Smishing works because the recipient can't tell your traffic from a lookalike. The playbook that holds up is four tenant-owned layers: register the sender identities you legitimately use, keep your own drafts clean, watch for hostile candidates against a watchlist of your brand tokens, and file takedowns with a prepared evidence pack. Each layer maps to a control you run yourself.
1. Register the sender identities you own
Smishing defense starts at the sender-identity layer — not at the message-content layer. Each sender class has its own registration mechanism: 10DLC brand and campaign registration in the US, alphanumeric sender-ID rules that vary per market, RCS verified senders, and WhatsApp business profiles. Carriers and receiving networks treat registered sender identity as the baseline signal that separates your legitimate traffic from a spoofed label.
Registering also raises the impersonation bar: when your sender classes are enrolled, a hostile sender-ID candidate that borrows your brand token is visible as such, and a takedown filing can point at a registered record. The per-country walk-through lives in Sender-ID registration by country, and the document-filing loop is worked end to end in The KYC loop checklist. The definitions post separates smishing from SMS pumping and caller-ID spoofing, so you file the right abuse class when a wave hits.
Registration does not block a hostile message — it makes the hostile sender visible as an impersonator. The remaining layers close the rest of the loop.
2. Protect your own drafts at compose time
Defense at the sender-identity layer is necessary but not sufficient — clean identity does not stop a bad URL. The SMS, WhatsApp, RCS, and batch compose surfaces scan every URL in your draft against heuristic phishing, malware, and smishing checks (punycoded or raw-IP hosts, embedded open-redirects, abused TLDs, smishing lure keywords) at compose time. A flagged URL is labelled Suspicious or Malicious with the top reasons shown inline, advisory by design.
Keep the URL panel on, resolve flags before send, and do not treat the scanner as a substitute for the offload layers below. It protects only the drafts you actually compose — the hostile candidates in your customers' inboxes are out of its reach.
3. Watch hostile candidates against your watchlist
The Brand Impersonation Monitor on Settings → Compliance holds the tenant-owned watchlist: the brand names, domains, and sender IDs you declare. Each candidate you observe — a suspicious domain, an SMS/RCS sender ID, or a display name — is scored against the watchlist for typosquatting, homoglyph spoofing, and other lookalike patterns, and banded clean (monitor), suspicious (investigate), or malicious (urgent takedown).
That scoring is what separates your own validly composed traffic from a lookalike candidate worth acting on. It never blocks or sends anything — scoring and banding only — which is why the watchlist layer is a screening instrument, not a gate.
4. File takedowns with a prepared evidence pack
When a candidate is worth acting on, the takedown case opens from the scan result with a filing-ready evidence pack: the matched watchlist token, the scoring detail behind the band, and the recommended abuse-desk contact. The lifecycle (open → evidence ready → reported → resolved) advances in your dashboard, and the case can be dismissed as a false positive. The service stays advisory: it never advances a case status on its own, and it never routes anything.
The operator walk-through for wiring the watchlist and running takedown cases over the API lives in the brand-impersonation takedown guide. Keep both surfaces in the loop: the dashboard panel for the human loop, the API for CI-driven screening.
Frequently asked questions
Does sender registration block smishing on its own?
No. Registration raises the impersonation bar and gives you a filed record to point at — it does not screen the messages you send or the hostile candidates your customers receive. Registration is layer one of four; the draft-clean, watchlist, and takedown layers close the rest of the loop.
What is a tenant-owned watchlist, and why is it the right shape?
The Brand Impersonation Monitor holds the brand names, domains, and sender IDs that belong to you, declared by you, isolated to your account. The scanner compares candidates you observe against those tokens — the watchlist is why the score separates your legitimate sender tokens from a lookalike candidate, not a generic global blocklist.
What does an evidence pack contain?
A takedown case opens with the matched watchlist token, the candidate's scoring detail (typosquat closeness, homoglyph spoofing, exact-label-on-wrong-TLD, and similar named findings), and the recommended abuse-desk contact for the candidate class. The pack exists for filing — it is not a blocking gate.
Which layer catches a bad link in my own draft?
The compose-time URL-reputation layer. The SMS, WhatsApp, RCS, and batch compose surfaces scan every URL in your draft as you type, label a flagged URL with the top reasons inline, and stay advisory — so you can resolve the flag before send, deliberately, never by surprise.