A2P Messaging API · Channels · SMS
Destination countries & SMS pumping
Destination countries limit where your A2P Messaging API project can send SMS, for every sender, over HTTP and SMPP. This page explains SMS pumping fraud, how the allowed and blocked country lists and the fraud-risk suggestions defend against it, and what a request to a country that isn't allowed returns.
Destination countries decide where your project can send SMS. They are the defence against SMS pumping, one of the most common frauds on any service that sends SMS from a public form, and they cost nothing to set: if your business works in a few countries, listing them closes every other destination to anyone abusing your integration.
What SMS pumping is
SMS pumping — also called artificially inflated traffic (AIT) — is fraud that exploits forms that send an SMS: sign-up, one-time passcodes (OTP), password reset. Bots fill those forms in with numbers in countries where the attacker, in league with someone along the delivery chain, earns a share of the fee for every message delivered. No real user is behind those requests.
The messages are sent and delivered normally, so you pay for them. The usual signs are a sudden rise in sends to countries where you have no customers, often to consecutive numbers, with no one completing the flow the SMS was for.
Limiting the countries you send to
In the dashboard, the A2P Messaging API project's SMS channel has a Settings tab with a Destination countries block — its ⓘ explains SMS pumping — and two lists:
- Allowed countries — if your customers are in only a few countries, list them here, and nothing goes anywhere else. Empty means every country.
- Blocked countries — specific countries your project never sends to. They apply on top of the allowed list: a country is blocked even if it is also in the allowed list.
Both lists apply to every sender of the project, and to traffic sent over HTTP and SMPP alike — transit traffic on the wildcard route included.
Countries with fraud risk
Under the lists, the dashboard suggests Countries with fraud risk: destinations where SMS pumping concentrates. Instasent maintains that list, and it changes over time. If you don't work with them, add them to Blocked countries one by one with the + next to each country, or all at once with Add all. The suggestions don't show when you have allowed countries: the allowed list already closes everything else.
They are a suggestion only: nothing is blocked unless you add it to Blocked countries.
Nothing in this block is saved until you select Save.
What a request to a country that isn't allowed returns
A message to a country outside your allowed list, or in your blocked list, is refused when
you send it, with 422, and nothing is sent or charged. The error is reported on the
to field:
{ "errors": { "fields": { "to": ["The destination country is not allowed by the project settings"] } } }In a bulk request the check runs per item: the refused message
is reported in errors, and the rest of the batch is sent.
Good practice
- Use Allowed countries if your business is in one or a few countries. It is the single setting that does most against pumping, because it closes every destination you didn't choose instead of chasing the ones attackers use today.
- Protect your own forms. The SMS is triggered from your sign-up, OTP or password-reset forms, so the first line of defence is there: rate-limit how many codes a phone number, an IP address or a session can request, and put a CAPTCHA in front of the request.
Last updated