Skip to contentSkip to navigationSkip to topbar
Page tools
Useful for sharing or LLM
Accelerate development with AI

On this page
Looking for more inspiration?Visit the

SMS Pumping Protection for Programmable Messaging


SMS Pumping Protection uses automatic fraud detection to block messages flagged as suspicious for SMS pumping fraud. It works by analyzing your accounts current and historical SMS traffic for unusual patterns based on your messaging use case. When unexpected fluctuations in your SMS traffic for a specific country, or system-known malicious activity, are detected, this feature automatically blocks messages to the phone numbers associated with the suspected fraud.

SMS Pumping Protection is offered in two tiers:

  • Basic tier — A foundational layer of risk protection that is automatically enabled for eligible accounts, at no additional software cost. Basic identifies fraud based on aggregate-level risk vectors but does not offer more granular controls for any customized configurations.
  • Advanced tier — A paid upgrade that adds configurable protection modes, country-specific overrides, and control over use-case classification for accounts with complex or mixed traffic profiles (for example, marketing plus OTP).
(information)

Existing users

If you were already using SMS Pumping Protection before the introduction of the Basic and Advanced tiers, your account has been moved to the Advanced tier automatically, ensuring your current cost structure remains unaffected. No action is required and your existing protection continues without interruption.

(warning)

Warning

No provider-side solution can guarantee 100% protection against sophisticated attackers. Customer participation in fraud prevention is essential. For steps you can take, read the guide to preventing messaging fraud.

SMS Pumping Protection (Basic or Advanced) is scoped per account and does not automatically extend to subaccounts — each subaccount is evaluated and enabled separately. Please note that enabling this feature on a Parent account does not automatically apply protection across its subaccount hierarchy.


Feature breakdown: Basic vs. Advanced

feature-breakdown-basic-vs-advanced page anchor
SMS Pumping Protection (Basic)SMS Pumping Protection (Advanced)
CostNo fixed/ recurring charges.Paid add-on: $0.025 per successfully sent message segment to messages terminating outside USA & Canada.
ActivationAuto-enabled for eligible accounts sending international traffic.Self-serve upgrade from Messaging Settings in the Console.
Content awarenessIntelligent Classification runs automatically to read message intent (for example, marketing vs. 2FA); not configurable.Same Intelligent Classification runs by default; you can switch to Custom classification and manually define your traffic profile instead.
Protection modesSingle, aggregate-level model — not configurable.Low, Medium, or High protection modes, selectable as an account-wide default.
Country-specific overridesNot supported.Set a different protection mode per country.
Blocking error codeBlocked messages return Error 30453.Blocked messages return Error 30450.
Blocked message chargesBlocked messages may still be charged at the standard termination rate.No charge for successfully blocked messages.

For pricing information on SMS Pumping Protection for Programmable Messaging:

  1. Navigate to the SMS Pricing(link takes you to an external page) page.
  2. Select the country you are interested in.
  3. Check the Features section.

For more information, contact Twilio Sales(link takes you to an external page).


Verify and Fraud Guard for OTP traffic

verify-and-fraud-guard-for-otp-traffic page anchor

If you're using Programmable Messaging to send one-time passcode (OTP) verifications, consider migrating to Verify instead, which includes Fraud Guard with customizable protection levels at no extra charge. Fraud Guard remains the recommended solution for verification traffic and offers the highest detection efficacy of Twilio's AIT prevention products.


Enable SMS Pumping Protection

enable-sms-pumping-protection page anchor

To enable SMS Pumping Protection, do either of the following:

Once enabled, your account starts on the tier that matches its eligibility:

  • Basic tier is selected by default for eligible accounts and requires no setup. Once enabled, protection begins immediately.
  • To move to Advanced tier, select Upgrade on the Advanced protection card. This opens the advanced protection setup page, where you can configure:
    • A default protection mode (Low, Medium, or High) that applies to all countries without a specific override.
    • Country-specific overrides that supersede the default mode for individual countries, including a "No protection" option for countries you want to exclude from SMS Pumping Protection entirely.
    • Your messaging use case classification — choose AI classification to let Twilio's models read message content to distinguish traffic types, or Custom classification to manually define the traffic types that make up your account.

Opting out

opting-out page anchor

Because unprotected accounts increase risk to the carrier ecosystem and Twilio's platform reputation, blanket, perpetual opt-outs from Basic tier protection are not self-serve. If your business has a use case that's incompatible with default protection, contact your account team or Twilio Support to request an exception. Be ready to share your affected Account SIDs, the reason for the request, the scope of exception (global or certain countries), and a brief description of your messaging use case.

For temporary, message-by-message control instead of an account-wide opt-out, use the RiskCheck parameter described below.


This feature works by detecting SMS pumping fraud. SMS pumping fraud happens when fraudsters take advantage of a phone number input field to receive a one-time passcode, an app download link, or anything else via SMS. The messages are sent to a range of numbers controlled by a specific mobile network operator(link takes you to an external page) (MNO), and the fraudsters get a share of the generated revenue.

Twilio uses a baseline of expected message data to find outliers in behavior-based traffic patterns. We combine behavioral data with known explicit fraud schemes to filter out bad behavior. On the Advanced tier, this baseline is further refined by your configured protection mode, country overrides, and use-case classification.

Our model is always changing and uses multiple parameters to determine fraud. Examples of things we may temporarily block include:

  • Messages to a specific region, country, or locale known to be engaging in SMS pumping
  • Messages in a country your account has never sent SMS to previously
  • Messages with parameters and characteristics that suggest non-human behavior

Twilio's AI Nutrition Facts provide an overview of the AI feature you're using, so you can better understand how AI is working with your data. The qualities of SMS Pumping Protection are outlined in the following Nutrition Facts label. For more information, including the glossary regarding the AI Nutrition Facts label, refer to Twilio's AI Nutrition Facts page(link takes you to an external page).

AI Nutrition Facts

SMS Pumping Protection for Programmable Messaging

Description
SMS Pumping Protection detects and prevents SMS pumping abuse based on the message use case in real time to protect customers from artificially inflated traffic using first-of-its-kind content aware technology and Twilio's Proprietary Customer AI engine.
Privacy Ladder Level
4
Feature is Optional
Yes
Model Type
Predictive
Base Model
Twilio Proprietary Model and Prophet

Trust Ingredients

Base Model Trained with Customer Data
Yes

Customer messaging traffic metadata is used for model training. Message content is analyzed at send-time by Intelligent Classification to determine traffic intent only for the purpose for detecting pumping fraud, and is used to train the underlying model.

Customer Data is Shared with Model Vendor
N/A
Training Data Anonymized
Yes
Data Deletion
Yes
Human in the Loop
No
Data Retention
30 days

Compliance

Logging & Auditing
Yes

Standard service logging is applied and logs are stored for future review.

Guardrails
N/A
Input/Output Consistency
Yes
Other Resources
SMS Pumping Insights available to provide transparency to customers around how the product works.

Preventing false positives

preventing-false-positives page anchor

Like any fraud prevention feature, there's a small chance our models may flag legitimate users as suspicious. We're constantly monitoring our results and adapting the fraud detection model to keep false positives extremely low.

You can use the Global Safe List API to maintain a list of phone numbers or 1k Prefixes (a set of 1,000 sequential phone numbers, formed by removing the final three digits of a full phone number) that will never be blocked by Programmable Messaging SMS Pumping Protection (Basic or Advanced), Verify Fraud Guard, or Verify Geo Permissions.

By adding safe and verified phone numbers, such as known customers, partners, or approved contacts, to the Global Safe List, you ensure timely delivery of critical communications to these message recipients.

When you create a Message with the Programmable Messaging API, you can use the RiskCheck parameter to adjust the level of risk protection for individual outbound messages. This works the same way on both Basic and Advanced tiers, and gives you more flexibility when sending messages for multiple use cases with different risk profiles using the same phone number.

For example, you may want to send messages for two different use cases using the same phone number:

  1. SMS messages with one-time passcode (OTP)/two-factor authentication (2FA) content
  2. Marketing SMS messages

Account- or phone number-level risk protection settings are not granular enough if you want to treat these two use cases differently for purposes of SMS Pumping Protection. However, to achieve this goal you can:

  1. Assign enable (the default) to RiskCheck when generating OTP/2FA messages. Because these flows are initiated by end users, they carry a higher risk of pumping fraud and benefit directly from built-in SMS Pumping Protection.
  2. Assign disable to RiskCheck for marketing messages that do not require SMS Pumping Protection. Since these communications are originated exclusively by your organization without end-user triggers, they remain safe from pumping risks.

Exercise caution when using the RiskCheck parameter. Apply it selectively only to message workflows that you are confident carry no risk of fraud. Disabling RiskCheck across your entire account removes SMS Pumping Protection for all your traffic and exposes your account to fraud risk.

Advanced Tier configuration options

advanced-tier-configuration-options page anchor

Accounts are set to the Medium protection level by default, providing a balanced threshold for detecting fraud while minimizing false positives. If this setting causes significant disruption to your legitimate global traffic, consider switching from Medium to Low. Alternatively, if fraud leaks persist despite SMS Pumping Protection being active, consider increasing the setting to High.

If legitimate traffic to a specific country is being blocked more often than expected, review your protection mode for that country under Country-specific protection in the Advanced settings. Lowering the mode for that country (or setting it to No protection, if your business need justifies it) takes effect immediately and overrides your account-wide default.

You can also take these actions if you suspect false positives:

  • Fall back to a different messaging method like WhatsApp or Facebook Messenger.
  • Create a separate subaccount for your legitimate users which has SMS Pumping Protection configured differently.
  • If you use the Advanced tier exclusively for marketing or promotional campaigns which are initiated directly by your organization rather than triggered by end users, you can switch to Custom classification in your advanced settings and set up the use case accordingly.
  • Reach out to your Solutions Architect or contact Twilio Support through the Console(link takes you to an external page) or Help Center(link takes you to an external page).

  • When SMS Pumping Protection (Basic) blocks a message, you'll see Error 30453 in your error logs.
  • When SMS Pumping Protection (Advanced) blocks a message, you'll see Error 30450 in your error logs.

Advanced tier accounts can also use the Messaging Intelligence > SMS Pumping Protection Insights dashboard to answer questions such as:

  • What are the projected monthly savings from using SMS Pumping Protection for Programmable Messaging?
  • What is the volume of sent messages that were blocked by SMS Pumping Protection, broken down by tier?
  • How do SMS pumping fraud activities break down by geography?