Written by the ITG Telecommunication team · Published 10 Aug 2026
Operators and regulators tightened network‑level and content enforcement in mid‑2026. If your SMS delivery fell after July, fix these five places first.
- Network filters blocked hundreds of millions of scam calls/SMS at operator level (U Mobile reported 265M blocks to date using a network firewall).
- Bank Negara / industry reporting shows scam losses ~RM2.8 billion in 2025 — regulators and telcos are prioritising anti‑scam enforcement.
You launched a high‑value campaign in July 2026 and saw deliveries crater: open rates low, complaints up, and carriers returning bulk rejections. That’s not random—July became a turning point because Malaysian operators and enforcement bodies moved from warnings to tighter, network‑level filtering and more active policing of SMS blasters and scam vectors. If your SMS program depends on mass sends, you need fixes that are technical, legal and operational — and that align with the new enforcement reality. This post gives five concrete, audit‑first fixes you can apply in the next 72 hours, plus the policy context behind them and realistic cost impacts for Malaysian businesses using sms blast services.
Why deliverability dropped after July 2026 — the short answer
Deliverability fell because carriers and regulators moved from advisory-era blocking into active, automated filtering: signature/behaviour detection at the signalling layer plus stricter content filtering. Operators are deploying SMS/voice firewalls and the GSMA‑backed anti‑scam taskforces are coordinating intelligence; the result is more aggressive blocking of high‑volume or suspicious senders and of messages that match anti‑scam patterns. Campaigns that previously slipped through (international routes, URL links, missing RM prefix, anonymous sender IDs) are now frequent false positives for network filters.
Further reading: U Mobile blocks 265M scam attempts (Cellusys press release, Dec 2025)
Further reading: GSMA/ACAST action against SMS blasters (Telecom Review Asia)
Five immediate deliverability fixes Malaysian SMS teams must apply now
Direct answer: Fix these five areas—consent records, message content, sender provisioning, sending topology, and feedback loops—and you will restore predictable delivery within 7–21 days for most campaigns. The remainder of this section explains how to run each fix practically and the exact checks to close.
-
Audit and fix consent & PDPA records (stop being an easy takedown target).
Why: regulators and operators increasingly treat poor consent records as evidence of nuisance or unlawful marketing. What to do: run a consent audit for the last 24 months, flag every record missing source metadata (date/time, opt‑in channel, copy of opt‑in text), and quarantine those numbers until you can obtain or re‑obtain explicit consent. Keep an export of auditable logs (CSV with E.164 number, opt‑in timestamp, opt‑in source).
Compliance step: under PDPA and the 2024 PDPA amendments (implemented in phases 2025), explicit and recordable consent is the commercial standard for marketing SMS in Malaysia.
-
Remove URLs/phone numbers; add the RM prefix and a clear brand tag.
Why: MCMC/operator filters have been blocking URLs and callback numbers aggressively since the URL‑blocking regime tightened in 2024, and operators will rewrite messages that don’t start with an RM prefix—breaking your segmentation and template layout. What to do: remove all clickable links; replace web links with short, pre‑registered short‑code flows or ask recipients to reply with a keyword (e.g., REPLY YES). Start every marketing message with the mandatory “RM 0.00” prefix (or operator variants) and include your brand name early in the body to reduce automated classification as ‘unknown’ or ‘scam’.
Warning: including a URL or a phone number will increase the chance of automated blocking and higher complaint rates—rework landing flows to use reply keywords or approved short codes instead.
Background: practical guidance on the RM prefix and URL filtering rules is summarised in recent Malaysia SMS compliance guides. Malaysia SMS Compliance Guide (Sent, 2026)
-
Use operator‑approved sender IDs and register short codes when possible.
Why: sender identity and route provenance matter more than sheer throughput. Messages from unregistered international routes or random numeric IDs attract filter scrutiny. What to do: switch to local A2P routes, register numeric sender IDs or 6‑series short codes as required, and avoid ad‑hoc international aggregators for high‑value sends. If you must send from an international origination, segment to low‑risk lists and ramp slowly.
Practical checklist:
- Confirm your sender ID type (numeric vs short code) with carriers.
- Keep a short‑code template bank and file templates where required.
- If you use concatenated (multi‑segment) messages, test encoding and character count (GSM‑7 vs UCS‑2) to avoid unintentional segmenting that triggers filters.
-
Throttle, warm, and localise your sending topology—don’t blast unknown volumes.
Why: sudden, high‑volume spikes are an easy trigger for carrier heuristics. What to do: adopt a staged ramp: sample to 1% of the list on day 1, 5% on day 2, 25% day 3, then full volume. Localise by operator where you can (route by MNO if your provider supports it). Use retries with exponential backoff rather than immediate resends for temporary failures.
Tie to ITGTEL: our SMS Blast platform supports scheduled delivery, per‑operator routing and contact segmentation so you can run a warming schedule and reduce filter friction.
-
Close the feedback loop: suppression lists, complaint monitoring and reporting.
Why: carriers and regulators expect rapid removal of opt‑outs and cause‑analysis for complaints. What to do: implement a 24‑hour suppression process (remove or suppress complaining numbers), keep clear MNP reconciliation for ported numbers, and instrument delivery and complaint dashboards so you can map which carrier or route is rejecting messages. If an operator flags a campaign, preserve the campaign logs and provide them immediately—speed helps reverse aggressive blocks.
Use structured reports (per‑campaign delivery %, per‑operator failures, SMPP error codes) to escalate with your SMS provider and the operator. Consider adding messaging alternatives (approved short codes, or a followup WhatsApp blast) for high‑value recipients—see the Messaging & Voice Blast options for multichannel fallback.
Messaging & Voice Blast (ITGTEL)
“Network‑level protection and operator cooperation are now the default—high‑risk routes are increasingly blocked before a user ever sees them.” — operator security briefing (industry sources, 2025–2026)
How much will these fixes change your SMS blast costs and ROI?
Direct answer: expect short‑term lift in operational cost (rework, template approvals, registered short code fees and smaller staged sends) but a faster, more predictable ROI and lower complaint/penalty risk. For large volumes, per‑message economics remain competitive in Malaysia — ITGTEL’s bulk credit pricing starts from RM0.10 per message for large packs — but you should budget a 5–15% margin for compliance and testing during the first quarter after remediation.
Concretely: if your baseline per‑message cost is RM0.10–RM0.12, add the cost of extra sends during warm‑ups (typically ~1.5× message count for sampling plus retries) and any short‑code registration fees or creative rework. Compare this to the cost of blocked campaigns (lost revenue and brand damage) and higher complaint handling overhead — fixes pay back quickly for repeat transactional campaigns (OTP, billing, collections) where delivery is business‑critical.
ITGTEL SMS Blast pricing and credit packs are detailed on the product pages: SMS Blast Malaysia (product) and the service overview at SMS Blast (service).
What regulators and operators are likely to do next (90‑day outlook)
Direct answer: expect continued operator deployments of SMS/voice firewalls, more aggressive blocking of unmanaged aggregator traffic, and faster takedowns of scam‑linked short codes. Regulators will press telcos to slash scam vectors—so the safest route for legitimate businesses is documented consent, registered sender IDs, and operator cooperation (technical onboarding and template approvals).
Why this matters: network solutions like the one U Mobile deployed show operators prefer to stop attacks at the signalling layer rather than rely on device apps. That reduces overall fraud but raises the bar for legitimate high‑volume A2P traffic which must be pre‑authorised and auditable. At the same time, cross‑industry anti‑scam coalitions (GSMA/ACAST, regional alliances) are sharing intel that speeds detection of SMS blaster patterns across countries — campaigns that look like regional scam blasts will be caught quicker.
Further reading: U Mobile / Cellusys network‑level protection (Dec 2025). Cellusys press release. For regional coordination and SMS blaster risk, see the GSMA/ACAST coverage at Telecom Review Asia.
Quick technical checklist (72‑hour triage)
- Export consent logs and flag anything without source metadata.
- Strip URLs & phone numbers; prepend “RM 0.00” + brand name.
- Switch to local A2P route / register short code for big sends.
- Throttle sends with a 4‑step warm ramp and monitor SMPP codes.
- Enable suppression automation for opt‑outs and complaints (24h SLA).
How ITGTEL helps: concrete services that close the loop
Direct answer: ITGTEL combines SMS Blast routing and contact management with scheduled delivery, per‑operator routing, and reporting that accelerates short‑code approvals and complaint investigations — so you can fix deliverability without rebuilding your whole messaging program.
Practical tie‑ins:
- Use ITGTEL SMS Blast for per‑operator routing and scheduled ramping to warm sender reputation. Service details.
- Move high‑value, link‑driven flows to WhatsApp or voice fallbacks — ITGTEL also offers WhatsApp Blast and voice blast options for controlled, opt‑in channels.
- Combine SMS with the broader Messaging & Voice Blast product suite for multi‑channel fallback and higher net reach. Messaging & Voice Blast overview.
Risk note: Ignoring MCMC/operator enforcement can lead to campaign suspension, short‑code deactivation, or legal notices. Prioritise audit trails and rapid suppression.
Common mistakes that make carrier blocks 10× more likely
Direct answer: the most common mistakes are (1) sending from international aggregators without local registration, (2) using messages with URLs or callback numbers, (3) lacking auditable opt‑in records, and (4) sudden volume spikes. Each alone raises suspicion; combined they almost guarantee aggressive filtering.
- Using global short‑cuts: a cheap international route often equals a higher block risk.
- Unverified opt‑in lists: scraped or rented lists trigger complaints and enforcement.
- Failure to honour opt‑outs within 24 hours—regulator and PDPA expectation.
Will removing URLs lower conversions and how can I replace links?
Yes, removing URLs reduces direct click conversions. Replace links with reply keywords, short codes, or a two‑step flow (SMS asks the recipient to reply YES to receive a link via a pre‑approved short code or to receive a WhatsApp message). For transactional flows, use registered short codes or authenticated WhatsApp templates to keep conversion while avoiding URL blocking.
How long does it take to recover delivery after implementing these fixes?
Small‑volume fixes (opt‑out removal, message edits) can show improvement in 24–72 hours. Reputation rebuilding and full scale recovery (after switching routes or registering short codes) typically takes 7–21 days with proper ramping and monitoring.
Do I need a short code for marketing in Malaysia?
Short codes are not always required, but they are the most reliable option for high‑volume marketing and two‑way campaigns because they are operator‑approved and easier to whitelist. For smaller programmes, local A2P numeric sender IDs with strong consent records and warming can be sufficient.
What alternatives should I use where URLs are essential?
If a URL is essential, use a pre‑approved short code landing flow, or move the experience to a sanctioned channel such as WhatsApp (with template approval) or voice callbacks. ITGTEL offers WhatsApp Blast as a compliant channel for conversation and links.
Context sources: Malaysia SMS compliance guide (Sent, 2026), U Mobile / Cellusys (Dec 2025), and regional industry analysis on SMS blaster risks via Telecom Review Asia (GSMA/ACAST coverage).