The Spanish National Commission for Markets and Competition (CNMC) has approved the creation of a national Alias Registry, a mandatory database for any brand or entity wishing to send commercial SMS, MMS, or RCS messages to Spanish mobile numbers. The move is a direct regulatory assault on smishing—the fraudulent practice of impersonating trusted companies via text message to steal personal data—aiming to create a more secure communications environment by 2026.
The Mechanics of the New Alias Registry System
The core function of the CNMC’s Alias Registry is to establish a verified identification system for commercial text message senders. From now on, any organization using a brand name, commercial alias, or alphanumeric sender ID to communicate with customers or the public via SMS in Spain must first register that identifier in the official database. Failure to do so will result in the messages being blocked by network operators before they reach the recipient’s phone.
The registry will compile all permissible alphanumeric identifiers—combinations of letters, numbers, and other characters used as the sender field. The CNMC, which will manage the system, will provide public access through a portal on its website. This transparency allows any citizen to verify which aliases are officially registered and identify the legitimate entity behind them, turning a previously opaque field into a publicly accountable one.
Who Must Register and How
According to the official circular, registration is open to alias holders themselves—including companies and public administrations—or to messaging service providers acting on their behalf. To successfully register an alias, applicants must provide documented proof linking the alias to a legitimate brand, trade name, corporate denomination, or domain. Furthermore, the alias must comply with strict technical and formatting rules outlined by the regulator to prevent spoofing and mimicry of official entities.
Strict Obligations for Messaging Providers to Enforce the Rules
The regulatory framework places the enforcement burden squarely on the shoulders of messaging service providers. These companies, operating at the origin, transit, or termination stages of a message’s journey, are now legally required to block messages that do not comply with the new registry rules. The mandatory blocking conditions are comprehensive and designed to close common loopholes used by fraudsters.
Four Key Scenarios for Mandatory Message Blocking
Providers must intercept and block SMS, MMS, or RCS messages in several specific scenarios. First, any message using an alias not inscribed in the official registry will be stopped. Second, messages originating from service providers that are not themselves registered with the system will be blocked. Third, messages sent without explicit authorization from the registered alias holder will be filtered out.
A fourth, crucial condition targets international scams: messages from foreign companies not registered in Spain will be blocked when sent to Spanish numbers. The regulation includes a notable exception for users who are roaming abroad, ensuring they can still receive legitimate messages from foreign networks while traveling.
The Implementation Roadmap Leading to 2026 Enforcement
The CNMC has established a clear, phased timeline to bring the Alias Registry into full effect, giving businesses and providers ample time to adapt. The process begins with the official publication of the Circular in the State Gazette (BOE), which triggers a one-month period for messaging providers to perform bulk uploads of existing client aliases into the new system.
Testing Phase and Final Deadline
Following this initial upload period, providers will have until June 6, 2026, for extensive testing and to finalize the technical integration of their systems with the central registry. This phase is critical for ensuring a smooth transition and minimizing disruption to legitimate business communications. The full weight of the regulation comes into force on June 7, 2026. From that date forward, the obligation to block non-compliant messages becomes mandatory, marking the start of a new era for SMS security in Spain.
How Smishing Scams Work and Why the Registry Matters
Smishing—a portmanteau of “SMS” and “phishing”—has become a pervasive threat. Fraudsters impersonate trusted institutions like banks, utility companies, insurance providers, tax agencies (such as the Agencia Tributaria), or popular marketplaces. The goal is to create a false sense of urgency, prompting the victim to either click on a malicious link that installs malware or harvests credentials, or to reply directly with sensitive personal or financial information.
The Alias Registry attacks this problem at its root by removing the fraudster’s primary tool: the ability to spoof a legitimate sender name with impunity. If a bank’s official alias is “BANCOXYZ,” only that registered entity can use it. A scammer attempting to send a message from “BANCOXYZ” would be blocked at the network level, never reaching the consumer. This system fundamentally changes the SMS landscape from a wild west of unverified senders to a gated community of authenticated ones.
Proactive Consumer Protection Measures Beyond the Registry
While the Alias Registry is a powerful systemic defense, consumer vigilance remains essential. Individuals should always be skeptical of unsolicited messages that convey extreme urgency or alarm, such as warnings about frozen bank accounts or failed parcel deliveries. Verifying the source by contacting the institution through official channels—never using contact details provided in the suspicious message—is a critical step.
It is paramount to never share confidential information like passwords, verification codes, ID numbers, or credit card details via SMS reply. Legitimate companies do not request such data through this channel. Extreme caution should be exercised with embedded links; hovering to preview the URL (on capable devices) can reveal subtle misspellings or strange domains. The safest practice is to manually type the official website address into a browser.
Enhancing Personal Digital Security
Adopting robust personal security habits provides an additional layer of protection. Enabling two-factor authentication (2FA) on all important accounts ensures that stolen credentials alone are not enough for account takeover. Furthermore, installing a reputable mobile security solution or antivirus application can help detect and block known smishing attempts and malicious links before they cause harm.
The launch of Spain’s Alias Registry represents a significant shift in regulatory strategy, moving from post-fraud remediation to pre-emptive infrastructure security. By mandating sender authentication, the CNMC is not just creating a list; it is building a gatekeeper for the nation’s text messaging channels. For businesses, it necessitates a procedural update to maintain customer communication lines. For consumers, it promises a future where every branded SMS has passed a verification check, dramatically shrinking the playground for smishing criminals and making the simple act of checking one’s phone a notably safer endeavor.