← All articles

2026 Sender ID Risks: Outbound SMS Compliance for Australian Marketers

2026 checklist for Australian marketers: secure consent records, honor 5 business day opt outs, register sender IDs, test vendors and unsubscribe flows.

2026 Sender ID Risks: Outbound SMS Compliance for Australian Marketers

Yes, outbound SMS is legal in Australia if you have valid consent, identify the sender and provide a working unsubscribe. These three obligations sit at the centre of the Spam Act, enforced by the Australian Communications and Media Authority (ACMA). If you send commercial texts in 2026, add one more item to your checklist: the new sender ID register.


TL;DR:

  • Businesses must ensure consent is actively obtained, recorded with precise wording, timestamps, and source details, and retained for as long as recipients remain on the list.
  • Sender identification must include the business name or ABN and contact details that stay valid for at least 30 days, regardless of who dispatches the message.
  • Unsubscribe options need to be functional, widely tested across carriers, and processed within five business days, especially when using alphanumeric sender IDs.
  • Registering alphanumeric sender IDs with the SMS provider is mandatory from 2026 to avoid delays or blocking, and fallback numeric IDs should always be ready.
  • Most compliance failures come from non-functional unsubscribe mechanisms, lack of clear consent evidence, or impersonation, leading to potential fines or enforcement actions.

Table of Contents

What counts as a commercial electronic message under the Spam Act

A commercial electronic message (CEM) is any text that markets, advertises or promotes goods, services or a business opportunity, and it must have an “Australian link”, meaning it’s sent from or to an Australian number or account. Not every business text is caught by this definition, and that’s where marketers get tripped up.

Designated messages, such as government notices or factual service updates, are generally exempt. But add a discount code or a “we think you’ll love this” line to a shipping notification, and it becomes a CEM.

Common misclassifications include:

  • Welcome sequences that mix onboarding tips with product recommendations
  • Receipts or order confirmations that carry cross-sell offers
  • Re-engagement texts to lapsed customers framed as “checking in” but pushing a sale

Express consent, where someone actively opts in, is the standard ACMA prefers and the safest position for any campaign. Inferred consent exists (think an existing customer relationship where a text is clearly related to a recent purchase) but it’s narrower than most marketers assume, and it doesn’t cover unrelated promotions.

Pre-ticked boxes, consent buried in lengthy terms and conditions, or a single checkbox covering both service and marketing communications won’t hold up. ACMA guidance is explicit that marketing consent needs its own clear opt-in, separate from any transactional agreement.

To build a defensible consent record:

  1. Capture the exact wording shown to the customer at the point of opt-in.
  2. Log the timestamp, source (web form, in-store, app), and channel.
  3. Store the IP address or user agent where technically available.
  4. Retain these records for as long as the customer remains on your list, plus a reasonable buffer after opt-out.

Pro Tip: Screenshot your opt-in forms every time you update them, so you can reconstruct exactly what a customer agreed to, even years later.

Identify the sender: required content and how long details must stay valid

Every marketing SMS needs to clearly name the sender, typically the business name or ABN, along with contact details the recipient can actually use. This isn’t a nice-to-have. It’s a statutory requirement under the Spam Act, and it applies even when a marketing agency or platform sends the message on your behalf.

Practical points to check before you hit send:

  • The message identifies the business that authorised it, not just the software or agency that dispatched it
  • Contact details (a phone number, email or website) remain valid for at least 30 days after sending
  • Simple phrasing works: “Sent by [Business Name]. Reply STOP to opt out. Contact us at [details].”
  • If you’re running campaigns through a vendor, your brand name should still appear, not the vendor’s

Make unsubscribe functional, not just present

An unsubscribe option that exists on paper but fails in practice is one of the most common breaches ACMA finds. The standard is specific: unsubscribing must be free or low-cost, require no login or extra personal information, and be honoured within five business days.

This is where alphanumeric sender IDs cause real problems. A message that arrives from “YourBrand” rather than a standard number often can’t receive an inbound “STOP” reply at all, which breaks the entire mechanism. Legal commentary points to this exact scenario as a frequent, avoidable cause of enforcement action.

Before any campaign goes live, test that:

  • STOP replies work from major Australian carriers (Telstra, Optus, TPG)
  • A toll-free number or working link is offered as a fallback where alphanumeric IDs are used
  • Opt-outs are processed and confirmed within the five-day window
  • The unsubscribe flow works on both iOS and Android without extra app downloads

Pro Tip: Run a live STOP test on every new sender ID before your first full campaign send, not after.

Sender ID register and alphanumeric header constraints introduced in 2026

From 2025 into 2026, ACMA has been rolling out a sender identification register designed to reduce spoofing and impersonation scams sent via SMS. The draft industry standard sets out registration requirements for businesses using alphanumeric sender IDs and obligations for the telecommunications providers that originate, transit and terminate these messages.

An unregistered sender ID risks being flagged as unverified, delayed in transit, or blocked outright by carriers applying the new checks.

Steps to stay ahead of this:

  • Register your alphanumeric sender IDs through your SMS provider or aggregator once registration opens for your identifier type
  • Confirm your provider actually participates in the register, since not all do yet
  • Keep a numeric fallback (long code or short code) ready for any international or transitional routes not yet covered

Transactional messages versus promotional content

Order confirmations, appointment reminders and delivery updates are usually treated as transactional, meaning they sit outside the strict marketing consent rules. The moment you add promotional content, a discount, an upsell, a “shop now” link, that message becomes a CEM requiring proper marketing consent.

To avoid this trap:

  • Keep service message templates free of offers or cross-sell language
  • Route any promotional add-ons through a separately consented marketing stream
  • Document the distinction in your messaging policy so customer journey teams don’t blur the line

Penalties and enforcement: what attracts ACMA’s attention

ACMA has issued substantial infringement notices and enforceable undertakings against large Australian organisations for SMS and email breaches, with penalties running into the millions for repeat or large-scale offenders. Telstra’s 2025 enforceable undertaking required staff training, tightened record-keeping, an independent review and a documented remediation plan after consent and unsubscribe failures were identified.

ACMA enforcement has produced fines and enforceable undertakings against major companies including Commonwealth Bank, Tabcorp and Latitude for spam-related breaches, a pattern that shows the regulator applies the rules regardless of company size (ACMA investigations).

Patterns that draw scrutiny:

  • Non-functional unsubscribe mechanisms, the single most common trigger
  • No evidence of consent when a complaint is investigated
  • Sender impersonation or scam-adjacent messaging

If you receive an ACMA compliance alert, pause the campaign, gather your consent and unsubscribe records immediately, and respond within the timeframe given.

Practical compliance checklist: pre-send audit and ongoing controls

Before any campaign leaves your system, run through a structured audit rather than relying on memory or habit.

  1. Confirm consent records exist for every recipient on the send list, with timestamps and source logged.
  2. Check the message copy includes sender identification and a working unsubscribe line.
  3. Verify your sender ID’s registration status against the current register requirements.
  4. Cross-check the list against Do Not Call Register obligations where telemarketing overlaps with SMS follow-up.
  5. Confirm unsubscribe processing time meets the five-business-day standard.

Beyond the pre-send check, build these into standing operations:

  • Weekly testing of unsubscribe flows across carriers
  • A complaint log that records every opt-out request and how quickly it was actioned
  • Delivery monitoring to catch unusual bounce or block rates early
  • Retained records covering consent, message content and unsubscribe handling for audit purposes

If something goes wrong, follow a simple remediation sequence: pause the campaign immediately, investigate the root cause, preserve every relevant log, and notify ACMA if the breach meets their reporting threshold.

Pro Tip: Treat your consent and unsubscribe logs the way you’d treat financial records, complete, timestamped and ready to produce on short notice.

Outsourcing and third-party vendors: who stays responsible

Handing your SMS sends to an agency or platform doesn’t transfer legal responsibility. ACMA guidance is clear that the authorising business remains accountable for consent and unsubscribe compliance, even when someone else pushes the send button.

Before signing any vendor contract, insist on:

  • Documented proof of consent capture and storage practices
  • Clear unsubscribe handling with reporting on turnaround times
  • Incident response commitments and audit access to raw message logs
  • Data residency terms that match your regulatory obligations

Run periodic unsubscribe tests on vendor systems yourself, and set a reporting cadence so opt-out and complaint data reaches you regularly rather than only when something breaks. Our Do Not Call Australia rules guide covers how these outsourcing responsibilities extend to telemarketing overlap.

How an Australian-hosted platform supports compliant outbound SMS

Data residency and audit trails matter more once your compliance obligations include five-day unsubscribe windows and sender ID verification. An Australian-hosted platform keeps consent records, message logs and unsubscribe timestamps on local infrastructure, supporting the kind of audit access ACMA investigations require. Automated unsubscribe handling and centralised consent stores reduce the chance a STOP request slips through the cracks, the exact failure pattern behind most enforcement action.

Outbound SMS compliance control chain

Data privacy considerations for storing recipient information

Every phone number, opt-in timestamp and consent record you hold is personal information, and it needs handling that matches your privacy obligations, not just your spam obligations. Storing this data securely means access controls limited to staff who need it, encryption for data at rest and in transit, and a clear retention policy rather than keeping records indefinitely “just in case”.

Consent records should be treated as evidence, not clutter. Keep the original opt-in wording, the timestamp, the source channel and, where available, technical identifiers like IP address, but avoid collecting more than you need. Over-collection creates risk without adding compliance value.

When customers unsubscribe, their record shouldn’t simply vanish. Retaining a suppression record (the fact that they opted out, and when) protects you from accidentally re-adding them to a future list, which is its own compliance failure. Separate your active marketing list from your suppression list and make sure any new data import checks against both.

If you use a third-party platform to store or process this data, confirm where it’s hosted and who can access it. For businesses in healthcare, finance or other regulated sectors, data residency within Australia often forms part of broader privacy and security obligations that sit alongside spam compliance, not instead of it.

Timing and frequency limits for SMS campaigns

The Spam Act doesn’t set a specific “no texts after 8pm” rule the way some telemarketing regulations do, but ACMA guidance and general consumer protection principles point strongly toward reasonable sending windows. Most compliant operators restrict marketing SMS to standard business hours, typically 9am to 8pm local time, avoiding early mornings, late nights and public holidays unless a customer has specifically requested otherwise.

Frequency matters just as much as timing. Sending multiple promotional texts in a single day, or several times a week without a clear cadence the customer agreed to, drives complaint rates up sharply, and complaint volume is one of the signals ACMA uses to prioritise investigations.

A practical approach:

  • Cap promotional sends to a preset frequency the customer was told about at opt-in (weekly or fortnightly, for example)
  • Separate transactional messages, which aren’t bound by the same cadence limits, from promotional streams
  • Monitor opt-out rates by campaign; a spike usually signals you’ve pushed frequency or timing too far

International compliance considerations for cross-border messages

If your SMS campaigns reach recipients outside Australia, or you’re sending from an overseas platform to Australian numbers, the Spam Act’s “Australian link” test still applies, meaning Australian rules govern the message regardless of where it originated. But you also need to account for the destination country’s own rules if you’re messaging international numbers.

Markets like the European Union operate under GDPR-influenced consent standards that are often stricter than Australia’s, while the United States applies its own telemarketing and messaging rules through the Telephone Consumer Protection Act framework. Sending the same campaign across borders without adjusting for local consent and unsubscribe requirements creates exposure in multiple jurisdictions at once.

For sender ID registration specifically, international routing can behave differently to domestic sends, since not every overseas carrier participates in Australia’s sender ID register in the same way local providers do. Keep a numeric fallback ready for cross-border sends where alphanumeric ID verification isn’t yet consistently supported.

If your business operates only within Australia and messages only Australian numbers, this is largely a non-issue. But it’s worth confirming with your SMS provider exactly which routes your messages travel through, since some platforms route messages via overseas gateways even for domestic sends.

International compliance considerations for cross-border messages — overview diagram

Pragmatic priorities for compliance officers and marketers

If you fix one thing first, make it consent records: without them, nothing else matters when ACMA asks questions. Unsubscribe reliability comes second, sender verification third. Small failures caught early rarely escalate; contracts and platform controls make the whole process repeatable rather than something you rebuild for every campaign.

— Sowrabh

How Conversational AI helps you run compliant outbound SMS at scale

Running SMS campaigns across a growing customer base gets harder to audit manually, and that’s exactly where an Australian-hosted platform earns its keep. Certain SMS AI agents build consent logging, automated unsubscribe handling and delivery records into the campaign itself, so proof is generated as you send, not reconstructed afterwards.

Conversational AI

Practical applications our clients use today include:

  • Appointment reminders that cut no-shows while staying clearly transactional, as shown in our SMS appointment reminders case study
  • Collections follow-ups that combine automation with compliant messaging, detailed in our collections automation guide
  • Full audit trails through the Conversational AI CRM, covering consent, unsubscribe and message history in one place

If you’re weighing up whether your current SMS setup can stand up to an ACMA request for records, explore the platform and book a compliance-focused walkthrough.

Where to check the rules yourself

Bookmark ACMA’s spam guidance and enforcement reports for updates, and forward suspected spam to ACMA on 0429 999 888.

Sources

FAQ

What are the new laws regarding SMS sending in Australia?

The main 2026 change is the rollout of a sender identification register requiring businesses using alphanumeric sender IDs to register them, as set out in ACMA’s draft industry standard. Unregistered sender IDs risk being flagged as unverified or disrupted in transit as carriers apply the new checks.

What are the regulations for SMS marketing in Australia?

SMS marketing is governed by the Spam Act, which requires valid consent, clear sender identification with contact details valid for at least 30 days, and a functional unsubscribe option honoured within five business days according to ACMA guidance. Breaching these rules has led to significant infringement notices and enforceable undertakings against major Australian companies.

What is SMS compliance?

SMS compliance means meeting the legal obligations that apply to any commercial text message sent to an Australian recipient: securing proper consent, identifying who sent the message, and giving recipients a genuine, working way to opt out. It also extends to keeping records that can prove each of these steps if a regulator asks.

Which platform helps Australian businesses manage compliant SMS campaigns?

Conversational AI offers an Australian-hosted SMS automation platform built with audit logging, consent records and unsubscribe automation designed for regulated industries. It’s one option among several for businesses wanting compliance controls built into the sending process rather than managed separately.

Does using a marketing agency remove my compliance responsibility?

No. ACMA guidance confirms that the business authorising the message remains legally responsible for consent and unsubscribe compliance even when a vendor or agency sends it. Contracts with vendors should include proof of consent handling, audit access and clear incident response commitments to manage this shared risk.

Jess, AI voice agent