Flowstates messaging platform logo
    GB · +44 · MCC 234, 235

    United Kingdom SMS guide

    What actually changes when you send OTP, transactional or marketing SMS into the United Kingdom — separated into law and regulation, carrier and route policy, and what we recommend operationally.

    Last reviewed: 17 August 2026 · UK & Ireland

    On this page

    At a glance

    A quick operational read on the United Kingdom. Permission, identification and opt-out duties come from PECR and the UK GDPR as supervised by the ICO; sender behaviour, filtering and provisioning come from the provider and operator layer; and Ofcom's A2P anti-scam obligations are a dated future change, not a rule that binds traffic today.

    Direct-marketing rules
    Law / regulation
    SMS is “electronic mail” for PECR direct-marketing purposes, and whether a message is marketing is decided by its content, not by the label attached to the template
    Individual subscribers
    Law / regulation
    Unsolicited direct-marketing texts to individual subscribers need consent or a valid soft opt-in, and sole traders and ordinary partnerships count as individual subscribers
    A public number is not consent
    Law / regulation
    A mobile number being publicly available is not consent, and a bought or third-party list cannot inherit another organisation’s soft opt-in
    Charitable soft opt-in
    Law / regulation
    Available since 5 February 2026 to charities only, on its own statutory conditions, and only for details obtained directly on or after commencement — it does not legitimise older databases
    Sender identity and opt-out
    Law / regulation
    A marketing message must not conceal or disguise the sender’s identity and must give a valid address or contact route for opting out
    ICO enforcement ceiling
    Law / regulation
    From 5 February 2026 the PECR maximum is aligned to UK GDPR levels — up to £17.5 million or 4% of worldwide annual turnover, whichever is higher. That is a statutory maximum, not an expected penalty
    Two-way SMS
    Carrier or route policy
    Available in the UK overall, but the sender type you choose decides whether replies are possible
    Alphanumeric sender ID
    Carrier or route policy
    Supported and generally preserved on Twilio's current UK route, but one-way
    Domestic long number
    Carrier or route policy
    Supported, preserved and reply-capable on Twilio's current UK route
    International long number
    Carrier or route policy
    Not supported as a sender on Twilio's current UK route
    UK short code
    Carrier or route policy
    Supported on Twilio's current route through an approved programme; provisioning and commercial detail is confirmed privately
    Protected sender IDs
    Carrier or route policy
    MEF and BT protected brand sender IDs must be preregistered with the provider before use, and BT blocks them by default until allowlisted
    Generic sender IDs
    Carrier or route policy
    Generic identifiers such as SMS, TEXT, INFO, Verify and Notify are liable to be blocked by operators
    Sender-ID character set
    Carrier or route policy
    Maximum 11 characters with at least one letter, and for UK routing keep to A–Z, a–z, 0–9, period, dash, underscore, space and ampersand
    Short-code lead time
    Carrier or route policy
    UK short codes need carrier approval and registration, and provisioning typically runs 8–12 weeks
    Short-code consent
    Carrier or route policy
    Express end-user consent is required before messaging on a short code; friend-to-friend invitation and lead-generation opt-in campaigns are not supported on that route
    Cannabis content
    Carrier or route policy
    Prohibited on the cited provider route
    CBD content
    Carrier or route policy
    Permissible in the UK on the cited provider route, but keep it under legal review rather than treating route acceptance as legal clearance
    Age-restricted campaigns
    Carrier or route policy
    Alcohol, gambling and similar age-restricted programmes are assessed case by case by UK carriers, not universally approved
    Media / MMS
    Carrier or route policy
    No native MMS: media is converted to an SMS carrying an embedded URL, so treat media support as partial and converted
    Complaints process
    Law / regulation
    Since 19 June 2026 organisations handling personal data must operate a data-protection complaints process
    Number format
    Law / regulation
    +44 followed by the national digits, with the domestic trunk 0 removed — 07... becomes +447...
    Mobile-service ranges
    Law / regulation
    Domestic UK mobile numbers ordinarily run to 11 digits including the leading trunk 0, on mobile service ranges 071–075 and 077–079
    070 and 076
    Law / regulation
    070 is personal numbering and 076 is radiopaging, so a validator must not treat every 07 number as an ordinary mobile
    Number portability
    Carrier or route policy
    Supported in the UK, so a prefix does not identify the subscriber's current mobile network
    Line-type intelligence
    Flowstates recommendation
    Validate country or territory, line type and live carrier before routing instead of inferring from 07 syntax or the original prefix
    Concatenation
    Carrier or route policy
    Supported, subject to sender type and encoding, and each added part changes the payload and the cost
    Message length
    Carrier or route policy
    GSM-7 160 characters or Unicode 70 characters in a single inbound or outbound message
    Special characters
    Carrier or route policy
    Diaeresis and other accented characters may not arrive intact and can be substituted for delivery, so test templates
    SMS to landlines
    Carrier or route policy
    Not pre-rejected by Twilio: it may be passed to the carrier and converted into a text-to-speech voice call, and Twilio notes Virgin Mobile no longer supports SMS to UK landlines, so it is not a dependable SMS experience
    MMS
    Carrier or route policy
    Converted on Twilio's UK route to an SMS containing an embedded media URL
    M2M destinations
    Carrier or route policy
    Delivery to M2M numbers is best effort only on Twilio's route
    Content categories
    Carrier or route policy
    Category acceptance is supplier- and route-specific and is confirmed privately rather than published here
    Corporate subscribers
    Law / regulation
    Corporate subscribers can generally receive unsolicited electronic-mail marketing without PECR consent or the soft opt-in, but the sender must still identify itself, give a valid opt-out contact, honour objections and comply with the UK GDPR — corporate B2B SMS is not unregulated
    Soft opt-in
    Law / regulation
    The customer soft opt-in is narrow: details obtained directly in a sale or negotiations for a sale, the sender's own similar products, and a simple opt-out at collection and in every message
    Charity soft opt-in
    Law / regulation
    The Data (Use and Access) Act 2025 charitable-purpose soft opt-in took effect on 5 February 2026 for qualifying charities, subject to its own conditions
    Right to object
    Law / regulation
    The UK GDPR right to object to direct marketing is absolute, and processing for that purpose must stop
    No SMS preference service
    Law / regulation
    There is no text-message equivalent of TPS or CTPS, so suppression is your own control to build and run
    Ofcom A2P anti-scam rules
    Law / regulation
    Finalised but not yet in force: the A2P General Condition changes take effect on 15 July 2027, and mobile providers and aggregators will pass the controls through the supply chain
    Sender-ID registration
    Carrier or route policy
    There is no universal statutory UK sender-ID registration mandate; protected-brand allowlisting and generic-ID filtering are provider and operator controls
    2027 readiness
    Flowstates recommendation
    Start supply-chain readiness now for the Ofcom A2P due-diligence, sender-corroboration and Know Your Traffic controls: legal-entity evidence, brand and domain authority, sender-purpose records, traffic profile and escalation contacts
    Branded links
    Flowstates recommendation
    Use a controlled branded domain rather than a public or shared shortener
    Sending window
    Flowstates recommendation
    Default promotional sending 09:00–20:00 recipient local time. This is a Flowstates operating standard, not a UK statutory quiet-hours rule
    Last reviewed
    Flowstates recommendation
    17 August 2026

    Route-dependent: “Route-dependent” means the behaviour is decided by the provider, aggregator and operator path your traffic uses, not by UK law. Two suppliers can behave differently on the same day, and a route can change its policy. Confirm before launch.

    Law, route policy and recommendation

    UK A2P messaging is often summarised as one rulebook. It is not. Permission, identification and objection duties come from PECR and the UK GDPR, numbering and the future anti-scam duties come from Ofcom, sender behaviour and filtering come from the route you buy, and our deployment gates sit deliberately above all of them.

    • Law / regulation

      Law and regulation

      PECR (SI 2003/2426), the UK GDPR, the direct-marketing changes made by the Data (Use and Access) Act 2025, ICO guidance on electronic-mail marketing and the right to object, and Ofcom's numbering plan and anti-scam decisions. These bind you whichever supplier you use.

    • Carrier or route policy

      Carrier or route policy

      Alphanumeric support and preservation, protected-brand allowlisting and generic sender-ID blocking, special-character restrictions, domestic long-code and short-code availability and provisioning, concatenation, UCS-2, MMS conversion, landline text-to-speech conversion, M2M best-effort handling and category acceptance. This layer changes independently of UK law.

    • Flowstates recommendation

      Flowstates operational recommendation

      What we ask customers to do because it protects deliverability and keeps you comfortably inside both of the layers above. Deliberately stricter than the legal or route minimum, and never a substitute for legal advice.

    Numbering and networks

    The basics your validation layer and templates need to get right before the first send.

    • Law / regulationNumbering plan

      The UK uses ITU country code +44 and mobile country codes 234 and 235. Ofcom's National Telephone Numbering Plan allocates the ranges, and a UK mobile number is normally stored internationally as +44 followed by the national digits.

    • Law / regulationDomestic trunk zero

      A domestic UK number written 07... carries a national trunk 0 that is not part of the international number. Normalising 07xxx xxxxxx to E.164 means removing that 0 and prefixing +44.

    • Law / regulationOrdinary mobile ranges

      Ordinary UK mobile-service ranges are 071 to 075 and 077 to 079. Those are the ranges an ordinary consumer handset number sits in.

    • Law / regulation070 is not a mobile

      The 070 range is personal numbering — a follow-me service that can forward anywhere and is charged differently. It is not an ordinary mobile range, and treating it as one is a common and expensive validation bug.

    • Law / regulation076 is radiopaging

      The 076 range is radiopaging, apart from the 07624 sub-range used for Isle of Man mobile service. A validator that accepts any 07 number as an ordinary mobile will accept paging destinations.

    • Flowstates recommendationExclude 070 and 076

      Exclude 070 and 076 from ordinary-mobile assumptions in validation, pricing and routing logic, and handle them explicitly rather than letting them fall through a generic 07 rule.

    • Carrier or route policyPortability breaks prefix inference

      UK number portability is available, so the prefix range a number was originally issued in does not tell you which mobile network holds the subscriber today.

    • Flowstates recommendationLine-type and carrier intelligence

      Where routing, eligibility, cost or fraud controls depend on the network or the line type, use current line-type and carrier intelligence at send time instead of a cached prefix mapping.

    • Flowstates recommendationKeep the checks separate

      Syntax validation, line-type validation, consent evidence and deliverability are four different checks. A number that parses is not necessarily a mobile, a mobile is not necessarily permissioned, and a permissioned mobile is not necessarily reachable on the route you bought.

    • Flowstates recommendationNormalisation

      Normalise at capture rather than at send time and store +44 plus the national digits, so the same contact cannot exist in two formats across systems and vendors.

    • Carrier or route policyNetworks to plan for

      Representative operational paths include EE, O2 (VMO2), Vodafone and Three, plus the MVNOs riding on them. Not every supplier holds the same behaviour on every path, and BT-side protected-brand filtering applies to its own subscriber base.

    • Carrier or route policyLandline destinations

      Twilio does not check whether a UK destination is a landline and will attempt delivery. Some carriers convert the SMS into a text-to-speech voice call rather than rejecting it, and at least one operator no longer supports SMS to UK landlines.

    • Flowstates recommendationLandline handling

      Identify line type before sending anything sensitive or time-critical. A one-time passcode read aloud by text-to-speech to a shared office phone is a security and support incident, not a delivery success.

    • Carrier or route policyM2M destinations

      Message delivery to M2M numbers is on a best-effort basis only on Twilio's route.

    • Flowstates recommendationM2M handling

      Do not build a customer-facing or authentication flow on an M2M destination. Identify those numbers during validation and handle them on a separate, tested path.

    E.164 example

    +44 7XXX XXXXXX

    A schematic example, not a real subscriber number: replace the domestic leading 0 with +44 and store the result. Confirm the range is 071–075 or 077–079 before treating it as an ordinary mobile SMS destination.

    Sender options

    The UK supports a wide sender set, and the practical choice is decided by whether you need brand identity, reply handling or a high-volume interactive programme. Sender choice, not the country, is what determines whether a recipient can answer you.

    Carrier or route policy

    This whole comparison — best for, what the recipient sees and replies — describes provider and operator route behaviour and programme availability on current UK paths, not UK law. PECR permission, identification and opt-out duties and UK GDPR objection duties apply regardless of which sender you choose. Protected-brand allowlisting and generic-ID filtering are provider and carrier controls; category acceptance and provisioning detail are confirmed privately.

    Dynamic alphanumeric sender

    Best for
    One-way branded OTP, transactional and permissioned marketing traffic where no reply path is needed
    What the recipient sees
    Up to 11 characters including at least one letter, generally preserved on Twilio's current UK route
    Replies
    No — one-way only. Alphanumeric senders cannot receive a STOP reply, so every marketing, fundraising or political message must carry an alternative opt-out route: a reply-capable UK long code or short code, or a direct unsubscribe link

    Domestic UK long code

    Best for
    A numeric UK identity for service, support and conversational flows where inbound replies are configured
    What the recipient sees
    The UK long code assigned to the service, preserved on Twilio's current route
    Replies
    Yes, on the supported route when inbound is configured and tested

    UK short code

    Best for
    Higher-volume or interactive UK programmes running through an approved short-code programme with keyword handling
    What the recipient sees
    A stable short UK identity, preserved on Twilio's current route
    Replies
    Yes — STOP and HELP handling is expected in the programme flow. Provisioning typically 8–12 weeks with carrier approval and registration; commercial detail is confirmed privately

    International long code

    Best for
    Not a dependable production option for the UK — plan a domestic sender instead
    What the recipient sees
    Not supported on Twilio's documented UK route
    Replies
    Not applicable on that route

    Route policy: on Twilio's documented UK route, dynamic alphanumeric senders are supported and generally preserved, and general preregistration is not required — but MEF-protected and BT-protected brand sender IDs must be preregistered and allowlisted with the provider before use. Use a brand-related sender ID: generic identifiers such as SMS, TEXT, INFO, VERIFY, NOTIFY and OTP are blocked or heavily filtered by operators. Keep to a maximum of 11 characters with at least one alphabetic character, and for UK routing use only A–Z, a–z, 0–9, period, dash, underscore, space and ampersand. Domestic long codes are supported, preserved and reply-capable with no general pre-registration; UK short codes are supported and country-specific, need carrier approval and registration with a typical 8–12 week provisioning window, and require express end-user consent — friend-to-friend invitation and lead-generation opt-in campaigns are not supported on that route. UK toll-free numbers are not an SMS substitute, and international long codes are not supported. None of that is UK legislation, there is no universal statutory UK sender-ID registration scheme, and protected-sender registration on a provider route is not the same thing as Ofcom's future A2P due-diligence regime.

    What changes by traffic type

    The same UK destination behaves very differently depending on the category you send, the sender type you chose and the permission you actually hold. Content decides the category — a template named “service” that carries an offer is direct marketing.

    OTP / authentication

    Best served by an alphanumeric sender with a non-reply support route, or a domestic long number where a reply flow is intentional.

    • Flowstates recommendation

      Use a brand-recognisable alphanumeric sender rather than a generic identifier, and keep the copy purely transactional and within one segment where practical.

    • Flowstates recommendation

      Include the brand, the purpose and an expiry cue, and never attach promotional copy to an authentication template.

    • Flowstates recommendation

      Record the user action that triggered the code. That evidence supports the authentication exchange; it is not marketing permission.

    • Carrier or route policy

      An alphanumeric sender is one-way, so an authentication flow that expects a reply needs a domestic long number or short code instead.

    • Flowstates recommendation

      Validate line type first: an OTP delivered to a landline may be converted into a text-to-speech voice call, and to a 070 personal number may forward somewhere you did not intend.

    • Flowstates recommendation

      Monitor delivery, latency and completed-verification conversion per sender and per network rather than submitted-versus-delivered counts alone.

    • Flowstates recommendation

      Configure failover, but make sure every fallback sender and path is itself valid for the UK and for the traffic you are sending.

    Transactional / service

    Expected alerts, confirmations, account updates and support on a valid sender, with the marketing boundary policed.

    • Law / regulation

      A purely administrative or service message is not direct marketing, but adding promotional material can turn the whole message into direct marketing and pull it inside PECR.

    • Flowstates recommendation

      Keep the content inside the purpose the number was provided for, and keep marketing copy out of service templates entirely.

    • Flowstates recommendation

      Identify the brand and the purpose in the body, and give a working support route that does not depend on a reply the sender type cannot receive.

    • Carrier or route policy

      Branded links are deliverable only where the URL and the sender type are accepted on the selected path; test them rather than assuming.

    • Flowstates recommendation

      Test sender preservation, inbound replies, URLs, concatenation, Unicode and MMS-to-URL conversion on the exact path before launch.

    • Flowstates recommendation

      Maintain an objection, revocation and suppression process for every recurring programme, with a named owner.

    Marketing / promotional

    PECR permission duties, UK GDPR objection rights and route acceptance are three separate gates.

    • Law / regulation

      Unsolicited direct-marketing texts to individual subscribers generally require SMS-specific consent or a valid PECR soft opt-in.

    • Law / regulation

      Consent must be specific enough to cover text messages. Vague permission to receive generic “electronic mail” should not be treated as consent for SMS.

    • Law / regulation

      Solicited messages — those the person specifically asked for — sit outside the unsolicited-marketing consent rule, but the identification and opt-out duties still matter.

    • Law / regulation

      The customer soft opt-in applies only where the details were obtained directly during a sale or negotiations for a sale, the marketing is for the sender's own similar products or services, and a simple opt-out was offered both at collection and in every subsequent message. It is not a route for bought-in lists, unrelated prospects or third-party marketing.

    • Law / regulation

      PECR generally does not require prior consent for unsolicited marketing texts to corporate subscribers, but the sender must identify itself and provide a valid contact and opt-out route. Sole traders and some partnerships are treated as individual subscribers, so “B2B” is not a sufficient classification on its own.

    • Law / regulation

      The right to object to direct marketing under the UK GDPR is absolute, and processing for that purpose must stop.

    • Flowstates recommendation

      Do not use bought or rented lists, and do not treat a customer relationship on its own as blanket SMS marketing permission.

    • Flowstates recommendation

      Recognise STOP plus reasonable natural-language equivalents, and suppress immediately across every sending system rather than at the next campaign build.

    • Flowstates recommendation

      Use a branded full domain. Do not use public or shared shorteners in production messages.

    • Flowstates recommendation

      Send during recipient-local daytime unless the user has requested a genuinely time-critical service message.

    • Carrier or route policy

      Category acceptance, URL handling and sender eligibility remain supplier- and route-specific rather than uniform across the UK. We confirm what a given route will carry privately during onboarding instead of publishing a category list.

    • Carrier or route policy

      Cannabis-related content is prohibited on the cited provider route. CBD-related content is shown as permissible in the UK on that route, which is a deliverability position rather than legal clearance — keep the category under UK legal review.

    • Carrier or route policy

      Age-restricted programmes such as alcohol and gambling are evaluated case by case by UK carriers. Assume nothing until the specific programme and sender are approved.

    • Carrier or route policy

      A short-code programme requires express end-user consent before messaging, and carriers do not support campaigns where that consent cannot be obtained — including friend-to-friend invitation campaigns and lead-generation opt-ins on that route.

    • Flowstates recommendation

      Where the sender is an alphanumeric ID, the opt-out in the body must be an alternative path — a reply-capable UK long code or short code, or a direct unsubscribe link. Never print “reply STOP” against a sender that cannot receive replies.

    Operational compliance checklist

    What we expect to see in place before a UK route goes live.

    • Flowstates recommendation

      Separate transactional, OTP, service and marketing use cases into distinct templates, senders and permission records.

    • Flowstates recommendation

      Verify recipient type and number type before sending, and exclude 070 personal numbering and 076 radiopaging from ordinary-mobile assumptions.

    • Flowstates recommendation

      Store destinations as +44 plus the national digits with the domestic trunk zero removed, normalised at capture.

    • Flowstates recommendation

      Resolve line type and current carrier at send time rather than inferring the network from the prefix, because portability is available.

    • Law / regulation

      Record the PECR permission path for every UK programme: solicited request, SMS-specific consent, customer soft opt-in, charitable soft opt-in, or corporate-subscriber marketing with identification and an opt-out.

    • Law / regulation

      Record the UK GDPR lawful basis for the processing and the notice presented at collection.

    • Flowstates recommendation

      Sync opt-outs and objections to a single suppression list across every system and vendor, immediately rather than at the next campaign build.

    • Flowstates recommendation

      Match the sender type to the reply and opt-out design: an alphanumeric sender needs a non-reply opt-out route, a two-way flow needs a domestic long number or short code.

    • Flowstates recommendation

      Evidence your rights to the brand and sender ID, preregister protected brand IDs before use, and avoid generic identifiers and unnecessary special characters.

    • Flowstates recommendation

      Use branded links on a controlled domain, validate the destination domains, and keep public or shared shorteners out of production traffic.

    • Flowstates recommendation

      Test all UK mobile networks and representative ported numbers where commercially appropriate, plus landline text-to-speech behaviour where relevant.

    • Flowstates recommendation

      Test GSM-7 versus Unicode, accented and diaeresis characters, concatenation behaviour and the true message-part cost of each template.

    • Flowstates recommendation

      Monitor delivery receipts, complaints, reply handling, URL and domain signals and traffic anomalies per sender and per network.

    • Flowstates recommendation

      Keep the default promotional sending window at 09:00–20:00 recipient local time as a Flowstates operating standard, not as a claimed UK quiet-hours rule.

    • Flowstates recommendation

      Do not use bought or rented lists, and keep OTP, transactional or service and marketing purposes, templates and permission records separate.

    • Flowstates recommendation

      Put the brand and the purpose in the message body even where the alphanumeric sender is preserved, and confirm protected-sender registration and the visible fallback sender before launch.

    • Flowstates recommendation

      Re-review before 15 July 2027 when the Ofcom A2P obligations take effect, and whenever your provider changes its sender or filtering rules.

    Encoding and delivery

    UK copy usually fits GSM-7, but smart punctuation, emoji and accented characters can switch a template to Unicode and change both what arrives and what you pay for.

    GSM-7, single segment
    160 characters
    GSM-7, concatenated
    153 characters per segment
    Unicode / UCS-2, single segment
    70 characters
    Unicode / UCS-2, concatenated
    67 characters per segment
    • Carrier or route policy

      Twilio lists inbound and outbound UK message length as GSM 3.38 160 characters and Unicode 70 characters, with concatenation supported subject to sender type and encoding. Concatenation reduces the per-part payload and increases the number of parts you are billed for.

    • Carrier or route policy

      Character substitution can occur for some non-GSM characters on Twilio's UK route: the provider recommends testing templates before launch because characters such as letters with a diaeresis may be replaced to facilitate delivery. Test the final copy rather than treating one character warning as a universal UK rule.

    • Carrier or route policy

      UCS-2 is supported on Twilio's dynamic alphanumeric, domestic long-code and short-code rows for the UK. International long codes are not a supported UK sender.

    • Flowstates recommendation

      Test the real encoded copy and its true segment count on the exact sender and network paths you will use, and treat the segment count as a cost decision rather than a formatting detail.

    • Carrier or route policy

      MMS is converted on Twilio's UK route into an SMS containing an embedded media URL, so plan for the link to be the deliverable rather than the media itself. Concatenated GSM-7 carries 153 characters per segment and concatenated UCS-2 carries 67, so segment maths — not the single-message ceiling — decides what arrives and what you pay for.

    • Carrier or route policy

      An SMS sent to a UK landline is not pre-rejected by Twilio: it may be passed to the carrier, some carriers convert it into a text-to-speech voice call, and Twilio notes Virgin Mobile no longer supports SMS to UK landlines. Treat it as an undependable SMS experience and identify line type before sending sensitive or time-critical content.

    • Flowstates recommendation

      Use the schematic format +44 7XXX XXXXXX in documentation and test fixtures. Never publish or share a real subscriber number.

    • Flowstates recommendation

      Keep OTP to one segment where practical. A provider maximum is a technical ceiling, not a copy target.

    A country guide is only useful when the route follows it.

    Knowing the UK rules is the easy half. Keeping every send inside them — on the right sender, across route policy that changes independently of the ICO and Ofcom — is the operational half, and that is the part we run.

    • Per-country and per-category routing

      OTP, transactional and marketing traffic take different UK paths, with the right sender type and policy applied to each category.

    • SenderID management

      We manage sender identity across alphanumeric senders, domestic long numbers and short-code programmes, including protected-brand preregistration, and keep the approved use case aligned with what you actually send.

    • Carrier-grade failover

      When a UK path degrades, traffic moves to another valid sender and route rather than to whatever is available.

    • Per-route visibility

      Delivery, latency and OTP conversion measured per sender and per network, so a filtering change shows up as data rather than as complaints.

    • 24/7 vendor escalation

      We chase the supplier and the operator. You get the update, not the ticket queue.

    • BYOV / BYOG

      Keep your existing UK supplier, senders and contracts and let us operate the routing, or use ours.

    • Branded short links

      Links on your own domain instead of a shared shortener, which route filters and future Know Your Traffic controls treat very differently.

    What we need to validate your United Kingdom route

    Send us these and we will come back with the sender options that apply, the route behaviour we can confirm and the rules that govern your category.

    • Company or legal entity and website
    • Customer-facing brand name and evidence of your rights to it
    • Traffic category and use case, split by transactional, OTP, service and marketing
    • Sample templates for each distinct use case
    • Expected monthly volume and peak sending rate
    • Preferred sender type and whether replies are required
    • Existing UK sender inventory and current provider at a high level
    • Opt-in and permission journey, screenshots or evidence and the exact wording
    • The PECR permission path relied on and any soft opt-in analysis
    • UK GDPR lawful basis and the owner of the legal review
    • Privacy-notice and terms URLs
    • Internal objection, opt-out and suppression process and its owner
    • Link domains you intend to use
    • How numbers are collected, normalised, line-type checked and validated
    • MMS, Unicode and multi-segment requirements
    • Target launch date

    Frequently asked questions about SMS in United Kingdom

    Can I send SMS to mobile numbers in United Kingdom?

    A quick operational read on the United Kingdom. Permission, identification and opt-out duties come from PECR and the UK GDPR as supervised by the ICO; sender behaviour, filtering and provisioning come from the provider and operator layer; and Ofcom's A2P anti-scam obligations are a dated future change, not a rule that binds traffic today. Direct-marketing rules: SMS is “electronic mail” for PECR direct-marketing purposes, and whether a message is marketing is decided by its content, not by the label attached to the template. Individual subscribers: Unsolicited direct-marketing texts to individual subscribers need consent or a valid soft opt-in, and sole traders and ordinary partnerships count as individual subscribers. A public number is not consent: A mobile number being publicly available is not consent, and a bought or third-party list cannot inherit another organisation’s soft opt-in. Charitable soft opt-in: Available since 5 February 2026 to charities only, on its own statutory conditions, and only for details obtained directly on or after commencement — it does not legitimise older databases.

    Which sender ID options work for SMS in United Kingdom?

    The UK supports a wide sender set, and the practical choice is decided by whether you need brand identity, reply handling or a high-volume interactive programme. Dynamic alphanumeric sender — Best for: One-way branded OTP, transactional and permissioned marketing traffic where no reply path is needed. Domestic UK long code — Best for: A numeric UK identity for service, support and conversational flows where inbound replies are configured. UK short code — Best for: Higher-volume or interactive UK programmes running through an approved short-code programme with keyword handling. International long code — Best for: Not a dependable production option for the UK — plan a domestic sender instead.

    What are the consent and opt-out requirements for SMS in United Kingdom?

    Three separate bodies of rule are involved and supplier documentation routinely merges them: PECR, the UK GDPR as supervised by the ICO, and Ofcom's numbering and anti-scam regime. SMS is treated as “electronic mail” for PECR direct-marketing purposes, so PECR governs unsolicited direct marketing by text, and the UK GDPR governs the underlying processing of personal data. Whether a message is direct marketing is decided by its content and purpose, not by the label attached to the template. A purely administrative or service message is not direct marketing. Adding promotional material to it can make the whole message direct marketing. A mobile number being publicly available is not consent, and a bought, rented or third-party list cannot inherit another organisation's soft opt-in.

    How many characters fit in an SMS to United Kingdom?

    UK copy usually fits GSM-7, but smart punctuation, emoji and accented characters can switch a template to Unicode and change both what arrives and what you pay for. GSM-7, single segment: 160 characters. GSM-7, concatenated: 153 characters per segment. Unicode / UCS-2, single segment: 70 characters. Unicode / UCS-2, concatenated: 67 characters per segment.

    Sources and change control

    Official UK statute, ICO and Ofcom sources control every legal and regulatory statement on this page. Twilio material controls only statements about that provider's current UK route, and nothing in it should be read as UK law.

    • Provider route policy
      Twilio — United Kingdom SMS guidelines

      One provider's current UK route only: two-way SMS and number portability supported, concatenation supported with sender and encoding caveats, GSM-7 160 and Unicode 70 single-segment limits, dynamic alphanumeric senders supported and generally preserved with protected brand IDs (including BT-protected brands) requiring the applicable registration path and generic IDs blocked or heavily filtered, domestic long codes and approved short codes supported, international long codes unsupported, MMS converted to SMS with an embedded URL, landline SMS not pre-rejected and possibly converted to text-to-speech with Virgin Mobile no longer supporting it, M2M delivery best effort, and mobile country codes 234 and 235. Not UK law.

    • Provider route policy
      Twilio — Registering a protected alphanumeric sender ID in the United Kingdom

      The provider's registration route for MEF-protected and BT-protected UK sender IDs: controls the statement that general alphanumeric preregistration is not required but protected brand IDs must be registered and allowlisted before use.

    • Regulator guidance
      ICO — How do we comply with the PECR electronic mail marketing rules?

      Current ICO electronic-mail marketing guidance, updated 28 April 2026. Controls the consent and soft opt-in position for marketing by electronic mail including SMS, the individual and corporate subscriber distinction, the treatment of sole traders and ordinary partnerships, the duty not to conceal the sender's identity and the requirement for a valid opt-out contact.

    • Regulator guidance
      ICO — DUAA 2025 summary of changes: privacy and electronic communications

      The regulator's summary of the DUAA changes to PECR: controls the charitable-purposes soft opt-in and the alignment of PECR enforcement penalties with UK GDPR maximum levels.

    • Regulator statement
      ICO — Statement on the commencement of the Data (Use and Access) Act

      Dated 5 February 2026. Controls the commencement date used throughout this page for the PECR changes and the charitable-purposes soft opt-in.

    • Regulator statement
      ICO — New data protection complaints law now in force

      Controls the operational note that organisations handling personal data must have a data-protection complaints process, in force since 19 June 2026.

    • Regulator guidance
      ICO — Direct marketing and PECR guidance hub

      The ICO's current direct-marketing guidance set, including how to comply with the electronic-mail marketing rules, the consent standard, the products and services soft opt-in and the charitable-purposes soft opt-in available since 5 February 2026.

    • Regulator guidance
      ICO — Privacy and Electronic Communications Regulations

      The regulator's page for PECR itself, including the changes taking effect on 5 February 2026 and the alignment of the PECR enforcement ceiling with UK GDPR levels.

    • Regulator guidance
      ICO — Right to object

      The absolute right to object to processing for direct-marketing purposes and the duty to stop that processing.

    • Statute
      PECR — SI 2003/2426, regulation 22

      The statutory rule on unsolicited direct marketing by electronic mail to individual subscribers, including consent, the soft opt-in conditions and the charitable-purposes soft opt-in.

    • Statute
      PECR — SI 2003/2426, regulation 23

      The prohibition on sending direct marketing by electronic mail that conceals or disguises the sender's identity or fails to provide a valid address for opt-out requests.

    • Statute
      Data (Use and Access) Act 2025, section 114

      The amendment introducing the charitable-purposes soft opt-in into PECR regulation 22, commenced on 5 February 2026 alongside the wider PECR changes recorded on the ICO's PECR page.

    • Regulator
      Ofcom — numbering data

      The current UK numbering datasets and the National Telephone Numbering Plan they accompany, controlling which ranges are ordinary mobile service (071-075, 077-079), personal numbering (070) and radiopaging (076), together with Ofcom's mobile number portability material.

    • Statute
      Data (Use and Access) Act 2025 — contents

      The full Act, for reading section 114 in the context of the wider data and PECR amendments.

    • Government
      GOV.UK — Data (Use and Access) Act 2025 collection

      Official commencement and implementation material for the Act, supporting the 5 February 2026 date used on this page.

    • Regulator statement
      Ofcom — Tackling mobile messaging scams

      Ofcom's final statement and the General Condition changes it publishes, including the final statement PDF linked from that page: the A2P measures take effect on 15 July 2027 and cover customer due diligence, corroborating alphanumeric sender IDs, protected and generic sender policies, Know Your Traffic monitoring, incident controls, blocking and record-keeping. Not in force at this review date, and automated retrieval of Ofcom pages is blocked, so re-verify against the PDF at each review.

    Change log

    • 17 August 2026 — Audit pass: added the UK sender-ID character set and 11-character limit, the one-way alphanumeric alternative opt-out requirement, short-code express-consent and 8–12 week provisioning detail, cannabis-prohibited and CBD-permissible route positions, case-by-case age-restricted assessment, converted (non-native) MMS wording, PECR regulation 22(3A) non-retrospective charitable soft opt-in conditions, separate tracking of the two soft opt-ins, the 19 June 2026 data-protection complaints duty, and an explicit statement that no statutory UK quiet-hours window applies. Added the Twilio protected sender-ID registration article and the current ICO electronic-mail, DUAA/PECR summary, 5 February 2026 commencement and complaints-law sources.
    • 17 August 2026 — Initial publication; separated PECR regulation 22 and 23 duties, the UK GDPR consent standard and right to object, the products-and-services and charitable-purposes soft opt-ins and the 5 February 2026 PECR changes from Twilio route policy; recorded the 070 personal-numbering and 076 radiopaging exclusions and the portability warning; described the alphanumeric, domestic long-code and approved short-code sender set with protected-brand and generic-ID controls; and dated the Ofcom A2P General Condition changes to 15 July 2027 rather than presenting them as live.

    Last reviewed 17 August 2026

    Disclaimer

    This is operational guidance, not legal advice. Requirements vary by law, message purpose, recipient type, sender, provider, carrier route and customer setup. Flowstates confirms the live route during onboarding.