The Sender ID Register is open. The hard part starts now.
Vericode · 2 December 2025
In one week Treasury named the three industries that carry the first version of the new scam regime, and ACMA opened the front door to the Sender ID Register. Banks, telcos and digital platforms. One designation, one register and one date — 1 July 2026 — that quietly tells you when the lights actually come on.
It’s the kind of week that doesn’t make the news, because nobody got scammed in an announcement. It’s also the kind that matters, for what it sets up.
The Scams Prevention Framework designation is the broad move. It pulls banks, telecommunications providers and digital platforms into the first wave of the regime. Codes do the harder work from here, but you can see the shape now. These are the sectors expected to prevent, detect, disrupt and respond to scams in a more coordinated way.
The Sender ID Register is the narrower move, and it’s easier to explain. Brands use alpha tags in SMS, so a message looks like it comes from “CommBank”, “myGov”, “AusPost” or another name you trust. Scammers have leaned on that trust for years, because the name in the sender field has been too easy to fake.
The register changes the premise. An entity registers the sender IDs it’s entitled to use, and telcos check against that register at delivery. The end state is simple. If you’re not authorised to send from a protected name, the message shouldn’t arrive wearing that name.
That’s outbound brand authentication. It matters.
It matters because SMS is still a workhorse channel in Australian fraud. Not because SMS is elegant, but because it’s familiar, immediate and good enough to move people. A fake delivery message, bank alert, tax prompt, parcel link or account warning can still start the chain. If the name on the thread looks right, the user gives the message more credit than it deserves.
The register isn’t a magic line through SMS fraud. It won’t strip malicious links off ordinary numbers, fix every compromised account or mule flow or social-engineering script, and it doesn’t switch on for everyone the day the front door opens. Onboarding is the start of the operational work, not the end.
Still, the direction is right. Australia is moving the trust question from the user to the infrastructure. Instead of asking every person to work out whether “CommBank” is really CommBank, the system starts asking whether the sender had the right to use that name before the message lands.
That’s the right place for the check to live.
The distinction worth keeping sharp is what the register doesn’t touch. It says nothing about the person calling your contact centre. It can’t tell a staff member whether the caller claiming to be from a bank actually is, or whether it’s safe to hand account details to someone with the right name, the right phone number and a plausible story.
That’s not a criticism of the register. You don’t mark a tool down for failing to solve a different problem. The point is that outbound SMS brand trust now has a named mechanism and a regulatory path. Inbound caller verification doesn’t have an equivalent owner yet.
That gap will matter more as the other pieces harden. Make SMS impersonation harder, tighten payee checks at the banks, pull more scam ads off the platforms, and the pressure doesn’t vanish — it moves. Fraud doesn’t disappear because one channel gets more expensive. It goes looking for the next believable conversation.
This week gave Australian messaging trust a backbone. That was the easy part. 1 July 2026 is where the work actually shows up.