Contents

Backend Development › Email & Notifications

SMS Delivery

Sending text messages through providers, and the cost and fraud pitfalls.

Also known as: SMS delivery, sending SMS, sms gateway

SMS delivery sends a short text message to a phone number through a gateway or aggregator provider (Twilio, Vonage and others). It’s used for two-factor codes, alerts, delivery updates and time-sensitive notifications — reaching people who may not check email or an app promptly.

backend → SMS provider API → carrier network → user's phone

The important characteristics:

  • Cost per message. Unlike email, each SMS costs money, so volume directly costs money. This shapes design: send fewer, more targeted messages.
  • Delivery receipts, not guarantees. Providers report delivery status, but SMS can still fail or be delayed (carrier issues, unreachable numbers). Best-effort.
  • Regulation and consent. Sending SMS is regulated (opt-in, opt-out, quiet hours in many jurisdictions). Sending without consent is a legal problem (see notification preferences).
  • Sender identity. Messages come from a short code, long number, or alphanumeric sender ID, each with different capabilities and rules per country.

The classic mistakes:

  • No consent / no opt-out. SMS is heavily regulated; sending without consent, or without an opt-out mechanism, invites complaints, fines and blocking. Always provide opt-out (e.g. reply STOP) and honour it.
  • Ignoring cost. Using SMS for non-urgent messages (marketing, routine updates) is expensive. Reserve it for high-value or time-critical communication.
  • Assuming delivery. Assuming an SMS arrived is wrong; delivery can fail. For critical flows (2FA), provide a fallback or resend.
  • Not handling opt-outs centrally. An opt-out must be recorded and honoured across all sends; scattered logic misses some (see notification preferences).
  • Long messages. SMS length is limited; long messages split into multiple billable segments. Keep them short.
  • Provider lock-in and routing. Delivery quality varies by provider and country; a provider that’s great in one region may be poor in another. Consider routing/fallback for global reach.
  • Putting sensitive data in the message. SMS isn’t encrypted end-to-end and appears on lock screens; avoid sending secrets. Send a code, not the context.

When to use it: for 2FA codes, critical alerts, and time-sensitive notifications where immediate reach matters and the user has opted in. It’s the highest-urgency, highest-cost channel — use it sparingly, with consent and an opt-out. See third-party integration for the provider-call side.