Guardivia

Grey Routes and Bypass

What is Sender ID manipulation?

Reviewed 2026-09-12 by the Guardivia QoS Engineering Team

In short

Sender ID manipulation occurs when the displayed sender identity is changed, spoofed, substituted or otherwise presented differently from the expected authorised identity. It can be associated with fraud, bypass, phishing or unauthorised routing, and it is one of the clearest indicators available that a message did not travel the route it was supposed to.

Two different problems

Manipulation at submission and manipulation in transit look similar on a handset but mean very different things. At submission, an unauthorised party declares a Sender ID it has no right to use — this is impersonation, and the target is the subscriber. In transit, an intermediary replaces the legitimate Sender ID with something else — usually a local mobile number — and the target is the operator's billing.

The second case is the one that exposes grey routing, because a legitimate, agreed route has no reason to rewrite a registered sender identity.

Why routes substitute senders

Alphanumeric Sender IDs are frequently restricted to A2P channels. A message terminating through a SIM box physically cannot present one, because it is being sent from a real SIM and inherits that SIM's MSISDN.

So a bank's OTP submitted as "BANKNAME" arrives from a local number nobody recognises. The subscriber's trust in the message drops, the bank's support desk fills up, and the operator is the party in the middle receiving both complaints.

Variation attacks

A subtler form substitutes a near-identical sender rather than a different one: a substituted character, an added full stop, different spacing, a lookalike glyph from another script. The result passes an exact-match registry check while being visually indistinguishable to a subscriber.

Detecting these requires normalised comparison against the registry — folding case, stripping punctuation, mapping confusable characters — rather than literal equality.

Proving it happened

Submission records show what was sent. Only the receiving device shows what arrived. Guardivia's Honeypot SMS Testing platform compares the two directly, reporting the received Sender ID alongside content, encoding, message parts and timing.

One caveat worth stating plainly: a changed Sender ID is a strong indicator, not automatic proof of fraud. Some networks legitimately normalise sender formats, and regulatory rules in certain markets require substitution. The verdict should correlate the change with route, Global Title, CDR, SMSC and operator evidence before a route is classified.

Discuss this with the engineers who build the platform

Questions about how this applies to your network go straight to the QoS Engineering Team.