Guardivia

SMS Firewall

What is an SMS firewall?

Reviewed 2026-09-12 by the Guardivia QoS Engineering Team

In short

An SMS firewall is a telecom security platform that monitors, analyses and controls SMS traffic entering or leaving a mobile network. It helps operators detect spam, spoofing, grey routes, fraudulent messaging, unauthorised A2P traffic and signaling abuse, while enforcing messaging and commercial policies. It sits alongside the SMSC rather than replacing it.

Why messaging needs its own firewall

An IP firewall makes decisions from packet headers and ports. Neither tells you anything useful about an SMS. Two messages can arrive over the same interconnect, with the same protocol, from the same peer, and one is a bank's one-time password while the other is a phishing message impersonating that bank. The difference lives in the sender identity, the content, the routing path and the behaviour of the source over time.

A messaging firewall therefore operates at the messaging layer. It reassembles what the message actually is, who really sent it, how it arrived, and whether that combination is permitted by the operator's policy — commercial as well as security policy, because in messaging the two are inseparable.

What it protects against

The threat set spans subscriber harm and operator revenue, which is why messaging security tends to be jointly owned by security and wholesale teams:

  • Spam and smishing campaigns reaching subscribers
  • Sender ID spoofing and near-identical variation attacks impersonating brands
  • Grey routes delivering commercial traffic outside billable channels
  • SIM box and SIM farm termination disguised as subscriber traffic
  • Unauthorised direct injection into the SMSC or over SMPP
  • SMS home routing bypass and Global Title manipulation
  • Flooding, OTP abuse and artificially inflated traffic

Where it sits in the network

For signaling traffic, the firewall is normally inline between the STP and the SMSC, so inbound interconnect and roaming SMS is screened before the message centre sees it. For application traffic, it sits in front of SMPP binds, so aggregators and enterprises connect to the firewall rather than directly to the SMSC.

Guardivia's SMS Signaling and ESME Gateway Firewall covers both domains in a single policy environment: the Hawk engine handles SS7/SIGTRAN SMS signaling, while the Dolphin and Shark engines handle SMPP and ESME inspection. Traffic arriving over either path is evaluated against the same rules, registries and classifiers.

What it is not

A firewall is not a message centre. It does not store messages for unreachable subscribers, schedule retries or perform the store-and-forward function — that is the SMSC's job.

It is also not a general SS7 security product. Guardivia's signaling scope here is SMS signaling specifically; broader categories such as location tracking are addressed through the STP platform in the Core Network Suite. And it provides no lawful-interception capability.

Discuss this with the engineers who build the platform

Questions about how this applies to your network go straight to the QoS Engineering Team.