From tomorrow, Tuesday, 15th September, the mobile phones of citizens in the Valencian Community will have a new barrier against one of the most difficult types of fraud to detect: messages that use the name of a bank or company to pretend that they come from a legitimate entity.
From that date, the obligations related to the new Alias Registry, managed by the National Markets and Competition Commission, will come into full effect. Operators will be required to block certain SMS, MMS, and RCS messages that use an unregistered identifier as the sender or that have been sent by an unauthorised provider.
The measure will be applied throughout Spain and will therefore also affect the phone numbers of users in the Valencian Community. Its aim is to hinder identity theft campaigns in which criminals display the name of a well-known company on the screen to gain the victim’s trust.
What is the alias that appears in an SMS?
An alias is the name that appears at the top of certain messages instead of a phone number. It can belong to a bank, a company, a brand, or a government agency, and it helps the recipient quickly identify the supposed sender.
This feature is useful for recognising legitimate communications, but it has also been exploited to commit fraud. A message can appear convincing by displaying the name of a known entity, even though it was actually sent by a third party with no connection to it.
The risk increases when the message is embedded in a previous conversation the user was having with the legitimate entity. Because it appears within the same thread, the victim may believe it is an authentic communication and follow the instructions without suspecting the deception.
The new registry aims to verify which companies and public administrations are authorised to use each alphanumeric identifier. Only previously registered aliases linked to their legitimate owners may be used as senders.
Messages that should be blocked
From 15th September, providers will be required to block messages using aliases not registered in the system. They will also have to prevent the delivery of messages that, despite displaying a registered name, originate from messaging providers not authorised to use it.
The blocking will also apply when the message is sent without the alias holder’s authorisation. Therefore, if a company properly registers its business name and a third party attempts to use it without permission, the message must be intercepted before reaching the recipient.
The regulation also includes the blocking of messages from foreign companies not registered in Spain, except when the recipient user is roaming.
The new requirement is not limited to traditional SMS messages. The system also covers MMS messages and RCS communications sent to Spanish numbers.
What will banks, companies, and government agencies have to do?
Companies wishing to continue sending messages using their brand name as the sender must register that alias with the CNMC (National Markets and Competition Commission). To do so, they will need to demonstrate a legitimate link to their brand, company name, trade name, or domain name.
Public administrations may also register their identifiers. Registration may be carried out directly by the owner or through authorised representatives and courier providers acting on their behalf.
The system aims to prevent anyone from impersonating a well-known entity when sending communications. Furthermore, the CNMC plans to launch a public portal that will allow users to check which aliases are registered and who is listed as the owner.
For residents of Valencia, the change will be automatic. Users will not need to register, activate any phone functions, or install a specific application to benefit from the blocking feature.
The new filter will not eliminate all scams
The implementation of the Alias Registry provides additional protection, but it does not mean all fraudulent messages will disappear. The system is designed to address the irregular use of names or alphanumeric identifiers, not all possible forms of digital deception.
Criminals can continue sending messages from unknown numbers, use other communication channels, or resort to different techniques to try to obtain personal data, passwords, or banking information.
For this reason, receiving a message from a seemingly recognisable sender should never replace basic precautions. It is advisable to avoid clicking directly on unexpected links and never provide passwords, verification codes, or bank details requested via SMS.
If the message reports a strange transaction, an account block, or any urgent problem, the verification should be done by accessing the entity’s official application or contacting it through its usual channels.
A measure postponed until September
The blocking obligation was initially scheduled for 7th June 2026. However, the technical and operational complexity of the alias loading process led to an extension of the deadline to complete the system adaptation.
The Official State Gazette finally set 15th September 2026 as the date for the full implementation of the obligations. The extension was intended to guarantee the proper functioning of the registry and prevent the undue blocking of legitimate communications.
These legitimate messages may include notifications related to banking services, medical appointments, reminders, or administrative procedures. The challenge lies in curbing impersonation without preventing users from receiving necessary communications.
A new enemy for SMS spoofing
Smishing involves sending messages designed to generate fear, urgency, or curiosity. The victim receives a warning about a supposed charge, incident, or pending action and is directed to a website designed to steal their data.
The sender’s appearance is one of the tools that lends credibility to the scam. Therefore, the new registry focuses on verifying who is really behind the name displayed on the screen.
Starting this Tuesday, mobile phones in Valencia will have this new firewall against identity theft. It will be an additional obstacle for scammers, although the final barrier will continue to be user caution when faced with any message requesting urgent action.
