Guardivia

Grey Routes and Bypass

What is GT manipulation in SMS traffic?

Reviewed 2026-09-12 by the Guardivia QoS Engineering Team

In short

GT manipulation involves using or modifying Global Title information in ways that can obscure the true source or routing characteristics of signaling traffic. An operator can use signaling validation and traffic profiling to identify suspicious GT behaviour, because a forged address rarely behaves like the network it claims to be.

Why it is possible at all

SS7 has no mechanism binding a node to the Global Title it presents. The calling-party address in an SCCP message is an assertion, and the network that receives it has historically had no way to verify that assertion cryptographically.

That design reflects the era: SS7 assumed a closed community of licensed operators who had contractual reasons not to lie to each other. Once signaling access became commercially available through hubs and resellers, the assumption stopped holding.

Forms it takes

Manipulation is not always outright forgery:

  • Spoofing — presenting a Global Title belonging to another operator to inherit its interconnect privileges
  • Borrowed capacity — legitimately holding a GT but using it for traffic from parties the agreement never covered
  • Rotation — cycling through a pool of addresses to stay ahead of blocklists
  • Inconsistent addressing — using different GTs for the routing query and the subsequent delivery, so the two cannot be correlated

How it is detected

Detection almost never works by inspecting the address alone. It works by correspondence: does the traffic carried by this Global Title match what that network actually sends?

A GT claiming to be a European operator that suddenly carries Sender IDs belonging to banks in another region, at volumes it has never previously produced, to destination ranges it has never touched, is inconsistent regardless of whether the address itself appears on an approved list. Volume envelopes, operation-type expectations, Sender ID correspondence and destination profiles together make a forgery visible.

What to do with a suspicious GT

Blocking immediately can sever a legitimate partner's traffic if the analysis is wrong, so the usual sequence is to tag and quantify the traffic, raise it with the interconnect partner whose address is being used, and correlate with route-testing evidence showing what actually reaches handsets. Where the partner confirms the traffic is not theirs, the case for blocking is both technically and commercially solid.

Discuss this with the engineers who build the platform

Questions about how this applies to your network go straight to the QoS Engineering Team.