SMS Grey Routes: How They Work and How to Detect Them

Grey routes are the main way A2P SMS revenue leaks from mobile operators. This guide explains how they are built, why they exist and the evidence that exposes them.

Short answer

An SMS grey route is a delivery path that carries commercial A2P messages into a mobile network through connections meant for person-to-person traffic, so the receiving operator is not paid its A2P termination rate. Common forms are SIM boxes, which inject messages through local SIM cards, and interconnect bypass, which sends A2P traffic over P2P or roaming links. Operators detect them by comparing how messages actually arrive with how they should, using SMS firewalls and honeypot trap numbers.

Why grey routes exist

Mobile operators charge an A2P termination rate for commercial messages, usually well above P2P interconnect rates. Any path that delivers A2P traffic at the P2P price, or at a retail SIM price, saves money for whoever sells it. Senders under price pressure buy the cheapest route, often without knowing how it works.

Common types

SIM box (SIM farm) termination
A device holding many local prepaid SIM cards sends bulk messages as ordinary subscriber traffic. The sender ID becomes a local mobile number.
P2P interconnect bypass
A2P messages are handed to a foreign operator or intermediary that delivers them over its P2P agreement with the destination operator.
Roaming and signaling misuse
Messages are injected over SS7 using a Global Title that has no A2P agreement, sometimes leased or spoofed.
Blended routes
A route sold as direct mixes some approved delivery with grey delivery, so it passes small tests but leaks at volume.

What grey routes cost

For the receiving operator, the loss is the A2P revenue that should have been paid. For subscribers, grey paths also carry spam and phishing, because they skip the checks applied on A2P connections. For senders, grey-routed messages are increasingly blocked, delayed or delivered from random local numbers, which hurts OTP completion and trust.

How grey routes are detected

MethodWhat it looks atStrength
SMS firewall inspectionEvery inbound message: origin GT and SMSC, sender ID, content, volumeCovers live traffic; can block in real time
Honeypot trap numbersHow test messages actually arrive on controlled numbersHard evidence tied to a specific route
SIM behaviour analysisOn-net SIMs that only send SMS, never call or moveFinds SIM boxes inside the network
Revenue reconciliationDelivered A2P volumes vs billed volumesMeasures the financial gap

The clues in a single message

  • The originating SMSC or Global Title does not belong to the network the sender claims to use.
  • A brand's alphanumeric sender ID arrives as a local mobile number.
  • The same message template reaches many recipients from one origin within seconds.
  • A delivery report says delivered before, or without, the handset receiving the message.

Why one method is not enough

Grey routes change quickly. A firewall rule blocks one source and traffic moves to another; a honeypot sees only the routes that deliver to its numbers. Operators that combine firewall inspection, honeypot evidence and periodic revenue assurance close the gaps each method leaves alone.

What senders should ask their provider

  • Is this route direct to the operator, or through which partner?
  • Will my sender ID be preserved, and is registration required?
  • Are delivery reports produced by the delivering network?
  • Why is this price below the operator's published A2P rate?

Talk to our carrier team

Tell us which destinations, volumes or networks you are working with. A member of our team will reply by email.

We use these details only to reply to your request. See the privacy policy.