Spain’s new sender ID registry: a barrier against fraud and smishing
Latinia

Real-time fraud prevention keeps getting more sophisticated. It is no longer just about spotting a suspicious transaction, but about reinforcing every layer involved before, during and after a potential threat. One of those layers is communication with the customer.
Spain has just added a new measure along those lines. With the new registry now in force, operators must block SMS, MMS and RCS messages that use a sender ID — the name of a bank or a company, for instance — that has not been previously registered with the National Commission on Markets and Competition (CNMC), as well as messages sent by providers not authorised to use it.
According to Cinco Días, only 13,565 companies had registered their sender IDs a few days before the measure took effect, although many of the country’s leading utilities, banks and insurers were already on the list.
What changes with the new sender ID registry?
The goal is to make it harder for a third party to use a legitimate organisation’s name to pass off a fraudulent message as authentic. The CNMC explains that the registry will make it possible to verify the names or brands appearing as senders on SMS, MMS and RCS messages sent to Spanish numbers.
From the moment it takes effect, a sender ID must be registered in advance and linked to its rightful owner. Operators must also block messages that use registered sender IDs when they come from providers not authorised to use them.
The measure does not eliminate fraud on its own, nor every possible form of impersonation, but it adds a further barrier and seeks to strengthen user confidence in the messages they receive.
Spain is not an isolated case
Spain’s new registry does not stem from any harmonised EU obligation. There is currently no single European registry of SMS sender IDs, and the mechanisms are being developed mainly at national level. Even so, the direction is fairly clear: regulators across Europe are introducing systems to verify sender identity and make impersonation harder.
In Ireland, ComReg launched an SMS Sender ID Registry in 2025. Since July 2025, messages sent with unregistered IDs are flagged as “Likely Scam.” The regulator plans to block them at a later stage, although that block has been postponed while technical issues are resolved.
Finland has gone even further: since May 2026, organisations sending SMS to Finnish numbers must demonstrate in advance their right to use the sender IDs in question. When the operator cannot reliably identify the sender, the ID is replaced with “Unknown”; from November 2026, the label will change to “Spam.”
Sweden introduced new rules in August 2026 requiring operators to stop calls and messages suspected of being used for fraud, and allowing the regulator PTS to maintain a voluntary registry of sender names to verify that an SMS really comes from who it claims to.
At EU level, the approach is broader. The new European payment services framework, provisionally agreed by the Council and the European Parliament, specifically strengthens the fight against impersonation and spoofing fraud, and provides for greater cooperation between payment service providers and electronic communications providers. In other words, there is no single European model for sender ID registration yet, but there is a converging trend towards more sender authentication, more blocking capability and more shared responsibility in fraud prevention.
Can an SMS help prevent fraud?
Yes. And it can also be part of the problem. Spain’s National Cybersecurity Institute (INCIBE) defines smishing as a technique in which a cybercriminal sends an SMS posing as a legitimate organisation — a bank, a public institution or a company — in order to obtain private information or cause financial harm.
In financial services, this kind of impersonation is especially sensitive. Customers are used to receiving messages from their banks to confirm a purchase, flag a transfer, report a login or alert them to potentially suspicious activity.
That trust in the channel is exactly what attackers can exploit. Smishing, which we already examined in our article on AI-driven fraud in banking, is one of the vectors that takes advantage of the relationship of trust between the institution and the customer.
That is why sender identity is also part of the security of the communication itself.
One more layer in an increasingly sophisticated approach to fraud prevention
The new sender ID registry also reflects a wider shift in fraud prevention. For years, much of the effort went into detecting anomalous behaviour or transactions.
That capability remains essential today, but the response is becoming more complete. You have to detect what is happening, interpret its context, decide what action to take and, where necessary, communicate with the customer at the right moment.
That process raises increasingly relevant questions: can the customer trust that the message really comes from their bank? Does the alert arrive quickly enough? Is it contextualised with what has just happened? Can the institution react while the risk can still be avoided or contained?
The authenticity of the message, its context and the speed of the communication do not replace fraud prevention systems, but they can become an additional layer of protection.
At Latinia, we believe the transaction, the detection and the communication are all part of the same chain of trust. In an environment where fraud evolves constantly, protecting the customer also means making critical communications timely, contextualised and trustworthy.
What can Latin American banks learn from this?
The new regulation applies to the Spanish market, but it raises questions that are equally relevant for financial institutions in Latin America when it comes to fraud prevention.
Not every market will necessarily follow the same regulatory model as Spain. Still, looking at the initiatives being rolled out in Europe points to a trend: customer protection is gradually extending from the transaction itself to the communication environment around it.
For banks, this means thinking of notifications not only as an operational mechanism for informing customers, but also as part of the customer’s security experience.
Detecting possible fraud in time is essential. Making sure the right communication reaches the customer immediately, through a channel they can trust, is essential too.
FAQs
Where do you register a sender ID for sending SMS in Spain?
Sender IDs must be registered in the CNMC’s Sender ID Registry, through the procedure available on its electronic office portal. The application can be filed directly by the company or public body that owns the sender ID, or by an authorised provider or third party acting on its behalf.
Is registering a company’s sender ID mandatory?
It is mandatory if the company wants to keep using that name, brand, corporate name or domain as the sender of SMS, MMS or RCS messages sent to Spanish numbers. The requirement does not mean every company needs a sender ID: it applies to those that want to use one to identify themselves as the sender of these messages.
What happens if a company does not register its sender ID?
Since 15 September 2026, operators have been required to block SMS, MMS and RCS messages sent with unregistered sender IDs, which means those messages will not reach their recipients. The company can continue sending communications without using the sender ID, and can register it later in order to use it again as a sender.
Does the provider sending the messages have to be registered too?
Yes. Having the sender ID registered is not enough: the messages must also come from providers authorised to use it. Operators must block messages using a registered sender ID when they arrive from a provider that the owner has not authorised.
Contact
