SMS Firewall

Our SMS firewall inspects every message entering your network, on signaling and SMPP interfaces, and decides whether it is allowed, blocked or moved onto a commercial route. We design and build it in-house.

What is an SMS firewall?

An SMS firewall is a network element that inspects SMS arriving at a mobile operator, on SS7/SIGTRAN signaling links and on SMPP connections, and applies rules that allow, block, rate-limit or re-route each message. Operators use it to stop grey routes, SIM box termination, sender ID spoofing and spam, and to make sure application-to-person (A2P) traffic reaches their subscribers only through paid agreements.

Who uses an SMS firewall

Mobile network operators deploy SMS firewalls on their international and national interconnects. Telecom groups use one firewall policy across several operating companies, and some regulators require operators to filter A2P traffic or protect registered sender IDs.

The firewall protects three interests at once: the operator's A2P revenue, the subscriber's trust in messages from banks and brands, and the integrity of the operator's own signaling network.

The problems it solves

  • Grey routesCommercial A2P messages delivered through interconnects priced for P2P traffic, so the receiving operator is not paid A2P termination.
  • SIM box terminationBulk messages injected through local SIM cards in a gateway, so they appear to be on-net P2P traffic.
  • Spoofing and fakingMessages whose origin address or SMSC Global Title has been manipulated to look like a trusted network or sender.
  • Sender ID abuseA bank's or brand's name used by someone who has no right to it, often for phishing (smishing).
  • Spam and floodingHigh-volume unsolicited messages that generate complaints and load.
  • Lost visibilityNo reliable view of who sends A2P traffic into the network, at what volume, through which partner.

Our guide to SMS fraud types explains each pattern in more detail.

How the SMS firewall works

International SMS reaches a mobile network in two main ways: as signaling over SS7 or SIGTRAN from a foreign SMSC, and as SMPP traffic submitted by aggregators or partners to the operator's own SMSC. The firewall inspects both.

Where the SMS firewall sits: on the signaling path behind the STP, and in front of the SMSC for SMPP traffic Foreign SMSCSS7 / SIGTRAN STP /SIGTRAN GW SMS firewallallow, block, route MSC / SMSFto the subscriber HLR / HSS / UDMSRI-for-SM AggregatorESME over SMPP Operator SMSCA2P gateway Billing / CDRA2P revenue
Mobile-terminated SMS from abroad is checked on the signaling path; A2P traffic submitted over SMPP is checked at the SMSC. Network element names differ by generation: HLR (2G/3G), HSS (4G), UDM (5G).
  1. Routing lookup. A foreign SMSC asks the home network where to deliver a message with a MAP SendRoutingInfoForSM (SRI-for-SM) query. With SMS home routing, the answer points to the firewall instead of exposing the subscriber's real location and IMSI.
  2. Delivery. The foreign SMSC sends the message itself in a MAP MT-ForwardSM operation, which arrives at the firewall.
  3. Inspection. The firewall checks the calling Global Title and SCCP addresses against the MAP-layer origin, classifies the sender ID, compares content against known templates and checks volume patterns per source.
  4. Decision. The message is delivered, blocked, rate-limited, or flagged as A2P traffic that must come through a commercial route. Every decision is logged.
  5. Reporting. Blocked and allowed traffic is aggregated by source network, sender ID and partner, so commercial teams can act on it.

Grey route and SIM box detection

A grey route is an unauthorised path that delivers A2P messages over interconnects priced for P2P traffic. A SIM box is a device holding many local SIM cards, used to inject bulk messages as if they were sent by ordinary subscribers. Both are cheaper for the sender because the receiving operator is not paid A2P termination.

The firewall detects them with a combination of signals:

  • Mismatches between the originating SMSC or Global Title and the network the message claims to come from.
  • Alphanumeric or brand sender IDs arriving through P2P interconnects that should carry only numeric senders.
  • The same message template fanning out to many recipients from one source.
  • Velocity: one source sending at machine-regular intervals and volumes no subscriber produces.
  • On-net SIM behaviour: outbound-only SMS, no voice or data, no movement between cells.
  • Evidence from our honeypot, which shows exactly which routes are delivering to trap numbers today.

Read more in SMS grey routes: how they work and how to detect them.

Sender ID protection and content policies

Operators can register the sender IDs of banks, government services and brands, and allow them only from the aggregators authorised to send them. Messages using a protected sender ID from any other source are blocked. Content policies add rules for phishing links, prohibited keywords and binary SMS where required.

A2P monetization and routing controls

Blocking is the means; the outcome is that A2P traffic arrives through agreements that pay the operator. The firewall can enforce that senders of commercial traffic use the operator's A2P interconnect, apply per-partner and per-sender limits, and tag A2P messages for billing so they are reconciled against CDRs. For a full reconciliation of what arrived against what was billed, see SMS revenue assurance.

Reporting and analytics

  • Traffic by source network, Global Title, partner and sender ID.
  • Blocked traffic by rule and reason, with message samples for disputes.
  • New sources and sudden volume changes, with alerts.
  • Exports for commercial, fraud and regulatory reporting.

Deployment and integration

The firewall connects on SIGTRAN (M3UA over IP) to the operator's STP or signaling gateway, and on SMPP to the SMSC where A2P traffic is inspected. It can be deployed on the operator's premises or hosted, and runs as virtualised software. Integration with billing and CDR systems is agreed during the assessment.

A typical engagement starts with a traffic assessment: we measure the current mix of P2P, A2P and suspected grey traffic before any rule is switched on, so the operator sees the expected impact first.

Standards it follows

Policy design follows GSMA guidance, in particular FS.11 (SS7 interconnect security monitoring and firewall guidelines), FS.12 (A2P SMS bypass and fraud: methods, detection and mitigation) and SG.22 (SMS firewall best practices and policies). Our guide to GSMA SMS security documents explains what each one covers.

SMS firewall, SMPP firewall and signaling firewall compared

ProductProtectsInterfacesMain goal
SMS firewallInbound SMS to subscribersSS7/SIGTRAN, SMPPStop grey routes and abuse; protect A2P revenue
SMPP firewallSMPP connections from ESMEsSMPPControl who binds, how fast they send and what they send
Signaling firewallThe core network and subscribersSS7, Diameter, GTPStop tracking, interception and impersonation attacks

Why operators choose Wise Network

  • Built in-house. We design, build and support the product ourselves, so rules and integrations are changed by the people who wrote them.
  • A carrier's view of bypass. We route international SMS ourselves and know how blended and grey routes are assembled.
  • Evidence, not guesses. Honeypot data shows which routes deliver to your subscribers, before a rule goes live.
  • Telecommunications experience since 2003.

Frequently asked questions

Does an SMS firewall block person-to-person messages?

No. The firewall classifies traffic first. Genuine person-to-person (P2P) messages from other subscribers and roaming partners pass as normal. Rules target commercial A2P traffic that arrives on paths priced for P2P, messages with spoofed or faked origins, and known spam or phishing content.

How is an SMS firewall different from a signaling firewall?

A signaling firewall protects the network against SS7, Diameter and GTP attacks such as location tracking, interception and subscriber impersonation. An SMS firewall focuses on the messages themselves: who sent them, through which route, with what sender ID and content. Many operators run both; our two products share threat data.

Do we need to change our SMSC or HLR to deploy it?

Usually not. The firewall sits on the signaling path, at or behind the STP or SIGTRAN gateway, and can use SMS home routing so that inbound mobile-terminated SMS is delivered to it first. Integration is planned with your core and SMSC teams during the assessment.

How does the firewall tell A2P from P2P?

It combines several signals: whether the sender ID is alphanumeric or numeric, whether the originating SMSC and Global Title match the claimed sender, message velocity and fan-out from one origin, content templates repeated across many recipients, and evidence from honeypot trap numbers. No single signal is enough on its own.

Can the firewall help us earn revenue, not just block traffic?

Yes. Blocking grey routes is how A2P traffic is pushed back onto your commercial termination agreements. The firewall's reports show which senders and partners were affected, which supports new A2P agreements and pricing.

See the SMS firewall on your traffic

Tell us about your network: subscriber base, current SMS interconnects and whether A2P traffic is already under agreement. We will propose a demo or a traffic assessment.

We use these details only to reply to your request. See the privacy policy.