# PureSMS and Ofcom's rules on combatting mobile messaging scams

> PureSMS already complies with Ofcom's new anti-scam rules for A2P messaging (General Condition C9), a year ahead of the July 2027 deadline. KYC on every sender, verified Sender IDs in every country, no generic senders, continuous traffic monitoring with random human audits, automatic scam URL blocking, and immediate suspension of suspected scam senders.

## What Ofcom has decided

On 15 July 2026, Ofcom published its statement [Combatting mobile messaging scams](https://www.ofcom.org.uk/phones-and-broadband/scam-calls-and-messages/consultation-combatting-mobile-messaging-scams), introducing General Condition C9 and accompanying guidance for providers. For the first time, every UK mobile operator and messaging aggregator will be required to:

- Run Know Your Customer (KYC) checks on business senders (GC C9.10)
- Verify Sender IDs before allowing their use (GC C9.11)
- Maintain policies restricting protected and generic Sender IDs (GC C9.13)
- Conduct ongoing Know Your Traffic (KYT) checks (GC C9.12)
- Block messages containing known scam URLs automatically (GC C9.7)
- Act on suspected scam senders within one working day (GC C9.15)

The A2P messaging rules come into force on 15 July 2027.

As an A2P provider, PureSMS welcomes this regulation. Every provider that skips these checks makes SMS less trustworthy for everyone, and it is end users who pay the price when scammers impersonate trusted brands. Regulation raises the floor. PureSMS is already well above it.

## Already compliant, ahead of the deadline

| Ofcom will require (from July 2027) | PureSMS does (today) |
| --- | --- |
| KYC checks on new senders (GC C9.10) | Full KYC on every new sender before a single message is sent: identity, company details and intended use |
| Sender ID checks (GC C9.11) | Every Sender ID, for every sender, in every country, pre-registered and verified before use: domain verification, terms and conditions, privacy policy and company checks, with per-country approvals |
| Protected and generic Sender ID policies (GC C9.13) | Generic senders ("Alert", "Delivery", "Security") are not allowed at all; every sender name must identify a real, verified organisation |
| Know Your Traffic checks (GC C9.12) | Continuous automated monitoring of traffic patterns, backed by random human compliance audits |
| Automated scam URL blocking (GC C9.7) | Messages containing suspected spam or scam URLs are blocked automatically, in transit |
| Incident management within 1 working day (GC C9.15) | Suspected scam senders are blocked or suspended automatically the moment they are detected, pending human review |

### Beyond Ofcom: data protection

PureSMS is fully compliant with both UK and EU GDPR in how it handles data. As part of sender checks, PureSMS also validates that customers' messaging complies with the Privacy and Electronic Communications Regulations (PECR), including having a proper basis to contact recipients.

As far as we know, PureSMS is the only UK provider that already operates every one of these controls as standard.

## Why we do it

These controls were not built for Ofcom. They exist because a sender's deliverability, sender reputation and their customers' trust ride on the quality of everyone's traffic on the platform. Compliance is how PureSMS protects its customers, their reputation and its own, and how it keeps delivery reliable, month after month.

- Sign up: https://new.puresms.app (no credit card required)
- Contact: https://puresms.uk/ContactUs
- HTML version of this page: https://puresms.uk/Compliance
