Guardivia

SMS Honeypot and Route Testing

How can SMS honeypots detect grey routes?

Reviewed 2026-09-12 by the Guardivia QoS Engineering Team

In short

Controlled messages are sent toward dedicated test SIMs through known sources. Guardivia compares expected and observed delivery characteristics, including Sender ID, content, message-centre information, delivery path indicators and timing, helping investigators determine whether traffic followed the expected route.

The comparison

The validation engine compares each submitted attribute against what arrived:

  • Submitted Sender ID against received Sender ID
  • Submitted content against received content, including any URL
  • Expected destination operator against the operator observed by the device
  • Sending timestamp against receiving timestamp, producing true end-to-end latency
  • Expected encoding and message parts against what was received
  • Gateway CDR and firewall decision against the device's observation
  • Expected delivery status against actual handset receipt

What each discrepancy suggests

A Sender ID replaced by a local mobile number points toward SIM-based termination. A changed message-centre address points toward a path other than the declared one. Excessive latency suggests additional hops. Truncated content or broken multipart assembly suggests an intermediary re-encoding the message.

A message that a supplier reported as delivered but that never arrived at the handset is the most commercially significant result of all, because it means the delivery receipt itself was unreliable.

The verdicts a test can support

Results are expressed as evidence-based verdicts rather than a binary pass or fail:

  • Confirmed legitimate or confirmed direct route
  • Suspected grey route; suspected SIM-box or SIM-farm termination; suspected unauthorised GT route
  • Sender ID modified or replaced; content or URL modified; message-centre changed; encoding changed
  • Multipart message incomplete; excessive delivery delay; duplicate delivery; message not received
  • Inconclusive due to insufficient evidence, or requires signaling or CDR correlation

The limit worth stating

Testing can provide strong evidence about route behaviour, but a single test should not automatically be treated as definitive proof of the complete network path. A handset cannot see the originating Global Title, the exact SMSC path or the identity of every intermediary — those require network-side CDRs, traces or signaling records.

A defensible conclusion therefore correlates testing results with signaling, routing, messaging and other network evidence, and rests on repeated tests across time of day, message types and destination operators rather than a single send.

Discuss this with the engineers who build the platform

Questions about how this applies to your network go straight to the QoS Engineering Team.