Skip to content
Messaging & A2P SMS

SMS Firewall & Messaging Security

Protect subscribers, brands and A2P revenue - grey-route and spoofing detection, smishing and SIM-farm analytics, content filtering and monetisation controls for mobile operators and enterprises.

SMS Firewall & Messaging Security - Dollu
  • < 50 ms

    Inline filtering latency

  • 24×7

    SOC threat monitoring

  • 100%

    A2P traffic visibility

Overview

What is SMS Firewall & Messaging Security?

SMS remains the channel that fraudsters, spammers and grey-route operators target hardest, because it reaches every handset and carries the passcodes that guard bank accounts. Dollu's SMS firewall gives mobile operators, MVNOs and large enterprises the visibility and control to stop that abuse: every message crossing the interconnect or the enterprise sender is inspected in real time, classified and either delivered, blocked, throttled or flagged according to policy - with decisions taken inline in under 50 milliseconds.

For operators, the firewall sits at the SS7 and SMPP edges of the network. It detects grey routes - international A2P traffic disguised as person-to-person to avoid termination fees - through signalling analysis, sender and SMSC address validation, volume patterns and content fingerprints. It closes spoofing of subscriber and enterprise sender IDs, identifies SIM farms and SIM-box clusters generating artificial traffic, and blocks smishing campaigns by analysing URLs, brand impersonation and message templates. Blocked grey traffic is redirected to contracted A2P channels, converting leakage into revenue.

For enterprises and brands, the same engine protects outbound messaging: it prevents your registered sender IDs from being spoofed on our network, filters outbound content against regulatory and carrier policies before it can be blocked downstream, detects OTP-pumping and artificially inflated traffic against your account and reports on impersonation attempts targeting your customers. Banks, payment providers and government agencies use it to keep the SMS channel trustworthy for the people who depend on it.

The firewall is a managed service. Dollu's messaging security team maintains the threat intelligence - global sender ID registries, malicious URL feeds, SIM-farm signatures and content classifiers updated hourly - tunes rules to each customer's traffic profile and monitors alerts around the clock from our SOC. Deployment options include a hosted service, an on-premises virtualised appliance for operators with data-residency requirements, and a hybrid model where policy is central and enforcement is local.

How it fits together

A2P SMS path: from your application to the handset.

A2P SMS path: from your application to the handset.Application · HTTPS or SMPP · gateway · operator SMSC · handset, with delivery receipts returning on the same pathYour applicationCRM · bank · platformHTTPS APISMPP 3.4DOLLU SMS GATEWAYSender-ID registryDLT · 10DLC · alphanumeric IDsSMS firewallcontent · velocity · AIT patternsRouting enginedirect binds first · DLR-verifiedOperator SMSC800+ direct connectionsSMPPHandsetsubscriberSS7 / MAPdelivery receipts (DLR): delivered · undelivered · expired, returned to your webhook or SMPP sessionRegistered sender IDs and templates are checked before routing; the firewall drops spoofed traffic and AIT-pattern bursts before they cost you.Direct operator binds mean fewer hops, faster OTP delivery and receipts that reflect the handset rather than an intermediate hub.
Reading the diagramYour application submits messages over the HTTPS API or an SMPP 3.4 bind. The Dollu SMS gateway checks the sender ID against the registry (DLT, 10DLC and country-specific registrations), passes traffic through the SMS firewall for content, velocity and artificially inflated traffic patterns, and routes over direct operator binds - more than 800 of them - to the subscriber's handset. Delivery receipts travel back along the same path to your webhook or SMPP session.
Why Dollu

Why choose Dollu for sms firewall.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • Recover A2P revenue

    Grey routes leaking into your network are identified, blocked and redirected to contracted channels, turning bypass into billable enterprise traffic within weeks of go-live.

  • Protect subscribers from fraud

    Smishing, spoofed bank alerts and scam campaigns are stopped before delivery, reducing complaints, regulatory exposure and the reputational damage of a fraud wave.

  • See every message class

    Real-time classification of P2P, A2P, international and domestic traffic by sender, route and content gives operators and enterprises a complete picture of what flows and why.

  • Keep your brand's sender safe

    Enterprises gain sender ID protection and impersonation alerts so customers can trust that a message from your name is really from you.

  • Respond in real time

    Alerts to your NOC, fraud or security team within seconds of an anomaly, with automated blocking rules that contain an attack before humans join.

Capabilities

Capabilities in detail.

Everything included with SMS Firewall & Messaging Security - the platform features, options and controls you get from day one.

  1. 01

    Multi-protocol inspection

    SS7 MAP (MO-ForwardSM, MT-ForwardSM, SRI-SM) and SMPP inspection at international gateway and SMSC; Diameter and SIP MESSAGE support for 4G/5G cores; sub-50 ms inline decisions.

  2. 02

    Grey-route detection

    Correlation of signalling origin, SMSC and sender addresses, MSISDN ranges, volume and timing patterns and content fingerprints to identify A2P disguised as P2P and SIM-box termination.

  3. 03

    Anti-spoofing controls

    Validation of originating address against home-network and roaming data, SMSC allow-lists, global title checks and blocking of unauthorised use of enterprise sender IDs and subscriber MSISDNs.

  4. 04

    Smishing and content security

    Real-time URL analysis against malicious and newly registered domain feeds, brand impersonation detection, template clustering and content classifiers tuned per language and market.

  5. 05

    SIM-farm and AIT analytics

    Behavioural profiling of SIMs and IMEIs, cluster detection, velocity and diversity scoring and OTP-pumping detection with automated quarantine and evidence for enforcement.

  6. 06

    Policy engine

    Rules by sender type, route, content class, destination and time; actions to deliver, block, throttle, quarantine or redirect; A/B evaluation of rules before enforcement; per-tenant policies for MVNOs.

  7. 07

    A2P monetisation

    Sender registration portal, allow-listing of contracted aggregators, redirection of blocked grey traffic to commercial channels, and settlement-grade reporting for revenue-share and reconciliation.

  8. 08

    Managed threat intelligence

    Hourly updates of sender registries, malicious URL feeds, SIM-farm signatures and campaign fingerprints drawn from our 800+ operator connections and SOC investigations.

  9. 09

    Reporting and integration

    Real-time dashboards, scheduled compliance reports, SIEM integration via syslog and API, and evidence exports for regulators and law-enforcement requests.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Assess

    We run a two-week traffic audit on a mirrored feed or sample dataset to quantify grey-route leakage, spoofing, smishing and SIM-farm activity, and estimate the revenue at stake.

  2. Step 02

    Deploy

    The firewall is deployed hosted, on-premises or hybrid, integrated with your SS7 STP, SMSC or SMPP hub, and run in monitor-only mode while rules are tuned to your traffic.

  3. Step 03

    Enforce

    Blocking, throttling and redirection policies are switched on progressively by category, with your team approving each stage and our SOC watching for false positives.

  4. Step 04

    Monetise and maintain

    Grey traffic is redirected to contracted A2P channels, settlement reporting starts and our team maintains threat intelligence and rule tuning under a managed-service SLA.

Compare

Direct, premium or grey.

Where an SMS route class shows up: in delivery, in the sender ID your customer sees, in the truthfulness of the delivery receipt and in the compliance risk you carry.

A2P SMS route classes compared on delivery, sender ID, delivery-receipt quality, compliance risk and price.
DimensionDirect operatorPremium aggregatedGrey routesNot offered by Dollu
DeliveryDirect SMPP bind to the mobile operator; the highest and most consistent deliveryVia a vetted hub or Tier-1 aggregator holding operator agreements; high delivery with occasional re-routingVia SIM farms or unauthorised international paths; unpredictable, filtered and blocked without notice
Sender IDRegistered alphanumeric ID, short code or long number preserved exactlyRegistered sender ID normally preserved; may be substituted on a few destinationsOverwritten with a random numeric sender; your brand is invisible
DLR qualityHandset delivery receipts from the operatorOperator or hub receipts; reliable, occasionally delayedFake or aggregator-generated receipts; no proof of delivery
Compliance riskLowest - operator-approved, with DLT, 10DLC or sender-ID registration completed up frontLow - operator agreements in place; Dollu vets every hub it usesHigh - breaches operator terms and local law; carries fines, blacklisting and lost sender IDs
Price positionHighest per message; the lowest cost per delivered, verified messageMidLowest headline price; the hidden cost is failed OTPs, blocked traffic and brand damage

Dollu does not sell grey routes. Every destination on our deck is direct operator or premium aggregated, and the route class is shown against each price so you know exactly what you are buying.

Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Mobile network operators

    Close grey routes, protect subscribers from smishing and turn international A2P into a monetised product with firewall enforcement and settlement reporting.

  • MVNOs and MVNEs

    Per-tenant policies and reporting on a shared platform, giving each brand protection without running its own security stack.

  • Banks and payment providers

    Sender ID protection, impersonation monitoring and outbound content checks so customers can trust security alerts and OTPs.

  • Aggregators and hubs

    Traffic hygiene on inbound binds to keep operator relationships healthy and avoid route suspensions caused by abusive customers.

  • Government and public services

    Protect citizen-facing sender IDs from spoofing and ensure emergency and public advisories are not imitated by fraudsters.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

Inspection pointsSS7 MAP (STP/HLR/SMSC), SMPP, Diameter, SIP MESSAGE
LatencyInline decision < 50 ms; monitor-only mode available
DetectionGrey route, spoofing, smishing, SIM farm/SIM box, AIT, spam
ActionsDeliver, block, throttle, quarantine, redirect, alert
DeploymentHosted, on-premises virtual appliance, or hybrid
ThroughputScales to tens of thousands of messages per second per site
Threat intelligenceHourly feed updates; SOC-curated signatures and registries
IntegrationSIEM via syslog/API, sender registration portal, settlement reports
ComplianceGDPR data handling; ISO 27001-aligned operations; audit trails
Support24×7 SOC and NOC; P1 response ≤ 15 min; managed-service SLA
Pricing model

How Messaging is priced.

A2P, OTP and promotional SMS are priced per message by destination and route class - direct operator or premium aggregated. Wholesale SMPP decks for aggregators; RCS and WhatsApp per conversation or session.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Per message · by country & route
  • Direct-operator and premium route tiers per destination
  • Sender ID and DLT registration assistance included
  • Volume-based discounts by monthly message count
  • Two-way inbound priced per number
  • RCS and WhatsApp Business per conversation or session
Billing
Per submitted message, itemised by destination and route; prepaid or postpaid
Commitment
None - month-to-month; volume commitments unlock better tiers
Request a rate deckActual rates within one business day.
Where it is available

220+ destinations, 800+ operator connections.

Direct operator binds and premium aggregated routes into every major mobile network. Country guides explain the sender-ID rules, KYC and route options in the markets we are asked about most.

Sender-ID registration markets

In these destinations A2P traffic is scrubbed unless the sender is pre-registered. Dollu’s compliance desk prepares and submits the registrations before your first message.

  • IndiaDLT entity, header and template registration
  • UAESender IDs registered with e& and du under TDRA rules
  • Saudi ArabiaSender IDs registered with stc, Mobily and Zain under CST rules
  • SingaporeSMS Sender ID Registry (SSIR); UEN required
  • PhilippinesSender-ID whitelisting with Globe, Smart and DITO
  • United States10DLC brand and campaign registration
FAQ

SMS Firewall - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

A grey route is a path that delivers international A2P traffic into a network disguised as person-to-person messaging, or via SIM boxes, to avoid the operator's A2P termination fees. It costs the operator revenue, bypasses content and sender controls and often carries spam or fraud. The firewall identifies it by signalling, sender and content analysis and redirects it to contracted channels.

Let’s talk

Find out what is leaking through your network.

Ask for a two-week traffic audit and we will quantify grey-route volume, spoofing and smishing activity and the A2P revenue you could recover.

Abstract globe with connected network lines