Technology

Australia's New SMS Sender ID Register: What Businesses Need to Know

Martin HollowayPublished 2month ago4 min readBased on 5 sources
Reading level
Australia's New SMS Sender ID Register: What Businesses Need to Know

From 1 July 2026, any organisation sending SMS or MMS messages in Australia using a branded sender ID must register that ID on the ACMA SMS Sender ID Register. Messages from unregistered sender IDs will not be delivered by compliant carriers. For businesses relying on SMS for customer communications, two-factor authentication, or transactional alerts, this is a hard deadline with real operational consequences.

The Australian Communications and Media Authority designed the register as a defence against SMS phishing. Alphanumeric sender IDs — the branded text strings like "MyBank" or "AustralianTax" that replace a phone number in a message — have long been exploited by bad actors impersonating legitimate organisations. By requiring these identifiers to be registered and verified, ACMA aims to make it structurally difficult for scammers to spoof a trusted brand name in a message thread a consumer already knows.

The registration process has two layers. Businesses and organisations with an Australian Business Number (ABN) register their sender IDs through their message provider or telco — these intermediaries handle the actual registration with ACMA. On the other side, message carriers and providers must themselves apply to participate in the register if they want to transmit messages with registered sender IDs after 1 July 2026. Both layers need to be active for traffic to flow.

The timeline is compressed. With the deadline thirteen days away from publication, organisations that haven't started registration need to act immediately. The registration process runs through commercial intermediaries, and delays will multiply as providers approach the cutover date. Teams managing transactional SMS, customer notifications, appointment reminders, and authentication messages face the most immediate exposure.

It's important to note that the requirement applies only to alphanumeric sender IDs — not numeric originator numbers or short codes. If your organisation's outbound SMS uses a standard phone number or numeric code rather than a branded text string, you are not directly affected by the July deadline. However, many enterprise messaging systems use alphanumeric IDs precisely because they look clearer and more professional to recipients, so the compliance footprint is likely to be broad across Australian businesses.

The two-tier structure ACMA has created does introduce a dependency: if your current message provider hasn't yet applied to participate in the register, you cannot complete your own registration through that vendor. Compliance teams should verify their provider's participation status now, not at the last moment.

Australia has been progressively strengthening its SMS security framework. ACMA announced the register in October 2025, giving the industry roughly eight months to prepare. Legal and compliance analysts flagged the obligation for Australian businesses early — see DLA Piper's January 2026 analysis. The requirement was visible well in advance, yet deadline-driven compliance always compresses in the final weeks.

Sender ID registries exist in other countries. The UK's SMS SenderID Protection Registry, operated by the Mobile Ecosystem Forum, runs a comparable scheme, and several Asian markets have implemented similar controls. What sets the ACMA approach apart is its statutory backing and the explicit service-disruption consequence for non-compliance — carriers have a clear obligation to block unregistered IDs, not merely a recommendation to filter them.

For teams managing engineering and operations, the action list is straightforward: identify every alphanumeric sender ID currently in use across your outbound SMS infrastructure, confirm your message provider is a registered participant in the ACMA scheme, and initiate registration for each ID before the cutover. If your current provider is not yet a participant, the comfortable window for processing is closed — switching to a participating provider may now be the faster path.

The register itself is a structural control rather than a detective one. It will not catch every SMS fraud attempt, but it removes one of the easiest attack vectors: a scammer trivially spoofing a trusted brand name. That narrowing of the surface available to attackers is the practical intent.