What is non-forwardable SMS? Why Hong Kong financial institutions need it, when a text actually gets forwarded, and how to set it up
Published
On this page
Key takeaways
- Whether a text gets forwarded is decided by the recipient’s carrier, not the sender: once a subscriber has SMS forwarding or a one-card-two-number plan switched on, every message follows.
- In 2011 Hong Kong’s banks and mobile carriers agreed that OTP messages from banks and stored-value facilities are delivered only to the registered handset, forwarding or not.
- It works through a set of long sender numbers pre-assigned between carriers; messages sent through that route are never forwarded.
- Using the pre-assigned numbers is immediate; putting your own # Sender ID on the non-forwardable route needs a fresh configuration at every carrier, with a setup fee and lead time.
- Non-forwardable only closes the forwarding hole; phishing and social engineering still need # Sender IDs and customer education.
Your OTP messages need to be on the right route. We connect directly to the local carriers, verification traffic can be placed on the non-forwardable route, and every DLR is the carrier’s own. See business SMS or contact us for a route check.
The IT head of a brokerage asked us a good question: “Isn’t SMS delivered point-to-point to that mobile number? Why do we need to buy ‘non-forwardable’ on top?”
The answer: a text is delivered to a number, not a handset. Which handset sits behind that number, and whether the message is copied to another one, is decided by the recipient’s carrier network. The sender has no say.
When does a text get forwarded?
Three common cases, the first two entirely on the recipient’s carrier network:
- The carrier’s SMS-forwarding service. Every major Hong Kong carrier offers a value-added service of this kind (3 Hong Kong’s “SMS Divert”, for instance) that copies incoming texts to another mobile number or an email address. It exists for people who travel or carry two phones, but once someone switches it on in a subscriber’s name, every text — bank OTPs included — is copied to the chosen destination.
- One-card-two-number plans. Mainland and overseas operators sell plans where one SIM also receives the texts of a Hong Kong number. Technically the Hong Kong number’s messages are being forwarded to another network. When the Hong Kong Association of Banks extended the # SMS Sender Registration Scheme to banks, it stated explicitly that the scheme does not apply to subscribers of such plans from non-Hong Kong operators.
- The user’s own device settings. iPhone’s Text Message Forwarding, for example, mirrors texts to an iPad or Mac. The sender cannot prevent this either, and it sits outside the carrier’s non-forwardable arrangement — worth knowing, but it only reaches devices the user is signed into.
The first two are what fraudsters target. In 2019 local media demonstrated that with nothing more than the subscriber’s ID card number (one carrier’s online account password defaulted to it at the time), they could log in, switch on SMS forwarding, use the forwarded codes to reset a payment wallet’s password and move money out — all in under an hour. HKCERT followed with an advisory on unauthorised SMS forwarding.
Why financial institutions in particular need it
Because in finance the text message is the authentication factor:
- login and transaction one-time passwords for internet banking and trading apps
- confirmation codes for binding a new device, changing transfer limits, adding a payee
- registration and transfer verification for stored-value facilities
If the code can be forwarded, the premise “you hold this phone” collapses and SMS OTP stops being “something you have”. That is why, as far back as 2011, the HKMA announced that the banking industry had agreed with the mobile carriers that OTP messages from banks and stored-value facilities are delivered only to the customer’s registered handset, whether or not SMS forwarding is active. After the 2019 incident the carrier concerned restated the same mechanism publicly: if a financial institution or stored-value facility gives the carrier its non-forwardable sender numbers, messages from those numbers are not forwarded.
In other words, this is not one vendor’s proprietary feature. It is a long-standing mutual arrangement between Hong Kong’s carriers. The only question is whether your traffic is on it.
How it actually works
The mechanism is straightforward:
- The carriers have pre-assigned a set of dedicated sender numbers between them. They are long numbers, not ordinary eight-digit mobile numbers, and commonly start with prefixes such as 6115… or 6119… (the exact range is carrier-assigned and varies by route).
- Each carrier’s network lists those numbers as non-forwardable. Any message from them is delivered only to the originally registered SIM, even when the subscriber has forwarding on.
- Your SMS platform pins OTP traffic to that route, so it goes out with those numbers as the sender.
So “non-forwardable” is a routing setting, not a flag inside the message. The one thing you have to do is confirm your vendor has direct, non-forwardable routes to every local carrier and put your verification traffic on them. At UFOSEND this is configured per use at account level: OTP on the non-forwardable route, promotions on the standard route, and the delivery receipts (DLR) for both are the carrier’s own status, not an estimate — see SMS DLR status codes explained.
What if you want your own # Sender ID?
The second most common question, and the most underestimated.
Since 2024 Hong Kong’s banks have moved to # Sender IDs under the OFCA SMS Sender Registration Scheme, so customers see “#BankName” rather than a string of digits. The natural follow-up: can we show #YourBrand and be non-forwardable at the same time?
Yes, but it is a different project:
| Carrier pre-assigned non-forwardable numbers | Your own # Sender ID on the non-forwardable route | |
|---|---|---|
| What the customer sees | A long number (e.g. 6115…) | #YourBrand |
| Carrier configuration | Already exists, use immediately | Every carrier must add a matching non-forwardable entry for this Sender ID |
| Lead time | Short | Wait for each carrier to complete its setup |
| Cost | Non-forwardable surcharge on top of the standard rate | Plus a one-off setup fee |
The reason is that non-forwardable is a mutually recognised list between carriers. Adding a Sender ID means adding an entry at every carrier and mapping them to each other — a manual process, hence the fee and the wait. Most institutions end up with: OTP on the pre-assigned numbers (fast, stable), branded notifications and promotions on the # Sender ID (recognisable), with a note in the app that “your verification code will arrive from a number starting 6115”. That is the starting point we recommend; apply carrier by carrier for #YourBrand non-forwardable only when you genuinely need it.
What non-forwardable does not solve
Being honest about the boundary avoids buying it and assuming everything is covered:
- Phishing SMS: a fraudster impersonating you has nothing to do with forwarding. That needs # Sender IDs plus customer education.
- The customer reading the code out to a fraudster: social engineering, which no route can stop. The HKMA’s push to replace SMS OTP with bound devices for high-risk transactions targets exactly this.
- SIM swap: the whole number moves to a new SIM, and texts naturally follow. That is the carrier’s real-name and replacement-verification process.
- OTP flooding / SMS pumping: a sender-side cost problem; see OTP flooding and SMS pumping protection.
Treat non-forwardable as the baseline configuration for OTP traffic, not as the whole of your security.
Pre-integration checklist
- Which sender number does your OTP traffic go out from today? Confirm with the vendor that it is on the carriers’ non-forwardable lists.
- Does the vendor connect directly to each local carrier, rather than hopping through an overseas aggregator? On a grey route the list simply never applies — see Grey routes vs direct carrier connections.
- Are verification and promotional messages on separate routes with separate Sender IDs?
- Is there a real DLR you can show an auditor to prove “delivered to the registered handset”?
- If you want your own # Sender ID on the non-forwardable route, get the setup fee and each carrier’s lead time in writing and put it on the launch plan.
To see whether your existing OTP traffic is on the right route, contact us for a route check, or start a free trial and send a test to a number of your own with forwarding switched on — trial credit on signup, no credit card required.
FAQ
What sender does a non-forwardable message show?
By default the carrier-assigned long number (for example one starting 6115). Showing your own # Sender ID needs separate configuration at each carrier.
Should promotional SMS also go non-forwardable?
No. Non-forwardable is designed for verification codes and transaction confirmations; promotions go on the standard route with a # Sender ID, at lower cost.
Can it stop an iPhone mirroring texts to an iPad?
No — that is syncing between the user’s own devices and never touches the carrier. It only appears on devices signed into the same Apple account.
Can I ask an overseas SMS provider for non-forwardable?
Only if that provider has a direct connection in Hong Kong and holds the local carriers’ non-forwardable configuration. Otherwise the message arrives on the local network as an ordinary international text and the list does not apply.