Messaging compliance & security articles
Sending commercial messages means staying within the law and keeping the service from being abused. These articles cover sender duties under the Unsolicited Electronic Messages Ordinance, OFCA’s “#” Sender ID registration, OTP and SMS pumping protection, and permissions and review for multi-team accounts.
-
How Scammers Use SMS: Hong Kong & Taiwan Cases, Consumer Defences, and What Providers Can Do
Publicly documented SMS/smishing patterns in Hong Kong and Taiwan, consumer reporting channels, and how rigorous A2P SMS providers can reduce platform abuse across KYC, content, traffic and sender identity.
Read article → -
SMS vendor due diligence for Hong Kong banks and brokerages — non-forwardable routes, # Sender ID, DLR audit trail, data residency
Compliance rarely rejects an SMS purchase over price. It rejects it because nobody can answer five kinds of question — route, identity, evidence, data, operations. A questionnaire financial institutions can send to any SMS vendor as-is, with the risk behind each question explained.
Read article → -
What is non-forwardable SMS? Why Hong Kong financial institutions need it, when a text actually gets forwarded, and how to set it up
SMS is not "non-forwardable" by default — carrier SMS-forwarding services and one-card-two-number plans will send a one-time password to a different handset. How the non-forwardable route works in Hong Kong, the pre-assigned long numbers carriers use for it, and the extra setup cost and lead time when you want your own # Sender ID on that route.
Read article → -
OTP Bombing and SMS Pumping Protection — Hong Kong Enterprise Guide (2026)
How do OTP bombing and SMS pumping (AIT) work? Prelude 2025: 11.83% of verification requests fraudulent. Rate limits, number-range monitoring, route separation, and six UFOSEND-ready controls.
Read article → -
Letting branches, agents and departments each manage their own lists — teams, roles and optional maker-checker
Use teams to separate business units, departments and agencies inside one account so each only sees its own lists and campaigns, then optionally add a maker-checker step where operators submit and reviewers approve. Five roles, the isolation rules, and four worked scenarios.
Read article → -
Registering a # Sender ID in Hong Kong — a practical guide to the OFCA scheme
How Hong Kong businesses obtain a dedicated "#" sender name under the OFCA SMS sender-registration scheme — naming rules, documents required, the secure network requirement, and what gets applications bounced.
Read article → -
Six pitfalls in OTP SMS implementation — from code design to SMS bombing defence
OTP looks like "send a number". Expiry, resend windows, rate limiting, route separation and AIT fraud defence all bite when they are wrong. The six we see most often in production integrations.
Read article → -
Hong Kong promotional messaging compliance checklist — what the UEMO requires of senders
Read before sending promotional SMS or MMS to Hong Kong numbers. Sender information, unsubscribe facilities, the 10-working-day rule, the three Do-not-call Registers — the ordinance's duties and a checklist you can actually run.
Read article → -
Phishing SMS scams
How phishing SMS works, how Hong Kong's OFCA sender-registration scheme (# Sender ID) helps counter it, and how businesses should protect their brand and their customers.
Read article → -
What SIM card real-name registration means for SMS providers
How Hong Kong's SIM card real-name registration scheme affects business SMS — legitimate routes versus SIM-based sending, and why it improves the industry.
Read article → -
What is an SMS code? How one-time passcodes (OTP) work
An SMS code is a one-time passcode used to confirm a login or a transaction. How the code is delivered, why dedicated routes and character limits matter, and best practice against social engineering.
Read article → -
Sending SMS to mainland China
Compliance requirements for sending SMS to mainland China — the signature format, the mandatory unsubscribe line, and what you need to know about keywords.
Read article →