SMS from companies: what changes on September 15 and what gets blocked

The SMS from companies change from this September 15. The operators will have to block messages that use names or business aliases not registered in the CNMC registry and also certain shipments made through unauthorized providers.

1 minute

fotonoticia 20260619153256 1920

fotonoticia 20260619153256 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

1 minute

Most read

The messages that arrive on the mobile identified directly with the name of a bank, a courier company, a clinic, or any other company enter this Tuesday into a new stage.

Since September 15, operators must block SMS, MMS, and RCS that use a business alias not listed in the register created by the National Commission of Markets and Competition. They will also have to prevent messages with registered aliases when they come from unauthorized providers to use them.

What is an SMS alias

The alias is the name that appears as the sender of the message instead of a phone number. It can be the name of a bank, a company, an administration, or a brand.

The objective of the new system is to make it difficult for a scammer to fraudulently introduce the name of a known company as the sender of an SMS.

As of September 10, the CNMC counted 13,565 aliases registered in its registry.

What will happen if a company does not register

Here is one of the keys to the change: the company is not completely incapacitated to send messages.

It will be able to continue sending them, but it will not be able to present them using its commercial alias. That is, the message may arrive from a conventional number instead of automatically appearing under the name of the brand. The CNMC allows new aliases to be registered even after September 15.

How a user can check it

The CNMC has a public consultation of registered aliases that allows checking if an identifier is registered and to whom it corresponds.

The system adds a barrier against smishing, but it does not make any received SMS infallible. Users should continue to distrust unexpected requests for passwords, banking keys, or payments and check links before using them.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What legal requirements does the CNMC demand to register a business alias and what documentation must the applicant company provide?

The “business alias” before the CNMC is the alphanumeric identifier (brand, trade name, company name, or domain) that appears as the sender of SMS, MMS, or RCS messages instead of a phone number. Its registration in the Alias Registry is mandatory to continue using it as a sender from the dates set in Order TDF/149/2025 and CNMC Circular 1/2026.

1. Who can request the alias registration

According to the CNMC itself, the following can register an alias:

  • The alias holder: private companies or public administrations that use that name to communicate with their customers or users.
  • Authorized third parties: entities or messaging service providers acting on behalf of the alias holder.

In the latter case, the CNMC has specified that the procedure requires the express authorization of the holder of the alias and a subsequent verification by the body to validate the request.

2. Legal and technical requirements the alias must meet

From Circular 1/2026 and the CNMC's informative guides ( explanatory entry on the Alias Registry ), the essential requirements can be summarized as:

  • Legitimate linkage: the alias must be legitimately linked to a brand, trade name, company name, or domain of the holder. It cannot be an arbitrary name unrelated to the entity.
  • Actual use in communications: the alias is intended for SMS, MMS, or RCS messages that the company already uses or will use to communicate with its customers (delivery notices, appointments, commercial communications, reminders, etc.).
  • Format requirements: it must comply with the technical rules set by the CNMC:
    • Maximum and minimum length of the alias.
    • Allowed character set (letters, numbers, and certain signs).
    • Avoid confusion with other already registered aliases or specially protected denominations.
  • Uniqueness and absence of impersonation: the alias cannot mislead about the sender's identity nor impersonate another entity; the CNMC verifies that the requester has the legitimate right to use it.

These criteria are developed in Circular 1/2026 and in the technical reference CIR/DTSA/010/25, cited by the CNMC as a detailed document.

3. Documentation the applicant company must provide

Official notes and guides emphasize that the applicant entity must “demonstrate its relationship with the brand, trade name, or domain it wishes to use and comply with the technical conditions set in the circular.” From there, the documentation is structured into three blocks:

  • Identification of the entity holding the alias
    The company or administration must provide its basic identification data through the CNMC's electronic form (identity of the holder, NIF/CIF, etc.), which allows linking the alias to a clearly determined subject.
  • Proof of ownership or right to use the alias
    The CNMC requires that the legitimate linkage of the alias with the company be proven. For this, in practice, the entity must attach documentation proving that the alias matches or is associated with its:
    • company name,
    • trade name or brand, or
    • own internet domain.
    The circular authorizes the CNMC to verify that linkage and reject applications when it does not obtain unequivocal confirmation from the applicant.
  • Authorization when a third party acts
    If the application is not submitted directly by the holder but by a messaging service provider or another entity, it is mandatory to provide express authorization from the alias holder. The CNMC has indicated that, in the absence of such clear authorization, requests must be rejected.

4. Procedure and validation by the CNMC

Once the application is submitted with the required information and documentation, the CNMC:

  • Verifies the identity of the holder and, if applicable, of the representative or provider acting on their behalf.
  • Checks the legitimate linkage between the proposed alias and the brand, trade name, company name, or domain of the entity.
  • Reviews that the alias complies with the format rules and does not cause confusion with other already registered aliases.

If the application does not pass these checks — for example, due to technical problems or lack of unequivocal authorization — the CNMC denies it, which, according to the body itself, is causing a significant number of rejections.

5. Where to consult the regulatory details

To know precisely all the legal and documentary requirements applicable to alias registration, the CNMC refers to:

In case of doubt, it is advisable to review those texts directly or, if the company acts through a messaging provider, coordinate with them so that the application includes all the required documentation and avoids rejections.

What powers and functions does the National Commission on Markets and Competition have in telecommunications?

In telecommunications, the National Commission on Markets and Competition (CNMC) acts as an independent regulator and supervisor of electronic communications markets in Spain. Its powers are mainly based on Law 3/2013, establishing the CNMC, and Law 11/2022, General Telecommunications Law, which designate it as the national regulatory body and develop its specific functions in this sector.

1. Ex ante regulation and market analysis

Law 3/2013 establishes that the CNMC must define and analyze the relevant markets related to electronic communications networks and services, both wholesale and retail, and delimit their geographic scope. When this analysis shows that effective competition does not exist, the CNMC:

  • Identifies operators with significant market power (SMP) in those markets.
  • Imposes specific ex ante obligations on those operators, in line with the framework of the General Telecommunications Law and its implementing regulations (access, transparency, price control, accounting separation, non-discrimination, etc.).
  • Periodically reviews the markets and, if competition improves, can modify or withdraw obligations.
2. Supervision and compliance control

The CNMC is responsible for supervising and controlling the proper functioning of electronic communications markets, according to Law 3/2013 and Law 11/2022. This includes:

  • Monitoring compliance with obligations imposed in market analyses.
  • Controlling that operators respect rules on access, infrastructure sharing, and use of essential resources.
  • Exercising inspection and sanction powers when sector regulations or CNMC decisions are violated.
3. Resolution of disputes between operators

Law 3/2013 assigns the CNMC the competence to resolve disputes in electronic communications markets, for example:

  • Disputes over technical or economic interconnection conditions.
  • Disagreements over access to networks and physical infrastructures capable of hosting high and very high capacity networks.
  • Conflicts arising from regulatory obligations imposed on an SMP operator.

These decisions are binding and are part of its function to ensure effective competition and access to essential infrastructures.

4. Protection of end users

Law 11/2022 details CNMC functions related to end users of electronic communications services:

  • Determine the methodology to calculate the net cost of universal service and manage the national universal service fund, including setting operator contributions and auditing economic information.
  • Specify, after consulting the competent ministry, the quality of service parameters, measurement methods, and how information should be made available to the public.
  • Require operators to publish complete, comparable, and reliable information on service quality and conduct periodic studies on quality in rural and sparsely populated areas.
  • Establish conditions and technical aspects of operator switching and number portability, as well as measures to adequately protect and inform users during that process.
  • Request information from operators to verify compensations and other subscriber rights (e.g., in operator changes or service failures).
5. Numbering, interconnection, and access

The CNMC plays a central role in managing numbering and addressing resources and in interconnection architecture:

  • Set, through circulars, technical and administrative conditions for number portability and operator switching.
  • Supervise the supply of numbering data by operators and its provision to services such as directories, subscriber queries, or emergency calls.
  • Regulate, through its involvement in market analyses, obligations of interconnection and access to networks and physical infrastructures, coordinating when appropriate with other authorities (e.g., on critical infrastructures).
6. Spectrum and European cooperation

The primary allocation of spectrum and the definition of public radio spectrum policy correspond to the Government and the competent ministry, but Law 11/2022 foresees:

  • CNMC reports on certain decisions affecting public service or coverage obligations linked to spectrum.
  • The use by the CNMC of information from geographic coverage and deployment studies for exercising its functions.

At the European level, Law 3/2013 indicates that the CNMC must regularly cooperate with the European Commission and other regulators, particularly through the Body of European Regulators for Electronic Communications (BEREC). This cooperation ensures coherent application of the European electronic communications framework and guidelines on market analysis, operator obligations, and user protection.

7. Relationship with the competent Ministry

The CNMC is an independent body but is attached to an economic ministry and coordinates with the ministry responsible for telecommunications. Schematically:

  • The Government and the ministry define general policy, draft the General Telecommunications Law and its regulations, and manage the public radio spectrum.
  • The CNMC applies that framework technically and independently in the markets: it analyzes, regulates, supervises, sanctions, and resolves disputes, ensuring effective competition and user rights.

Overall, the CNMC is the operational regulatory pillar of the electronic communications sector in Spain, under a framework of functional independence but in constant interaction with the ministry and European institutions.

How many similar initiatives to combat smishing have been approved in the European Union in recent years?

Based on the information found, there is no specific and exclusive body of legislation on “smishing” (SMS fraud) in the European Union equivalent to the Spanish measures for blocking fraudulent SMS. What exists are major horizontal reforms on payment services and fraud prevention that also cover SMS-based frauds, but without focusing solely on that channel.

Therefore, if we understand “similar initiatives” as European regulations whose main and explicit purpose is to combat smishing or fraudulent SMS, the number of regulations approved in recent years is, to date, practically zero. However, if a broader definition is accepted (anti-fraud instruments that also cover scams committed via SMS), there is indeed a large recent legislative package relevant at the EU level.

1. The large recent European package: PSR and PSD3

From the European documents consulted, it appears that the main EU legislative initiative with direct impact on frauds often relying on SMS (including smishing) is the new payment services framework, composed of:

  • A Payment Services Regulation (PSR), aiming to harmonize payment rules and strengthen fraud prevention across the EU.
  • A Third Payment Services Directive (PSD3), which revises and updates the current PSD2 to adapt the framework to new payment methods and reinforce supervision and competition.

According to the EU Council note of June 18, 2025, Member States agreed on their negotiating position on this package, aiming to:

  • “Reduce payment fraud” and “establish a comprehensive anti-fraud framework,”
  • include electronic communications providers and messaging platforms within the fraud prevention perimeter,
  • ensure consumers are not disadvantaged as a result of fraudulent behavior.

Subsequently, the European Parliament note of November 27, 2025 confirms that Parliament and Council reached a political agreement on the PSR and PSD3. Among the agreed measures:

  • Obligation for payment service providers (PSPs) to:
    • verify that the beneficiary's name and unique identifier (e.g., IBAN) match, denying the operation if discrepancies exist,
    • ensure strong customer authentication and risk assessments,
    • offer spending limits and blocking mechanisms to reduce fraud risk.
  • Rules of enhanced liability: if a provider has not implemented adequate prevention mechanisms, it must bear losses; transactions initiated or modified by a fraudster are considered “unauthorized” and the provider must reimburse the customer.
  • Protection against identity fraud (when the fraudster impersonates the bank or payment provider), obliging reimbursement to the customer if they report to the police and inform their PSP.
  • Possibility to hold online platforms liable when hosting fraudulent content linked to payment scams, strengthening interaction with the Digital Services Act.

Although neither the Council nor the Parliament mention the term “smishing” in these communications, the type of fraud they describe —impersonating the payment provider and deceiving the user into approving operations— clearly covers schemes currently channeled through SMS, calls, or instant messaging.

2. Can we talk about a number of “anti-smishing laws” in the EU?

With the available information, it can be summarized as follows:

  • No directive or European regulation whose main and explicit purpose is “to combat smishing” as a specific technique has been identified. European regulation tends to be technology-neutral, focused on payment fraud and identity theft regardless of the channel (SMS, email, apps, etc.).
  • There is a central legislative package (Payment Services Regulation + PSD3) which, due to its anti-fraud content and inclusion of electronic communications providers in prevention, is directly relevant to fighting scams committed via SMS.
  • That package was the subject of a political agreement between Parliament and Council in November 2025, but official notes remind that it still must be “formally adopted” before entering into force. That is, it is an advanced and agreed initiative, but its final legal act is not yet described as fully approved and in force in the sources consulted.

Consequently, and based on the reviewed sources, only a large recent European regulatory package with direct impact on frauds like smishing (PSR + PSD3) can be clearly spoken of, rather than a numerous set of “anti-smishing” laws in the strict sense. The Spanish sectoral regulation on SMS blocking and alias registration is, for now, more channel-specific than EU regulation, which focuses on the outcome (payment fraud and impersonation) rather than the technical tool used.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What measure comes into effect on September 15 regarding SMS with business aliases?

Question 1 of 3

What is the main objective of the new regulation on aliases in business SMS?

Question 2 of 3

What does the CNMC allow users to do regarding alias registration?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?