# Destination countries & SMS pumping

Destination countries limit where your A2P Messaging API project can send SMS, for every sender, over HTTP and SMPP. This page explains SMS pumping fraud, how the allowed and blocked country lists and the fraud-risk suggestions defend against it, and what a request to a country that isn't allowed returns.

**Language:** en
**Audience:** developer
**TLDR:** SMS pumping is bots abusing forms that send an SMS (sign-up, OTP, password reset) to trigger messages to numbers where the attacker earns part of the fee; you pay for those sends. In SMS > Settings > Destination countries, Allowed countries limits sending to the countries you list (empty means every country) and Blocked countries excludes countries on top. Both apply to every sender of the project, over HTTP and SMPP. A send to a country that isn't allowed returns 422 on `to`, and nothing is sent or charged.
**Search keywords:** sms pumping, AIT, artificially inflated traffic, toll fraud, IRSF, geo permissions, block countries, destination countries, allowed countries, blocked countries, countries with fraud risk, country allowlist, country blocklist, otp fraud, 422 to, country not allowed
**Related pages:** /a2p-messaging-api/channels/sms/senders, /a2p-messaging-api/http/errors, /a2p-messaging-api/http/bulk
**Docs index (every page):** https://staging-instasent-docs-nextjs.oscar-284.workers.dev/llms.txt
**This zone's index:** https://staging-instasent-docs-nextjs.oscar-284.workers.dev/a2p-messaging-api/llms-full.txt
**This page:** https://staging-instasent-docs-nextjs.oscar-284.workers.dev/a2p-messaging-api/channels/sms/destination-countries/ (HTML) · https://staging-instasent-docs-nextjs.oscar-284.workers.dev/a2p-messaging-api/channels/sms/destination-countries.md (Markdown)

**Destination countries** decide where your project can send SMS. They are the defence
against **SMS pumping**, one of the most common frauds on any service that sends SMS from a
public form, and they cost nothing to set: if your business works in a few countries, listing
them closes every other destination to anyone abusing your integration.

## What SMS pumping is

SMS pumping — also called **artificially inflated traffic (AIT)** — is fraud that exploits
forms that send an SMS: sign-up, one-time passcodes (OTP), password reset. Bots fill those
forms in with numbers in countries where the attacker, in league with someone along the
delivery chain, **earns a share of the fee for every message delivered**. No real user is
behind those requests.

The messages are sent and delivered normally, so **you pay for them**. The usual signs are a
sudden rise in sends to countries where you have no customers, often to consecutive numbers,
with no one completing the flow the SMS was for.

## Limiting the countries you send to

In the dashboard, the A2P Messaging API project's SMS channel has a **Settings** tab with a
**Destination countries** block — its ⓘ explains SMS pumping — and two lists:

- **Allowed countries** — if your customers are in only a few countries, list them here, and
  nothing goes anywhere else. **Empty means every country.**
- **Blocked countries** — specific countries your project never sends to. They apply **on top
  of** the allowed list: a country is blocked even if it is also in the allowed list.

Both lists apply to **every sender of the project**, and to traffic sent over
[HTTP](/a2p-messaging-api/http/quickstart) and [SMPP](/a2p-messaging-api/smpp/integration)
alike — transit traffic on the wildcard route included.

### Countries with fraud risk

Under the lists, the dashboard suggests **Countries with fraud risk**: destinations where SMS
pumping concentrates. Instasent maintains that list, and it changes over time. If you don't
work with them, add them to Blocked countries one by one with the **+** next to each country,
or all at once with **Add all**. The suggestions don't show when you have allowed countries:
the allowed list already closes everything else.

They are a suggestion only: **nothing is blocked unless you add it** to Blocked countries.

Nothing in this block is saved until you select **Save**.

## What a request to a country that isn't allowed returns

A message to a country outside your allowed list, or in your blocked list, is **refused when
you send it, with `422`**, and **nothing is sent or charged**. The error is reported on the
`to` field:

```json
{ "errors": { "fields": { "to": ["The destination country is not allowed by the project settings"] } } }
```

In a [bulk request](/a2p-messaging-api/http/bulk) the check runs per item: the refused message
is reported in `errors`, and the rest of the batch is sent.

## Good practice

- **Use Allowed countries if your business is in one or a few countries.** It is the single
  setting that does most against pumping, because it closes every destination you didn't
  choose instead of chasing the ones attackers use today.
- **Protect your own forms.** The SMS is triggered from your sign-up, OTP or password-reset
  forms, so the first line of defence is there: rate-limit how many codes a phone number, an
  IP address or a session can request, and put a CAPTCHA in front of the request.

---

This is one page of the Instasent documentation. For the complete machine-readable index of every guide and API reference, fetch https://staging-instasent-docs-nextjs.oscar-284.workers.dev/llms.txt — start there for full context.
