Legal & Compliance

Australia’s SMS Sender ID Register goes live, and unregistered branded messages now look untrustworthy by design

Australia’s communications regulator, ACMA, brought its SMS Sender ID Register into force on 1 July 2026. From that date, branded SMS and MMS sent to Australian numbers from a registered sender ID continue to display the organisation’s name, while messages from unregistered branded sender IDs must be labelled ‘Unverified’ by the carrier. Unverified messages are also grouped into a single thread with other unregistered senders, including potential scams. The register exists to stop text-message impersonation of trusted brands and public bodies, and ACMA is monitoring compliance, with telcos facing court-ordered penalties of up to A$250,000 per contravention of the register rules.

How it works

Sender IDs are the names that appear at the top of a text in place of a phone number, the ‘AusPost’, ‘StarTrack’, or ‘myGov’ label that tells a recipient who is writing. Under the new rules, an organisation registers its branded sender IDs through a participating telco or messaging provider, with registration anchored to Australian Business Register records. Registered IDs display as before. Unregistered IDs lose the brand name entirely and arrive as ‘Unverified’, filed alongside whatever else the carrier could not identify that day.

The presentation detail is the punishment. A legitimate appointment reminder from an unregistered brand does not merely lose its label. It lands in the same thread as the scam messages the recipient has been trained to distrust. As ACMA’s Samantha Yorke warned ahead of the deadline, unverified labelling means legitimate messages may simply be ignored or deleted, and “that puts legitimate communications and brand trust at risk.”

This is BIMI logic, made mandatory

Email readers will recognise the architecture immediately. Verified sender identity earns brand display at the message-list level. Unverified identity gets a generic, faintly suspicious presentation. That is the trust model the email industry built voluntarily with BIMI and Verified Mark Certificates, where authentication plus verified brand ownership earns a logo in the inbox. Australia has now made the same model mandatory in an adjacent channel, with a regulator rather than mailbox providers setting the rules and a penalty regime behind it.

The direction of travel is regional and consistent. Singapore’s SMS Sender ID Registry has run on similar lines since 2023, with unregistered senders labelled as likely scams. And in the same fortnight as ACMA’s go-live, Japan’s anti-phishing council urged senders towards DMARC reject, BIMI, and passkeys as phishing surged through compromised ISP mailboxes [INTERNAL LINK: Japan anti-phishing story]. Regulators and national ecosystems are increasingly willing to bake anti-spoofing controls into consumer-facing message presentation, not just back-end enforcement. Sender identity verification is going multichannel, and the inbox-level trust mark is becoming the enforcement surface.

Why email teams should care

The obvious reason is operational. Australian customer journeys typically run email, transactional SMS, security codes, and promotional messaging under a single brand-identity layer, usually managed by the same team. A brand that fails to register faces lower response and heightened fraud suspicion on appointment reminders, account notices, OTPs, and promotional texts, and that erosion of trust does not stay neatly contained in one channel.

The less obvious reason is displacement. When impersonating a brand over SMS becomes visibly self-defeating, the pressure does not disappear. It moves to the channels where spoofing still pays, and email remains the largest of them. Brands strengthening their SMS identity should expect attackers to probe their email identity harder, which makes DMARC enforcement, and increasingly BIMI, the matching move rather than a separate project.

We flagged the register’s development in our guide to ACMA’s compliance priorities, and it now sits alongside an aggressive enforcement record that includes more than A$5.4 million in wagering-sector penalties and this month’s [A$2.7 million action against TAB](INTERNAL LINK: TAB/ACMA story). Australia is regulating message trust at both ends: punishing consent failures behind the scenes and now labelling identity failures on the handset itself.

What to do

Any organisation sending branded SMS to Australian numbers should confirm its sender IDs are registered through its telco or messaging provider, and audit every route a branded message can take, including third-party platforms sending on the brand’s behalf, since one unregistered route is enough to put ‘Unverified’ next to your name. Multinational senders should treat the register as a template rather than a one-off. The combination of mandatory registration, visible labelling, and carrier-level enforcement is cheap for regulators to copy, and the markets most exposed to smishing will be watching how Australia’s version performs.

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory