An SMS message that leaves an application passes through at least three parties before it reaches a handset: the originating platform or CPaaS, one or more aggregators, and the terminating wireless carrier. Each of those parties can filter independently, for its own reasons, using its own signals. Deliverability is the practice of understanding what each layer looks for and keeping traffic clean enough to pass all of them.
The hard part is that filtering is rarely announced. A message can be accepted by the platform, billed, and reported as “sent,” and still never appear on the phone. Understanding the difference between submitted, sent, and delivered, and knowing how honest delivery receipts actually are, is the starting point for every deliverability investigation.
Submitted, sent, and delivered are three different claims
- Submitted
- The platform accepted the API request or SMPP PDU. Nothing has been proven about the network. A submitted message can still be rejected by the platform’s own compliance filters before it goes anywhere.
- Sent
- The platform handed the message to a downstream aggregator or carrier and got an acknowledgment of receipt. The message is in flight. It can still be silently dropped at any later hop.
- Delivered
- A delivery receipt (DLR) came back claiming the terminating network completed the message to the handset. This is the strongest signal available, and it is still not proof a human saw the text.
DLRs have honesty limits. Some international and grey routes fake or approximate them: a “delivered” receipt is generated at an intermediate hop rather than by the terminating network. Some handsets and networks never emit a final status, so a message sits in “sent” forever despite arriving. And a carrier that filters a message as spam may still return a delivered-looking status rather than reveal its filtering rules. On reputable US A2P routes DLRs are broadly trustworthy; treat them as strong evidence, not as ground truth.
Three layers can filter independently
| Layer | What it filters on | What you see |
|---|---|---|
| Originating platform / CPaaS | Its own acceptable-use policy: SHAFT content, unregistered traffic, missing opt-out language, abuse complaints against your account | An explicit API error or a rejected/failed status. This is the most transparent layer. |
| Aggregator (including DCAs) | Carrier codes of conduct it must enforce, campaign registration status, volume anomalies, known-bad content signatures | A failed DLR with an error code, or silent drops on some routes. Partially transparent. |
| Terminating wireless carrier | Machine-learning spam scoring on content and volume, 10DLC campaign standing, per-number and per-campaign reputation, subscriber complaint and block rates | Blocked-as-spam error codes at best; silent filtering at worst. The least transparent layer, by design. |
Content signals that trigger filtering
Carrier spam models score message content the way email filters score mail. The industry shorthand for categorically restricted content is SHAFT: sex, hate, alcohol, firearms, and tobacco. Cannabis, gambling, high-risk lending, and some lead-generation patterns are treated the same way on most US routes even where the underlying business is legal. SHAFT traffic is a policy block, not a scoring problem; no amount of rewording makes it deliverable on registered A2P routes.
Below the categorical bans, common scoring triggers include:
- Public URL shorteners (bit.ly, tinyurl, and similar). Shared shortener domains carry the reputation of every spammer who ever used them. Use a branded domain you control.
- All-caps urgency patterns: “ACT NOW,” “FINAL NOTICE,” exclamation stacking, and artificial-deadline phrasing score like the scams that trained the models.
- Links or callback phone numbers in the first message to a recipient who has never replied. A first-touch message that reads like a phishing text is scored like one.
- Mismatched sender identity: content naming a brand that does not match the registered campaign description or samples.
- Excessive repetition: the same body sent to thousands of recipients with no personalization is an easy fingerprint. Minor templated variation is normal; evasive randomization (junk characters, deliberate misspellings) is itself a spam signal.
Registration and volume signals
Content is only half the model. The other half is who is sending and how the volume behaves. Unregistered 10DLC long-code A2P into US handsets is filtered or blocked outright by the major carriers; that battle ended when the registration regimes matured. Registered traffic then lives within the throughput its campaign earned from TCR vetting and carrier tier assignment.
- Exceeding the campaign’s carrier-assigned throughput tier: messages beyond the AT&T per-minute class or the T-Mobile daily brand cap are queued or rejected with rate-exceeded errors. The fix is vetting and tier upgrades, not retry loops.
- Sudden volume spikes: a number that sends 200 messages a day and then sends 40,000 in an hour looks compromised or malicious, whatever the content says.
- Snowshoeing: spreading one program’s volume across many numbers to stay under per-number limits. Carriers detect the pattern (same content, same links, coordinated timing across numbers) and treat it as deliberate evasion, which damages the whole brand’s standing.
- New-number and new-campaign coldness: fresh numbers and freshly approved campaigns often see conservative treatment until a history of low-complaint traffic accumulates. Ramping volume gradually is standard practice.
Opt-out hygiene is a deliverability input
Carriers watch how recipients react. A campaign with a high STOP rate, a high complaint rate (subscribers forwarding messages to 7726/SPAM or filing carrier complaints), or a high rate of sends to disconnected numbers looks like a list that was bought rather than built. That standing degrades the campaign’s treatment across the board: the same content that delivered in January gets filtered in June because the audience kept opting out. Consent quality, list hygiene, and honoring opt-outs immediately are deliverability work, not just legal work.
Error-code culture
When a carrier rejects a message, it returns a coded failure to the aggregator, which maps it to the platform’s own error vocabulary. The codes differ by carrier and platform, but the categories are stable and worth reading conceptually:
- Blocked as spam
- The terminating carrier’s filter rejected the message on content, reputation, or registration grounds. Retrying the identical message makes standing worse, not better.
- Unreachable handset
- The subscriber is off-network, the number is disconnected, or the number was reassigned. Persistent unreachable errors on a list are a hygiene signal: suppress those numbers.
- Rate exceeded
- The campaign or account hit a throughput ceiling. The message may be queued and retried automatically, or dropped, depending on the platform.
- Carrier or route error
- A transient interconnect failure that has nothing to do with your content. Distinguishable from filtering because it is not systematic by carrier or by message body.
Platforms surface these differently: some expose raw carrier codes, some collapse everything into a generic “undelivered.” When diagnosing, insist on the most granular error data the platform can provide, broken down by terminating carrier.
Monitoring, and a practical fix list
Three metrics catch most problems early. Delivery rate by terminating carrier exposes filtering that a blended average hides: a campaign at 95% overall but 60% on one carrier has a carrier-specific standing problem. STOP rate trending up means the audience or the content changed for the worse. Response rate (any reply at all) falling toward zero on a conversational program suggests messages are not arriving, whatever the DLRs claim.
| Symptom | Likely cause | Fix |
|---|---|---|
| Everything shows “sent,” little shows “delivered” | Filtering at the aggregator or carrier, or a route with poor DLR fidelity | Break delivery rate out by carrier; pull granular error codes; verify the campaign registration covers this traffic. |
| One carrier delivers poorly, others are fine | Campaign standing or spam scoring at that specific carrier | Review recent content changes and complaint rates; check the campaign’s tier and daily cap at that carrier; slow the ramp. |
| Messages with links fail, plain messages deliver | Shared shortener domain or a link domain with poor reputation | Move to a branded short domain; send the first message without a link and add links after a reply. |
| Bursts fail mid-send with rate errors | Throughput tier exceeded (AT&T TPM or T-Mobile daily cap) | Spread sends over time; pursue external vetting to raise the tier; split traffic classes into properly declared campaigns. |
| Deliverability decayed gradually over weeks | Rising STOP and complaint rates degrading campaign standing | Audit consent sources; suppress non-engagers; cut frequency; make opt-out easy and immediate. See SMS consent and opt-outs. |
| New number or campaign underperforms from day one | Cold reputation, or a use-case mismatch between the registration and the actual traffic | Ramp volume gradually; confirm samples and declared use case match what is actually sent. |