The Mobile Ecosystem Forum (MEF) published an article on 15 July 2026 analysing the new anti-scam SMS rules issued by UK communications regulator Ofcom. MEF noted that the new rules aim to raise industry security standards, while arguing that regulation should remain proportionate to avoid imposing excessive compliance burdens on the industrial chain.
MEF explained that Ofcom’s new rules cover both P2P person-to-person SMS and A2P application-to-person SMS traffic. For P2P messages, Ofcom requires mobile operators to set SMS sending limits for prepaid SIM cards, accept reports from users and anti-fraud bodies, block scam numbers and malicious links, and intercept fraudulent SMS in transit. For A2P services, the new obligations apply to both mobile operators and SMS aggregators, mandating onboarding KYC due diligence and ongoing KYT traffic reviews, verifying the authenticity of alphanumeric Sender‑IDs to prevent spoofing, and establishing incident response workflows to block scam messages on the transmission path.
MEF states A2P aggregators and CPaaS providers will bear the highest operational compliance costs, and Sender‑ID validation requires sophisticated contextual monitoring systems. MEF mentions this UK regulatory package carries global demonstrative value and will be referenced by regulators in other countries. MEF also cautions that technical feasibility must be considered; regulation should be calibrated carefully and avoid undue interference with legitimate commercial SMS services.
Under Ofcom’s timeline, P2P provisions take effect on 18 January 2027, and A2P obligations come into force on 15 July 2027. This regulation applies only to SMS/MMS number-based messaging; OTT internet messaging services such as WhatsApp fall outside its scope.
