📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

Differences

This shows you the differences between two versions of the page.


trai-sms-template-variable-tagging-anti-phishing-2026 [2026/07/22 17:44] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +{{htmlmetatags>metatag-description=(TRAI now makes SMS senders pre-tag every link and number in a template, so a fraudster cannot slip a fake link into an approved message. Here is what it means.)&metatag-keywords=(TRAI SMS rule 2026, SMS phishing block, pre-tagging variables, fraud SMS report 1930, Sanchar Saathi Chakshu)&metatag-robots=(index,follow)&metatag-og:title=(TRAI SMS Rule 2026: Why Scam Links Get Blocked Now)&metatag-og:description=(TRAI now makes SMS senders pre-tag every link and number in a template, so a fraudster cannot slip a fake link into an approved message. Here is what it means.)&metatag-og:type=(article)}}
  
 +====== TRAI SMS Rule 2026: Why Scam Links Get Blocked Now ======
 +
 +
 +
 +{{ :social:auto:trai-sms-template-variable-tagging-anti-phishing-2026.png?direct&1200 |TRAI SMS Rule 2026: Why Scam Links Get Blocked Now — RTI Wiki}}
 +
 +<WRAP center round info 95%>
 +**Quick Reply:** TRAI now makes SMS senders pre-tag every link and number in a template, so a fraudster cannot slip a fake link into an approved message. Here is what it means.
 +</WRAP>
 +
 +TRAI now forces every SMS sender to label each changeable slot in a registered message template by content type, so a bank text must declare in advance which slot holds a web link and which holds a phone number. From November 2025, a fraudster can no longer quietly drop a fake link into a message that looks like it came from your bank. If the link or number was not pre-declared, the network rejects the SMS and it never reaches you.
 +
 +If you are short on time: jump to [[#what you will actually notice]] to see what changes on your phone, and [[#a suspicious sms still got through what now]] to report a scam text.
 +
 +===== What changed, in one line =====
 +
 +On 18 November 2025, the Telecom Regulatory Authority of India (TRAI) issued Press Release No. 133/2025 announcing a Direction under the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR 2018). The Direction tells phone companies and bulk senders to pre-tag every variable field in their SMS templates. Senders have about 60 days to fix existing templates. After that window, messages built on a non-compliant template are rejected and not delivered. (Source: [[https://www.trai.gov.in/notifications/press-release/trai-issues-direction-mandate-pre-tagging-variables-sms-content|TRAI Direction, 18 November 2025]].)
 +
 +===== How a commercial SMS actually reaches you =====
 +
 +The "OTP is 482913" text from your bank travels through a regulated pipeline built under TCCCPR 2018. Two things are registered in advance with the operators:
 +
 +  - **The header (sender ID).** The short code like VM-HDFCBK or AX-SBIINB, so the same name shows up every time.
 +  - **The content template.** The fixed wording, with blanks for the parts that change, such as "your OTP is {#var#} valid for 10 minutes".
 +
 +The blanks are the **variables**. The static text stays the same for everyone. The variable is the OTP, amount, link, or callback number that differs per message. Before this rule, the system checked that the wording matched an approved template, but it did not always check **what kind of content** went into each blank.
 +
 +===== Why that gap let scams through =====
 +
 +A fraudster who got hold of an approved template could keep the trusted wording and the fixed parts, then push a malicious payload into a variable slot. The message still passed the template check and still arrived under a header that looked official. But the "link" inside it now pointed to a phishing page, or the "callback number" rang a scam call centre.
 +
 +TRAI's own investigations found that the absence of predefined tagging was routinely exploited to insert unapproved links, app-download links, and callback numbers into otherwise legitimate templates. That is the loophole the new Direction closes.
 +
 +===== What "tagging variables" actually means =====
 +
 +Tagging means the sender must declare, in advance, what each blank is allowed to contain. Instead of a generic blank, the template now says: this slot holds a web link, this slot holds a phone number, this slot holds a numeric OTP. The sending system then checks the live message against those declarations before it goes out.
 +
 +Think of it like a form with typed fields. A field marked "phone number" rejects letters. A field marked "web link" rejects a stranger's URL that was never registered. If the actual content does not match the declared type, the message fails the check.
 +
 +===== Why this blocks scam links =====
 +
 +Once a slot is tagged as a link, the network can compare the link in a live message against what the sender registered. A random phishing URL slipped into that slot no longer matches, so the message is stopped before delivery. The same logic applies to a callback number: a scam number dropped into a slot tagged for a verified contact number will not match, and the SMS is rejected.
 +
 +In short, the trusted wording and the trusted header are no longer enough on their own. The **contents of every changeable slot** must also line up with what was pre-declared. That removes the fraudster's favourite trick: borrowing a genuine template and quietly swapping the dangerous part.
 +
 +===== What you will actually notice =====
 +
 +For ordinary genuine messages, almost nothing should change. Your OTPs, delivery updates, and bank alerts arrive as usual. Over the rollout you may notice:
 +
 +  - Fewer texts where a familiar bank or brand name carries a strange, shortened, or unfamiliar link.
 +  - A brief gap if a legitimate business was slow to re-register its templates inside the compliance window.
 +  - Over time, a cleaner inbox where the link in an "official" SMS is far more likely to be the real one.
 +
 +Note: this rule does not make every SMS safe. It blocks one specific abuse, slipping unregistered links and numbers into approved templates. It does not stop scams sent from ordinary 10-digit mobile numbers or over WhatsApp, which never use this template pipeline.
 +
 +===== A suspicious SMS still got through. What now? =====
 +
 +Treat any unexpected SMS asking you to click a link, share an OTP, or call a number as suspect, even after this rule. Use the right channel:
 +
 +  - **You have NOT lost money yet (suspicious text or call).** Report it on **Chakshu**, the fraud-communication reporting facility on the Department of Telecommunications portal **[[https://sancharsaathi.gov.in/|Sanchar Saathi]]**. Chakshu is for flagging a suspected fraud SMS, call, or WhatsApp message before any loss happens.
 +  - **You HAVE lost money (financial fraud).** Call the cyber-crime helpline **1930** immediately, then file a complaint at **[[https://www.cybercrime.gov.in/|cybercrime.gov.in]]**. Speed matters here; the sooner you report, the better the chance of freezing the transfer.
 +
 +Do not click the link. Do not call the number in the message. Verify by contacting your bank or service provider through their official app or printed customer-care number instead.
 +
 +===== What to do in the next 30 minutes =====
 +
 +  - Open your SMS inbox and look at recent "bank" or "delivery" texts. If any carries an odd link, do not click it.
 +  - Save **1930** in your phone now, so it is ready if money ever leaves your account.
 +  - Bookmark [[https://sancharsaathi.gov.in/|Sanchar Saathi]] to report a suspicious text on Chakshu.
 +  - Tell one less tech-comfortable family member the simple rule: a real bank SMS will never need you to click a link to "verify" or "reactivate" your account.
 +  - If you ever need to extract a fraud record from a bank or police, the [[https://righttoinformation.wiki/book|The RTI Playbook]] shows how to frame the request, and the [[https://righttoinformation.wiki/tools/ai-rti-draft-app.html|AI RTI Drafter]] helps you write it.
 +
 +===== Frequently asked questions =====
 +
 +==== Does this rule stop all scam SMS? ====
 +
 +No. It closes one major loophole: inserting an unregistered link or number into an approved commercial template sent through registered headers. Scams sent from ordinary mobile numbers, or over WhatsApp and Telegram, do not use this template pipeline, so they are unaffected. Stay cautious with every unexpected message.
 +
 +==== When does it take effect? ====
 +
 +TRAI issued the Direction on 18 November 2025 through Press Release No. 133/2025. Senders were given roughly 60 days to fix existing templates. After that window, a message built on a non-compliant template is rejected and not delivered. Treat early 2026 as the period when the effect becomes visible.
 +
 +==== Will my OTPs and genuine bank alerts still arrive? ====
 +
 +Yes. Legitimate messages that match a properly tagged template pass the check and arrive normally. The rule targets content that does not match what the sender declared. The only risk to a genuine message is if a business was slow to re-register its templates during the compliance window.
 +
 +==== What is the difference between Chakshu and 1930? ====
 +
 +Use Chakshu, on the Sanchar Saathi portal, to report a suspected fraud SMS, call, or WhatsApp message before you lose any money. Use 1930 and cybercrime.gov.in after a financial loss has already happened. They are different stages of the same fight, so pick the one that matches your situation.
 +
 +==== Under which law was this issued? ====
 +
 +It is a Direction issued under the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR 2018), the framework that governs commercial SMS, headers, and content templates in India. Press Release No. 133/2025 records the Direction.
 +
 +==== What is a "variable" in an SMS template? ====
 +
 +It is the changeable blank in an otherwise fixed message: the OTP, the amount, the delivery date, a link, or a callback number. The static wording stays the same for everyone; the variable differs per message. The new rule requires each variable to be labelled by content type before the template is approved.
 +
 +===== Sources =====
 +
 +  - TRAI, "TRAI issues Direction to Mandate Pre-Tagging of Variables in SMS Content Templates", Press Release No. 133/2025, dated 18 November 2025: [[https://www.trai.gov.in/notifications/press-release/trai-issues-direction-mandate-pre-tagging-variables-sms-content|trai.gov.in notification]].
 +  - Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR 2018), Telecom Regulatory Authority of India.
 +  - Sanchar Saathi / Chakshu fraud-communication reporting, Department of Telecommunications: [[https://sancharsaathi.gov.in/|sancharsaathi.gov.in]].
 +  - National Cyber Crime Reporting Portal and helpline 1930: [[https://www.cybercrime.gov.in/|cybercrime.gov.in]].
 +
 +===== Related articles =====
 +  * [[https://righttoinformation.wiki/trai-ai-spam-detection-block-without-complaint-2026|TRAI 2026: telcos must AI-block spam without a complaint]]
 +
 +  - [[https://righttoinformation.wiki/fake-pan-update-sms-scam-india|Fake PAN update SMS scam: how to spot and report it]]
 +  - [[https://righttoinformation.wiki/fake-kyc-update-scam-india|Fake KYC update scam: detect, block and recover]]
 +  - [[https://righttoinformation.wiki/report-fake-mobile-apps-india|How to report fake mobile apps in India]]
 +===== TRAI SMS template variable tagging anti-phishing (2026) =====
 +
 +===== TRAI SMS template and variable tagging: Anti-phishing rules (2026) =====
 +
 +  - **What are TRAI's SMS template rules?** (a) TRAI: (i) Telecom Regulatory Authority of India, (ii) SMS template regulations — to curb phishing and fraud, (iii) Framework: (1) DLT (Distributed Ledger Technology) platform — for template registration, (2) Header registration — 6-letter sender ID, (3) Content template registration — approved before use, (4) Variable tagging — variables marked with #VAR#, (b) Key rules: (i) Every SMS template must be registered — on DLT platform, (ii) Variables must be tagged — #VAR# — cannot inject arbitrary content, (iii) Unregistered templates — blocked by telecom operators, (iv) Entity (brand) must be registered — with PE (Principal Entity) ID.
 +
 +  - **How does variable tagging work?** (a) Variable: (i) Placeholder in SMS — for dynamic content — e.g., "Dear #VAR#, your OTP is #VAR#", (ii) Each variable must be declared — at time of template registration, (iii) Variable content cannot contain: (1) URLs/links, (2) Phone numbers (unless approved), (3) OT-ITC content, (4) Special characters that alter template, (b) Tagging rules: (i) Variable enclosed in #VAR# — e.g., #VAR#, (ii) Variable length — declared at registration — cannot exceed, (iii) Variable content — must match declared pattern, (iv) No mixing — of static and variable content — outside approved template.
 +
 +  - **Comparison table: DLT SMS categories.** (a) Transactional: (i) Purpose: OTP, account alerts, (ii) Header: 6-letter — starting with letters, (iii) Timing: 24/7, (iv) DLT scrubbing: yes — template match, (b) Promotional: (i) Purpose: marketing, offers, (ii) Header: 6-letter — random, (iii) Timing: 9 AM - 9 PM only, (iv) DLT scrubbing: yes — + DND check, (c) Service-implicit: (i) Purpose: service messages — to existing customers, (ii) Timing: 24/7, (iii) DLT scrubbing: yes, (d) Service-explicit: (i) Purpose: service messages — with consent, (ii) Timing: 24/7, (iii) DLT scrubbing: yes — + consent check. (Note: Promotional SMS to DND numbers — blocked. Transactional SMS — allowed to DND.)
 +
 +  - **How to register SMS templates on DLT platform?** (a) Step 1: Choose DLT platform — Jio, Airtel, VI, BSNL, (b) Step 2: Register as Principal Entity (PE) — with PAN + business proof, (c) Step 3: Register header — 6-letter sender ID — e.g., "RTIWIKI", (d) Step 4: Register content template — with variables tagged #VAR#, (e) Step 5: Get approval — typically 24-48 hours, (f) Step 6: Share approved template ID — with SMS service provider, (g) Step 7: Send SMS — using approved template + header.
 +
 +  - **E-E-A-T signals.** (a) Sources: trai.gov.in, dlt.airtel.in, dlt.jio.in, (b) Last reviewed: July 2026.
 +
 +  - **Priable tips.** (a) Register template on DLT — before sending SMS, (b) Tag variables with #VAR# — no arbitrary content, (c) Promotional SMS: 9 AM - 9 PM only — DND blocked, (d) Keep template approved — check status regularly, (e) Example: Company sent SMS without DLT registration; SMS blocked by operator; registered on DLT; template approved in 24 hours; SMS delivered successfully.
 +
 +See [[https://righttoinformation.wiki/trai-sms-template-variable-tagging-anti-phishing-2026|TRAI SMS Rules]] and [[https://righttoinformation.wiki/how-to-file-rti-india|How to File RTI]].
 +
 +{{tag>trai 2026 india sms template dlt variable tagging anti-phishing principal entity header 2026}}