Guardivia

SS7 and SIGTRAN Security

What is SRI-SM and why is it important for SMS security?

Reviewed 2026-09-12 by the Guardivia QoS Engineering Team

In short

Send Routing Information for Short Message (SRI-SM) is a MAP procedure used during SMS routing, in which the sending SMSC asks the recipient's HLR where that subscriber currently is. Monitoring SRI-SM behaviour helps operators identify abnormal routing requests, unauthorised network activity, information exposure and certain forms of messaging abuse.

What the query returns

Before delivering a mobile-terminated message, the sending SMSC issues SRI-SM to the destination subscriber's HLR. A normal response contains the subscriber's IMSI and the address of the serving MSC or SGSN — everything needed to deliver the message, and rather more than a stranger should learn about a subscriber.

That is the security tension at the heart of this procedure: the information required for delivery is also the information required to locate, track or impersonate a subscriber.

Abuse patterns visible in SRI-SM

Because every genuine MT delivery is preceded by an SRI-SM, the ratio and shape of these queries is highly diagnostic:

  • High SRI-SM volumes with few or no subsequent delivery attempts, suggesting information harvesting rather than messaging
  • Sequential queries walking through an MSISDN range, indicating enumeration
  • Queries from Global Titles with no messaging relationship with the operator
  • SRI-SM results that do not match the path the message subsequently took, an indicator of route manipulation
  • Repeated queries for the same subscriber from unrelated sources in a short window

How home routing changes the picture

With SMS home routing, the HLR does not hand out the real serving-node address. It answers with the address of the home SMSC or firewall, usually together with a correlation identifier. The originating network then delivers the message into the home network, which screens it and performs the real delivery itself.

This has two effects that matter here. Subscriber information stops leaking to every network that asks, and inbound international and roaming traffic is forced through a point where policy can be applied. Attempts to avoid that path — delivering without a preceding SRI-SM, or ignoring the returned address — are themselves a strong bypass indicator.

Discuss this with the engineers who build the platform

Questions about how this applies to your network go straight to the QoS Engineering Team.