Australia's SMS Sender ID Register Goes Live 1 July 2026 — What Businesses Must Do Now

Australia's SMS Sender ID Register Goes Live 1 July 2026 — What Businesses Must Do Now
From 1 July 2026, any entity sending SMS or MMS messages in Australia using an alphanumeric sender ID must have that ID registered on the ACMA SMS Sender ID Register. Miss the deadline and the consequence is straightforward: service disruption. Messages bearing unregistered sender IDs will not be carried by compliant providers.
The Australian Communications and Media Authority has framed the register as an anti-scam measure. Alphanumeric sender IDs — the branded strings like "MyBank" or "GovtAlert" that appear in place of a phone number — have been a reliable attack surface for SMS phishing. By requiring those identifiers to be registered and verified, ACMA aims to make it structurally harder for bad actors to impersonate legitimate brands in the message thread a consumer already trusts.
The registration obligation runs in two directions. Businesses and organisations with an Australian Business Number (ABN) register their sender IDs through participating message providers or telcos — those intermediaries act as the registration channel, not ACMA directly. On the other side of that relationship, message carriers and providers must themselves apply to participate in the register if they intend to use or carry messages with sender IDs from 1 July 2026. Both layers of the supply chain are required to be inside the system for traffic to flow.
The practical timeline is tight. The deadline is thirteen days away from the date of publication. Organisations that have not yet initiated registration through their message provider need to do so immediately — the registration process runs through commercial intermediaries, and any queue at those providers will only lengthen as the date approaches. Businesses that rely on SMS for transactional messaging, two-factor authentication, appointment reminders, or customer notifications are most immediately exposed to disruption if they delay.
The requirement covers alphanumeric sender IDs specifically — not numeric originator numbers. That distinction matters for operations teams scoping their compliance work: if your outbound SMS traffic originates from a standard long number or short code rather than a branded string, the July deadline does not directly apply to that traffic in the same way. However, many enterprise messaging deployments use alphanumeric IDs precisely because they are more legible and brand-consistent, so the affected footprint is likely broad.
Worth flagging here: the two-tier model ACMA has designed — where ABN-holding entities register via message providers, and those providers must themselves be enrolled — creates a dependency chain. If a business's current messaging vendor has not applied for participation, the business cannot complete its own registration through that vendor. Compliance teams should be confirming their provider's participation status now, not on 30 June.
The broader context is that Australia has been progressively tightening its SMS security posture. ACMA's October 2025 announcement gave the industry roughly eight months of lead time, and commentary from legal and compliance practitioners — including DLA Piper's January 2026 analysis — flagged the obligation early for businesses operating in the Australian market. The building blocks were visible well in advance. Still, deadline-driven compliance tends to compress at the end, and the final two weeks before a hard cutover are rarely calm.
Sender ID registries are not novel globally — the UK's SMS SenderID Protection Registry, run through the Mobile Ecosystem Forum, has operated a comparable scheme, and several Asian markets have implemented similar controls. What differentiates the ACMA approach is the statutory backing and the explicit service-disruption consequence for non-compliance, which gives carriers a clear obligation to block rather than a soft recommendation to filter.
For engineering and operations teams, the immediate action list is short but non-negotiable: identify every alphanumeric sender ID in use across your outbound SMS stack, confirm your message provider is a registered participant in the ACMA scheme, and initiate registration for each ID before the cutover. For providers that are not yet participants, the window to apply is effectively closed for comfortable processing before 1 July — escalation to a participating provider may now be the faster path.
The register itself represents a structural control rather than a detective one. It does not catch every SMS-based fraud attempt, but it removes the easiest vector: a scammer trivially spoofing a trusted brand name in a message thread. That narrowing of the attack surface is the point.


