to a registered company, brand, or product name and valid supporting documentation can be provided
Some Sender IDs are restricted or blocked entirely. AF2M maintains two lists: “Strictly Prohibited” (blocked outright — this includes senders that could impersonate institutions, e.g. government or telecom brands) and “Prohibited Unless Authorized” (allowed only with written authorization and operator validation).
Sending-time restrictions (important for marketing)
French operators do not allow marketing or promotional traffic on Sundays or French public holidays, or between 10 pm and 8 am. Messages attempted during these periods are queued and delivered afterwards. Plan campaign timing accordingly.
Opt-out requirement
All marketing/promotional messages must include a clear opt-out option in the message content. In France this typically takes the form of an appended instruction such as “STOP au 36179” at the end of the message, rather than only “Reply STOP.”
French mobile numbers can’t be used for A2P
In France, standard mobile numbers can only be used for person-to-person messaging. All business (A2P) traffic — including marketing and transactional messages such as one-time passwords — must be sent using an Alphanumeric Sender ID, a short code, or an approved technical platform number.
What to do
Confirm your Sender ID meets the updated rules, and plan around the sending-time restrictions before you send, so your messages aren’t blocked, filtered, or queued.
Spain – Alphanumeric Sender ID Registration (CNMC Alias Registry)
Spain now requires every alphanumeric Sender ID used in messages to Spanish numbers to be registered with the national regulator before it can be used. Unlike the other countries in this guide, you submit this registration directly to the regulator yourself — we then complete the provider side with Twilio.
What’s changing
The CNMC (Comisión Nacional de los Mercados y la Competencia) has created a national Alias Registry — an official database of every alphanumeric Sender ID (“alias”) permitted to send to Spanish numbers. The framework comes from Ministerial Order TDF/149/2025 and Circular 1/2026, and it exists to curb smishing and brand impersonation.
From September 15, 2026, Spanish mobile operators block any message sent to a +34 number using an alias that isn’t registered. This covers SMS, MMS, and RCS, and applies to every company sending to Spain — Spanish or not.
A registration ties three parties together:
- You, as the alias holder (titular) — you must prove the alias legitimately belongs to your business.
- Twilio Ireland Limited, as the originating provider (proveedor de origen) — operators only accept a registered alias when the traffic arrives from the provider named in its registration.
- Sender, as a third party (tercero) — the platform that operates the alias on your behalf.
Not affected: dedicated phone numbers (long codes and short codes) don’t require registration. If you only send to Spain from a phone number, nothing changes for you.
Start with the digital certificate
Do this first. The CNMC portal can only be accessed with a valid Spanish digital certificate, held by the person acting as your legal representative. There is no way around this — the regulator requires the alias holder to confirm the registration in the portal, and confirmation requires a certificate. Obtaining one takes time, so start here rather than leaving it until last.
If nobody at your company holds one, you can appoint an authorized representative who does and sign a Letter of Authorization (LoA) using the CNMC’s published template. Companies based outside Spain should check with us before assuming an eIDAS certificate will be accepted.
What else to prepare
- Your company details — full legal entity name and Tax ID. Spanish companies provide a NIF; companies elsewhere in the EU provide an EU VAT ID.
- Proof of your legitimate connection to the alias, plus the relevant registration number. Accepted grounds are a trademark registered with OEPM or EUIPO, a trade name registered with OEPM, a corporate name in the Commercial Registry, an internet domain registered with Red.es or ICANN, a name in another national or international public register, or legitimate and habitual use of the alias in the course of your professional activity.
- The exact alias, in the casing you send with. Registrations are case-sensitive at operator level, so
MyBrandandMYBRANDcount as different aliases. Register it exactly as it appears in your Sender account.
Generic aliases that don’t clearly identify your business (“Alerts”, “Offers”, “Shop”) won’t be approved.
Register with the CNMC
Twilio’s guide walks through the portal screen by screen, and we recommend keeping it open as you go:
How to Self-Register your Spain Alphanumeric Sender ID with CNMC
The short version:
- Log in to the Alias Registry portal with your Spanish digital certificate. In the applicant section (Solicitante), select On behalf of (En representación de).
- Fill in the applicant details. Your company’s Tax ID and legal name identify the entity that will own the alias. Your own NIF, name, and email are usually filled in automatically from your certificate.
- Set the application type (Tipo de solicitud) to Alias Registration (Inscripción de Alias).
- Add the representative of the holder (Representantes del titular). Choose natural person or legal entity, enter the identity and contact details, and tick Receive notifications so CNMC updates reach you. Attach the LoA here only if the representative is a third party — it isn’t needed when the person named is your own legal representative.
- Add your alias and legitimate connection. Enter the exact Sender ID, set message type to SMS/MMS, set an activation date (today or your intended launch date), and leave the end date blank for ongoing use. Then choose your legitimate linkage from the dropdown and enter the supporting registration number in the Specify which one is field.
- Add your telecommunications supplier (Proveedores). Click Add Supplier, then search for and select TWILIO IRELAND LIMITED (N0073355J).
- Add Sender as a third party (Terceros). Click + Add Third Party, select Legal Entity (Persona jurídica), and enter:
- Company name (Razón social): UAB “Sender.lt”
- NIF / VAT: LT100008985714
- Review and submit (Revisar y presentar). You can save a draft with Guardar Borrador if you need to finish later.
- Download and keep the confirmation document (Justificante). This is your proof of submission and you’ll need it in the next step.
After you submit
Your designated legal representative receives an email from the CNMC pointing to an electronic notification on the Alias Registry portal. They must log in and authorize the application within 10 working days of that notification, which generates a second confirmation document. Miss the window and the application doesn’t proceed.
The CNMC then reviews the request and sends approval updates to the email address you provided. Review normally takes up to a month, and can take longer in the period around the enforcement date.
Send us your confirmation document
Once you’ve submitted, send your confirmation document (justificante) to support@sender.net. We’ll complete the matching Sender ID registration with Twilio, which requires proof of your CNMC submission.
Your alias only becomes usable once both the CNMC registration and the Twilio registration are approved.
What to do
Confirm you have access to a Spanish digital certificate, gather your legitimate-connection evidence and registration number, then work through Twilio’s guide to submit your CNMC application. Send us the confirmation document so we can finish the Twilio side. Contact us via live chat or support@sender.net if you’re unsure which alias your Spanish traffic uses.
Requirements are set by carriers and regulators and can change. If you have any questions, contact us via live chat or at support@sender.net — we’re here to help.