appliedbits
FIELD NOTES PUBLISHED
PUBLISHED 2026-07-02

Australia's SMS Sender ID Register goes live

ACMA  ·  source ↗

Australia’s communications regulator has switched on its SMS Sender ID Register. From 1 July 2026, messages sent under a registered sender ID keep showing the brand name; messages using an unregistered sender ID must be labelled “Unverified” by the carrier and grouped into a single thread. The ACMA frames it against the scale of the problem: Australians lost more than A$13.8 million to text scams in the first nine months of 2025, much of it from messages spoofing trusted names like NAB, Australia Post, and myGov.

The design is label, not block: unregistered sender IDs aren’t cut off, they’re rendered “Unverified” and bundled into one thread, while the harder gate sits on carriers — non-participating telcos can’t handle sender-ID traffic at all. That raises the floor against casual spoofing. But it’s worth asking what the register actually authenticates. Registration is tied to a business identity (ABN), with a restricted-word list and an approval path for senders acting on a brand’s behalf — a know-your-registrant check plus gated carriage. What it doesn’t obviously establish is that a given message comes from a party with a validated right to use the identity it asserts. “Registered” is being asked to stand in for “authenticated.”

That’s the same seam STIR/SHAKEN and rich call data work on the voice side. Attestation exists precisely to assert a verified right-to-use of the calling number, and branded calling is meant to sit on top of that authenticated base, not beside it. A sender-ID registry with no equivalent origination-authentication layer risks letting the brand label carry more trust than the underlying binding has earned — the “Unverified” tag teaches people to trust the registered name, even though registration says little about who actually sent this particular message. The question worth tracking is whether label-plus-registry moves victim rates on its own, or whether it ends up needing an authenticated-origination layer underneath to mean what recipients will take it to mean — the same lesson the US 10DLC and branded-messaging efforts are working through.

Tagsacmasender-idbranded-messagingsmishingaustralia