Spain Is Now Blocking Unregistered SMS Sender Names — and the Carve-Out Most Coverage Missed
Updated: 6 hours ago
Spain began blocking SMS, MMS and RCS messages with unregistered sender names on 15 September 2026 — but not quite as the rule was written. Three days before the deadline the CNMC published a circular creating a transitional pre-registration, so an alias that had been applied for in time keeps working while the regulator finishes checking it. Most coverage reported the deadline as absolute. It was not.
Sigma Telecom has operated from Istanbul since 2003 and has been a wholesale carrier since 2014, with more than 1,000 interconnections reaching over 190 countries. We carry over 300 million messages a month across SMPP, HTTP and SS7. A rule that changes what a terminating operator does with a message is not a communications story for us. It is a change to a routing table, a set of customer conversations, and something the NOC has to be able to see.
This article covers what Spain switched on, the carve-out that arrived at the last minute, how the Spanish regime compares with the three other sender-ID registries already live, and what a registry does and does not fix for a buyer of wholesale SMS.
What Spain switched on
The legal instrument is Order TDF/149/2025 of 12 February 2025, implemented through CNMC Circular 1/2026. The register covers aliases — the alphanumeric sender name a recipient sees at the top of a message instead of a number. Any organisation sending SMS, MMS or RCS to Spanish numbers under a brand or company name has to register that name, whether or not the organisation is established in Spain.
On 1 September the CNMC issued a public call urging companies to register and to answer the regulator's correspondence before the deadline, warning that a company which does not register its aliases "will not be able to continue sending messages identified with its company name, name or commercial brand" (CNMC, 1 September 2026).
Two provisions matter more to a carrier than to a brand. The first is that blocking is not limited to unregistered names: operators are also required to block messages arriving from a messaging provider that is not itself registered, even where the alias is registered correctly. The second is that each alias is associated with the authorised originating provider through which its traffic is routed. A registration is therefore not a portable credential that travels with the brand. Change the path a message takes into Spain and the association has to follow it.
The carve-out that arrived three days early
On 12 September the Boletín Oficial del Estado published CNMC Circular 3/2026 of 8 September, amending Circular 1/2026 (BOE-A-2026-19053). It creates a transitional pre-registration. In the circular's own words, aliases whose registration was requested before 14 September 2026 at 15:00 peninsular Spanish time "quedarán preinscritos como medida transitoria para que puedan seguir utilizándose" — they are pre-registered as a transitional measure so that they can continue to be used.
That state lasts until the authorisation deadline for the alias holder expires or the CNMC resolves the application, with a maximum of three months from the point the alias was communicated. The regulator's stated reason was practical rather than political: a significantly high volume of applications and the material impossibility of validating them all before 15 September.
The distinction is narrow and worth stating precisely. This is not a general extension. An alias nobody applied for is blocked from 15 September exactly as originally drafted; an alias applied for before the cut-off is not. At the deadline the CNMC had 13,565 aliases registered, with reporting putting four to six thousand still pending — so the carve-out is not a rounding error. It covers a material share of Spain's branded traffic.
There is a lesson in the timing. A week before the deadline, the published position was that no further extension was expected. Four days before it, a circular in the BOE changed the operative rule for several thousand senders. The date held; the consequence of missing it did not.
Four registries, four different outcomes on the wire
Sender-ID registration is not new. What is new is the enforcement action attached to it, and that is where the four live regimes diverge.
Market | Regime in force since | What happens to an unregistered sender name |
|---|---|---|
Singapore — SSIR | 31 January 2023 | Delivered, marked "Likely-SCAM" |
Ireland — ComReg | 3 July 2025 | Delivered, modified to "Likely Scam". Blocking was scheduled for 3 October 2025 and deferred |
Australia — ACMA | 1 July 2026 | Delivered, over-stamped "Unverified" |
Spain — CNMC | 15 September 2026 | Blocked, unless pre-registered under Circular 3/2026 |
Three of the four keep the message and change what the recipient sees. Only Spain stops it. For a sender, that distinction is the whole difference between a damaged brand impression and a failed delivery. For a carrier, it is the difference between a message that generates an ordinary delivery receipt and one that does not arrive at all.
Australia's rules are worth a second look because they put the obligation on the operator, not only on the brand: originating telcos must join the register, offer to register sender IDs for customers, and verify that a customer has a legitimate reason to use a given name (ACMA, rules for telcos). That is a compliance function sitting inside the carrier, which is where this work is heading.
Ireland's published numbers give a sense of the scale a national register reaches once established. As of 10 September 2026 the ComReg registry held 21,770 registered sender IDs across 16,069 owners, against a Europe Economics estimate, which ComReg cites, that scam texts cause around €115 million of quantifiable harm a year in Ireland (ComReg SMS Sender ID Registry). Ireland labelled first and has still not moved to blocking. Spain went straight there.
What a registry proves, and what it does not
A register entry establishes that a sender name was claimed by an entity that completed a registration process, and that the traffic carrying it entered the network through a provider entitled to carry it. That is a genuine gain. It removes the cheapest form of impersonation, which is simply typing a bank's name into the sender field of a message and pushing it at a gateway.
It does not establish that the recipient consented to the message, that the route it travelled is a clean one, or that the volume behind it is real demand rather than manufactured traffic. Artificially inflated traffic, grey-route termination and SIM-farm origination all survive a sender-ID register intact, because in each case the name in the sender field can be perfectly legitimate. Treating registration as a proxy for traffic quality would be reading far more into it than it carries.
Registries are also national, and the mechanics differ in every market that has one. For anyone buying wholesale SMS across a wide footprint, compliance here is a per-destination property, not a company-wide certificate.
What it changes in a routing table
Destination rules become route metadata. Whether a destination blocks, labels or ignores an unregistered sender name now has to sit alongside the commercial attributes of a route, because it determines whether traffic arrives at all. Spain adds a third state to that field: registered, unregistered, and pre-registered pending resolution.
Rejections have to be readable. A message refused for a registration reason and a message refused for any other reason can look similar from a customer's side. Being able to say which is which, quickly, is the difference between a customer fixing a registration and a customer opening a route dispute. This is ordinary work for a 24/7 NOC, but it has to be set up before the traffic fails, not after.
Alias-to-provider binding constrains failover. This is the part most easily missed. If a registration ties a name to one authorised originating provider, then rerouting that traffic through a second path is not a neutral operational decision — it can turn a compliant message into a blocked one. Route diversity is still the right answer for availability, but in a market with binding of this kind it has to be arranged in advance rather than improvised during an incident.
What to ask a supplier now
The questions changed on 15 September. Before the deadline the useful one was whether a customer intended to register. Now it is which state each alias is actually in: registered, pre-registered under the transitional measure, or neither. The second and third answers carry a clock. A pre-registered alias has at most three months before the CNMC resolves it, and nothing about that state is visible to the sender from delivery receipts alone.
Worth asking alongside it: which authorised originating provider each alias is bound to, and whether that matches the route in use; and what a registration block looks like in the receipts you receive. None of this requires a new contract. It requires a supplier that keeps per-destination regulatory state as part of its routing data and will tell you what it holds — the kind of record-keeping discipline ISO and PCI DSS certification implies.
Frequently asked questions
What happened in Spain on 15 September 2026?
Operators began blocking SMS, MMS and RCS messages sent to Spanish numbers using an alphanumeric sender name that is not entered in the CNMC's Alias Register. Messages from a messaging provider that is not itself registered are also blocked, even where the alias is registered.
So was the deadline extended or not?
Not extended. CNMC Circular 3/2026, published in the BOE on 12 September, pre-registered aliases whose applications were submitted before 14 September at 15:00 peninsular Spanish time, so those can continue in use while the regulator resolves them. An alias that was never applied for is blocked from 15 September as originally drafted.
How long does the transitional pre-registration last?
Until the authorisation deadline for the alias holder expires or the CNMC resolves the application, with a maximum of three months from when the alias was communicated. It is a queue, not a reprieve.
Does this apply to companies based outside Spain?
Yes. The requirement attaches to messages sent to Spanish numbers under a brand or company name, regardless of where the sending organisation is established.
Does registering a sender name protect against SMS fraud generally?
No. Registration addresses impersonation of a brand in the sender field. It does not address artificially inflated traffic, grey-route termination or SIM-farm origination, in all of which the sender name can be entirely legitimate.
Which other markets run a sender-ID registry?
Singapore has operated one since January 2023, Ireland since July 2025, and Australia since July 2026. Each attaches a different consequence to an unregistered name, so the treatment has to be checked per destination rather than assumed.


