Spain will auto-kill unregistered sms in june—scammers get a 14-day countdown
Starting 06 June, any text message that lands on a Spanish phone without a government-issued sender ID will be dropped mid-air. The gatekeeper is a new registry run by the CNMC, the telecom watchdog, and the four big carriers have already flipped the switch in their labs. Fraudsters who spent the last decade spoofing CaixaBank or Correos now have two weeks to find a new hustle or go legitimate.
How the registry turns spoofing into a dead end
The mechanism is brutal by design. Brands must upload every alphanumeric alias they use—think BBVA, AmazonES, even the mom-and-pop courier—to the Registro de Alias. The string is cryptographically bound to the corporate tax number. When a message hits the network, the carrier’s edge node runs a 120-millisecond lookup; if the alias is missing or the hash doesn’t match, the SMS never reaches the handset. No bounce, no quarantine, no user setting to override. The same rule applies to RCS, the chat protocol Google is pushing as SMS 2.0.
Foreign operators are not exempt. A phishing farm in Riga blasting “NetflixES” will see its traffic null-routed at the Spanish border unless the Latvian shell company is registered to do business in Madrid and has secured the alias. The CNMC can levy fines up to €150 000 per spoofed batch, a figure that climbs to 0.5 % of Spanish turnover for repeat offenders.

Why june 6 is a soft cliff edge for banks and brands
Companies that wait until the final week risk a blackout. The registry API throttles at 500 requests per second; during testing, the largest retail bank needed 48 hours to upload 340 variants of its customer-service aliases. Miss the window and legitimate one-time passwords won’t arrive either—no exceptions, no grace period. Sources at Telefónica tell TechCurrent that 18 % of the 1.3 billion commercial texts Spain handles each month still come from unregistered senders, a tsunami that will evaporate overnight.
Consumer protection groups applaud the move, but they warn of a secondary market already emerging: cyber-criminals are cold-calling small businesses, offering to “rent” their clean aliases for a cut of the phishing profits. The CNMC has opened a whistle-blower channel; the first tip-off arrived 36 hours after the draft rule was published.
The bottom line: Spain is about to turn the humble SMS into a gated community. If your bank can’t prove it owns its name, its fraud alerts will rot inside a server farm in Móstoles. For once, the scammer’s inbox is the one that will stay empty.