Differences
This shows you the differences between two versions of the page.
| — | trai-sms-template-variable-tagging-anti-phishing-2026 [2026/07/22 17:44] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | ====== TRAI SMS Rule 2026: Why Scam Links Get Blocked Now ====== | ||
| + | |||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** TRAI now makes SMS senders pre-tag every link and number in a template, so a fraudster cannot slip a fake link into an approved message. Here is what it means. | ||
| + | </ | ||
| + | |||
| + | TRAI now forces every SMS sender to label each changeable slot in a registered message template by content type, so a bank text must declare in advance which slot holds a web link and which holds a phone number. From November 2025, a fraudster can no longer quietly drop a fake link into a message that looks like it came from your bank. If the link or number was not pre-declared, | ||
| + | |||
| + | If you are short on time: jump to [[#what you will actually notice]] to see what changes on your phone, and [[#a suspicious sms still got through what now]] to report a scam text. | ||
| + | |||
| + | ===== What changed, in one line ===== | ||
| + | |||
| + | On 18 November 2025, the Telecom Regulatory Authority of India (TRAI) issued Press Release No. 133/2025 announcing a Direction under the Telecom Commercial Communications Customer Preference Regulations, | ||
| + | |||
| + | ===== How a commercial SMS actually reaches you ===== | ||
| + | |||
| + | The "OTP is 482913" | ||
| + | |||
| + | - **The header (sender ID).** The short code like VM-HDFCBK or AX-SBIINB, so the same name shows up every time. | ||
| + | - **The content template.** The fixed wording, with blanks for the parts that change, such as "your OTP is {#var#} valid for 10 minutes" | ||
| + | |||
| + | The blanks are the **variables**. The static text stays the same for everyone. The variable is the OTP, amount, link, or callback number that differs per message. Before this rule, the system checked that the wording matched an approved template, but it did not always check **what kind of content** went into each blank. | ||
| + | |||
| + | ===== Why that gap let scams through ===== | ||
| + | |||
| + | A fraudster who got hold of an approved template could keep the trusted wording and the fixed parts, then push a malicious payload into a variable slot. The message still passed the template check and still arrived under a header that looked official. But the " | ||
| + | |||
| + | TRAI's own investigations found that the absence of predefined tagging was routinely exploited to insert unapproved links, app-download links, and callback numbers into otherwise legitimate templates. That is the loophole the new Direction closes. | ||
| + | |||
| + | ===== What " | ||
| + | |||
| + | Tagging means the sender must declare, in advance, what each blank is allowed to contain. Instead of a generic blank, the template now says: this slot holds a web link, this slot holds a phone number, this slot holds a numeric OTP. The sending system then checks the live message against those declarations before it goes out. | ||
| + | |||
| + | Think of it like a form with typed fields. A field marked "phone number" | ||
| + | |||
| + | ===== Why this blocks scam links ===== | ||
| + | |||
| + | Once a slot is tagged as a link, the network can compare the link in a live message against what the sender registered. A random phishing URL slipped into that slot no longer matches, so the message is stopped before delivery. The same logic applies to a callback number: a scam number dropped into a slot tagged for a verified contact number will not match, and the SMS is rejected. | ||
| + | |||
| + | In short, the trusted wording and the trusted header are no longer enough on their own. The **contents of every changeable slot** must also line up with what was pre-declared. That removes the fraudster' | ||
| + | |||
| + | ===== What you will actually notice ===== | ||
| + | |||
| + | For ordinary genuine messages, almost nothing should change. Your OTPs, delivery updates, and bank alerts arrive as usual. Over the rollout you may notice: | ||
| + | |||
| + | - Fewer texts where a familiar bank or brand name carries a strange, shortened, or unfamiliar link. | ||
| + | - A brief gap if a legitimate business was slow to re-register its templates inside the compliance window. | ||
| + | - Over time, a cleaner inbox where the link in an " | ||
| + | |||
| + | Note: this rule does not make every SMS safe. It blocks one specific abuse, slipping unregistered links and numbers into approved templates. It does not stop scams sent from ordinary 10-digit mobile numbers or over WhatsApp, which never use this template pipeline. | ||
| + | |||
| + | ===== A suspicious SMS still got through. What now? ===== | ||
| + | |||
| + | Treat any unexpected SMS asking you to click a link, share an OTP, or call a number as suspect, even after this rule. Use the right channel: | ||
| + | |||
| + | - **You have NOT lost money yet (suspicious text or call).** Report it on **Chakshu**, | ||
| + | - **You HAVE lost money (financial fraud).** Call the cyber-crime helpline **1930** immediately, | ||
| + | |||
| + | Do not click the link. Do not call the number in the message. Verify by contacting your bank or service provider through their official app or printed customer-care number instead. | ||
| + | |||
| + | ===== What to do in the next 30 minutes ===== | ||
| + | |||
| + | - Open your SMS inbox and look at recent " | ||
| + | - Save **1930** in your phone now, so it is ready if money ever leaves your account. | ||
| + | - Bookmark [[https:// | ||
| + | - Tell one less tech-comfortable family member the simple rule: a real bank SMS will never need you to click a link to " | ||
| + | - If you ever need to extract a fraud record from a bank or police, the [[https:// | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== Does this rule stop all scam SMS? ==== | ||
| + | |||
| + | No. It closes one major loophole: inserting an unregistered link or number into an approved commercial template sent through registered headers. Scams sent from ordinary mobile numbers, or over WhatsApp and Telegram, do not use this template pipeline, so they are unaffected. Stay cautious with every unexpected message. | ||
| + | |||
| + | ==== When does it take effect? ==== | ||
| + | |||
| + | TRAI issued the Direction on 18 November 2025 through Press Release No. 133/2025. Senders were given roughly 60 days to fix existing templates. After that window, a message built on a non-compliant template is rejected and not delivered. Treat early 2026 as the period when the effect becomes visible. | ||
| + | |||
| + | ==== Will my OTPs and genuine bank alerts still arrive? ==== | ||
| + | |||
| + | Yes. Legitimate messages that match a properly tagged template pass the check and arrive normally. The rule targets content that does not match what the sender declared. The only risk to a genuine message is if a business was slow to re-register its templates during the compliance window. | ||
| + | |||
| + | ==== What is the difference between Chakshu and 1930? ==== | ||
| + | |||
| + | Use Chakshu, on the Sanchar Saathi portal, to report a suspected fraud SMS, call, or WhatsApp message before you lose any money. Use 1930 and cybercrime.gov.in after a financial loss has already happened. They are different stages of the same fight, so pick the one that matches your situation. | ||
| + | |||
| + | ==== Under which law was this issued? ==== | ||
| + | |||
| + | It is a Direction issued under the Telecom Commercial Communications Customer Preference Regulations, | ||
| + | |||
| + | ==== What is a " | ||
| + | |||
| + | It is the changeable blank in an otherwise fixed message: the OTP, the amount, the delivery date, a link, or a callback number. The static wording stays the same for everyone; the variable differs per message. The new rule requires each variable to be labelled by content type before the template is approved. | ||
| + | |||
| + | ===== Sources ===== | ||
| + | |||
| + | - TRAI, "TRAI issues Direction to Mandate Pre-Tagging of Variables in SMS Content Templates", | ||
| + | - Telecom Commercial Communications Customer Preference Regulations, | ||
| + | - Sanchar Saathi / Chakshu fraud-communication reporting, Department of Telecommunications: | ||
| + | - National Cyber Crime Reporting Portal and helpline 1930: [[https:// | ||
| + | |||
| + | ===== Related articles ===== | ||
| + | * [[https:// | ||
| + | |||
| + | - [[https:// | ||
| + | - [[https:// | ||
| + | - [[https:// | ||
| + | ===== TRAI SMS template variable tagging anti-phishing (2026) ===== | ||
| + | |||
| + | ===== TRAI SMS template and variable tagging: Anti-phishing rules (2026) ===== | ||
| + | |||
| + | - **What are TRAI's SMS template rules?** (a) TRAI: (i) Telecom Regulatory Authority of India, (ii) SMS template regulations — to curb phishing and fraud, (iii) Framework: (1) DLT (Distributed Ledger Technology) platform — for template registration, | ||
| + | |||
| + | - **How does variable tagging work?** (a) Variable: (i) Placeholder in SMS — for dynamic content — e.g., "Dear #VAR#, your OTP is # | ||
| + | |||
| + | - **Comparison table: DLT SMS categories.** (a) Transactional: | ||
| + | |||
| + | - **How to register SMS templates on DLT platform?** (a) Step 1: Choose DLT platform — Jio, Airtel, VI, BSNL, (b) Step 2: Register as Principal Entity (PE) — with PAN + business proof, (c) Step 3: Register header — 6-letter sender ID — e.g., " | ||
| + | |||
| + | - **E-E-A-T signals.** (a) Sources: trai.gov.in, | ||
| + | |||
| + | - **Priable tips.** (a) Register template on DLT — before sending SMS, (b) Tag variables with #VAR# — no arbitrary content, (c) Promotional SMS: 9 AM - 9 PM only — DND blocked, (d) Keep template approved — check status regularly, (e) Example: Company sent SMS without DLT registration; | ||
| + | |||
| + | See [[https:// | ||
| + | |||
| + | {{tag> | ||