SMS Honeypot and Grey Route Detection

Our honeypot places controlled trap numbers in the SMS market and records exactly how messages reach them: which route, which originating network, which sender ID. It turns suspicion about grey routes into evidence.

What is an SMS honeypot?

An SMS honeypot is a set of controlled test numbers, also called trap numbers, on a mobile network, used to observe how SMS traffic reaches that network. Messages sent to the trap numbers are captured with their full delivery details, such as the originating SMSC, Global Title, sender ID and timing. Comparing that evidence with what each route claims to be reveals grey routes, SIM box termination and sender ID manipulation.

How trap numbers capture traffic

Test messages are sent through many routes to trap numbers on the operator's network; captured details reveal which routes are grey Route A Route B Route C Trap numberson the operator'snetwork Captured for eachorigin SMSC and GTsender ID, timingroute used Route C arrives from a local SIM: sender ID replaced, origin does not match
The same message sent through three routes. Two arrive as expected; the third arrives from a local SIM card with its sender ID changed, which identifies a SIM box route.
  1. Trap numbers are set up. Controlled numbers on the operator's network receive messages exactly like ordinary subscribers.
  2. Test traffic is sent through routes. Messages go through the commercial SMS routes being examined, as any sender would buy them.
  3. Every delivery is captured. For each message: the originating SMSC and Global Title, the sender ID as delivered, timestamps, and the route it was sent on.
  4. Evidence is compared. Delivery details are compared with what each route claims, and with the operator's agreements.
  5. Results feed action. Findings become SMS firewall rules, partner disputes and revenue claims.

What each captured message reveals

Originating SMSC and Global Title
Which network actually delivered the message, and whether it is a partner with an A2P agreement.
Sender ID as delivered
An alphanumeric sender ID replaced by a local mobile number usually means SIM box termination.
Delivery path
Messages that should arrive as A2P but arrive over a P2P interconnect expose a grey route.
Timing
Delays and bursts typical of SIM farms and blended routes.
Delivery report honesty
Whether the route's delivery report matches what actually reached the handset.

Continuous route monitoring

Grey routes change quickly: a path blocked today is replaced next week. The honeypot runs continuously, so operators see new routes as they appear rather than in a one-off audit.

Sender ID monitoring

Captured traffic shows which brand and bank sender IDs reach subscribers, and through which routes. This supports sender ID protection on the SMS firewall and helps identify phishing campaigns that impersonate trusted senders.

Turning evidence into firewall rules and disputes

Honeypot results are most useful when acted on. Confirmed grey sources become blocking rules on the SMS firewall. Partners whose interconnects deliver A2P traffic as P2P can be shown the captured messages. Revenue assurance teams use the same evidence to quantify losses; see SMS revenue assurance.

Honeypot vs active route testing

Route testing asks whether a specific route delivers well. A honeypot asks how traffic reaches a specific network. They use similar techniques but answer different questions; operators need the second. Our guide to SMS grey routes explains the detection methods side by side.

What a honeypot does not do

A honeypot does not inspect live subscriber traffic and does not block anything on its own. It shows the routes that deliver to its numbers, which is a sample, not the whole network. Used with an SMS firewall and regular audits, it closes the gaps each tool leaves on its own.

Frequently asked questions

How is a telecom honeypot different from a security honeypot in IT?

Both are decoys that attract activity so it can be observed. An IT honeypot imitates a vulnerable server. A telecom honeypot uses phone numbers that look like ordinary subscribers, so that messages and calls routed to them show how traffic actually travels.

Does the honeypot detect every bypass?

No. A honeypot sees the routes that deliver to its trap numbers. Bypass that targets other numbers, or that changes quickly, may not be captured. That is why honeypot evidence is combined with SMS firewall inspection of live traffic and with revenue assurance audits.

Is the traffic sent to trap numbers real?

Messages are sent through commercial SMS routes in the normal way, as any sender would. The difference is that we control the receiving numbers and capture every detail of delivery.

How is honeypot evidence used?

It supports SMS firewall rules, discussions with interconnect partners whose traffic arrives on grey paths, and revenue claims under A2P agreements. Each capture is stored with its route, timestamp and delivery details.

See which routes reach your subscribers

Tell us your network, the problems you suspect and whether you already run an SMS firewall. We will propose a honeypot pilot.

We use these details only to reply to your request. See the privacy policy.