The RCS is now available via API with smsmode©. Consult the doc Our terms and conditions change. More information Nuestras condiciones generales pueden cambiar. Más información I nostri termini e condizioni generali stanno per cambiare. Ulteriori informazioni Unsere Allgemeinen Geschäftsbedingungen ändern sich. Mehr Informationen
May 13, 2025 - 5 min read

Using SMS OTP for online payment

Image by Elsa Paparone
Elsa Paparone

Elsa Paparone

SMS OTP channel

Share :

Introduction

The "end of SMS OTP" has been much heralded in recent years. And with good reason: the European DSP2 directive, the rise of Fintech and the emergence of new authentication methods have called its effectiveness into question. However, the SMS OTP (One-Time Password) is far from having completely disappeared. In fact, it continues to play a key role in many use cases and payment types.

What are the authentication rules for online payment?

PSD2 (Payment Services Directive 2) came into force in 2019, with a key component: strong customerauthentication (SCA). This obligation requires 2 of the following 3 factors to validate a transaction:

SMS OTP only ticks two out of three criteria. It therefore remains partially compliant, but not sufficient on its own for payments requiring strong authentication.

What the regulations say:

SMS OTP can always be used as a complement to strong authentication or outside the DSP2 perimeter, depending on the case.

When is SMS OTP still used?

Despite being phased out for regulated payments, SMS OTP is still relevant in many cases of two-factor authentication:

Secure access (excluding payment)

GOING FURTHER
Best practice guide: SMS 2FA

Services not directly covered by PSD2

SUCCESS STORY
Oodrive dematerializes the signature with SMS OTP and improves its customer experience

Online payment (in certain cases)

Why is SMS OTP still a useful tool?

Advantages of SMS OTP Limits
Universal (no need for third-party applications) Less secure than biometric methods
Easy to deploy on the corporate side Can be intercepted by SIM swap attacks
Used in concrete business contexts, such as purchase validation via corporate virtual cards (Spendesk, Pennylane...) Dependent on mobile network
Haute délivrabilité (plus de 97% reçus <1min)

The smsmode point of view©

At smsmode©we believe that SMS OTP is not obsolete, but in the process of being reconverted. It remains a useful security tool, provided it is used properly, particularly in :

Good to know:

Our dedicated OTP infrastructure guarantees fast, reliable delivery (SLA >98% in under a minute).

How smsmode© can help you

By choosing the SMS OTP solution from smsmode©, you benefit from:

GOING FURTHER
Pay By Link: send a link by SMS and boost your sales

Use cases covered :

Create your free account

Try out our SMS platform and benefit from 20 free test credits, with no obligation.

Need more info?
We look forward to hearing from you.

SMS OTP AUTHENTICATION

COMPARATIVE
2FA or SSO?
The ultimate access security comparison

- PDF AVAILABLE IN ENGLISH AND FRENCH -

Do you choose 2FA/OTP or SSO to secure access to your services? By SMS, email, tokens or push notifications?

In this comparison, we analyze each method to help you choose the solution best suited to your needs, with the right balance between security, simplicity and cost.

Download the comparison

Need more info?
We look forward to hearing from you.
March 28, 2025 - 9 min read

Protecting yourself from OTP fraud

Image author

Romain Didelot

OTP fraud

Share :

Introduction

A new type of fraud is gaining ground for web services that use SMS OTP identity verification. It's called " SMS PUMPING" or "Artificially Inflated Traffic". Fraudsters generate large volumes of SMS from mobile applications or websites, by sending massive verification codes. According to a study by Mobilesquared, this fraud accounted for more than 20% of global business SMS traffic in 2022. Find out how you can protect yourself from this type of fraud and how smsmode© can help.

How does SMS Pumping work?

2FA OTP fraud scheme

Fraudsters use various methods, including bots, to generate false requests via SMS. For example, they create fake accounts on an application or website, request password updates, click on "forgot password", etc. They take advantage of the presence of a telephone number input field to receive a one-time access code (OTP ), a download link or any other type of content delivered by SMS. If this verification form is not monitored, fraudsters can exploit it to generate fraudulent SMS traffic from your account.

In the majority of cases, attackers use their bot to mass-fill a field or form to "validate" these fake accounts, which triggers the sending of an SMS.

The SMS are sent to numbers over which the fraudsters have "control", enabling them to obtain a share of the revenues generated by this Artificially Inflated Traffic ( SMS ).

If you suffer such an attack, as the owner of the application, you will probably be forced to pay the bill for message delivery. The aim of this fraud is to make money, not to steal information.

There are two ways to make a profit with this type of fraud:

Case n°1

Fraudsters benefit from a partner operator/aggregator, with whom they have concluded a revenue-sharing agreement. They generate massive shipments of SMS to these operators, and divide the revenues among themselves.

Case n°2

An operator/aggregator is unknowingly exploited by the fraudsters.

In the second case, small operators or aggregators are paid by larger players for the volume of traffic they can allow to pass through. A fraudster can therefore create a fake company and promise a large amount of traffic (which he will make himself). The small operator/aggregator may not seek to know the source of the traffic and ends up supporting the fraud.

As you can see, in both cases, this type of fraud is more likely to occur among smaller operators. It's also common for these traffic anomalies to originate from far-flung destinations , as some international destinations have higher delivery costs and are therefore more profitable for fraudsters (and more costly for victim companies).

But businesses aren't the only losers in this story. OTP authentication fraud is a problem for the entire messaging ecosystem.

Operators and aggregators can hardly take action without the validation of their customers, which reduces the scope of action against this fraud and leads to a loss of credibility as well as a legitimate frustration for their impacted customers.

How to determine if you are a victim of an attack?

This fraud can go completely undetected, only becoming apparent after comparing the volume of messages delivered with the number of actual authentications.

However, there are a number of things that can tip you off:

What actions can be taken to protect yourself?

Although there is no miracle protection against this new type of fraud, companies can implement a few good prevention and detection practices that can significantly reduce these attacks. Involving customers is key to effectively combating fraudNo vendor-side solution can guarantee 100% effectiveness against these attacks. smsmode© can support you in implementing these best practices, and also provide a range of features to drastically limit fraud.

GUIDE
2FA best practices by SMS

Two-factor authentication (2FA) via SMS has become a widespread way of improving security. However, these SMS 2FA must be optimized, and your supplier must guarantee a high level of security.

IP control

Add additional checks on IP, user or device identifiers when a new user creates an account (ISP/proxy/TOR/cloud provider, etc.). This allows you to identify suspicious behavior and take action before the fraudster requests that a message be sent.

You can also limit the number of SMS request attempts from the same IP address or device and include a latency in the requests, e.g. one password reset per hour, etc.

VPN monitoring and detection

While there are legitimate use cases for VPNs, attackers will surely use one, if only to circumvent an IP address block. There are many solutions for VPN detection.

Detecting bots

Fraudsters are likely to use bots to generate large volumes of SMS. Using a feature like CAPTCHA can help detect and prevent bots from repeating requests.

Set up a "pre-audit" system

Avoid making SMS your first and only authentication device. This type of process certainly adds a step to creation and therefore a little friction for legitimate users, but can deter automated scripts and bots. For example, you can ensure that your users confirm their e-mail address before their telephone number.

Set server limits and service rates

Ensure that your application will not send more than one message every X seconds to the same mobile number range or prefix. Set up throughput limits per user, IP or device ID.

You can set up rules that restrict the number of requests allowed from a specific IP address or user over a given period by implementing modules in your web server such as Nginx and Apache to limit the rate or frequency of requests to your server.

Set sending limits

You can set several types of limits in collaboration with your smsmode© account manager:

Establish exponential delays between audit attempts

Setting exponential delays between requests made with the same phone number is an effective way of preventing mass mailing. They may not prevent fraud, but they can slow attackers down enough for them to decide it's not worth attacking your application.

Implement geographic permissions to restrict destination countries

Review the geographical zones in which authentication on your application is possible, and disable all destinations not eligible for your services (most cases occur in countries where brands are not present).

You can also create a list of automatic authorizations or blocks based on the phone number's country code.

Check phone number before sending with smsmode©

Use our API Lookup to obtain all information on the phone number used for authentication (country code, type of number, network, etc.).

You can also automate this API request. Lookup can help you identify the operator(s) responsible for excessive traffic (knowingly or unknowingly), so you can block them.

Monitor unique access code (OTP) conversion rates and create alerts

Create an alert in your internal monitoring tool for the authentication conversion rate (i.e., number of OTP validated by end users / number of OTP sent). If you notice that this rate starts to drop abnormally, especially if the OTP requests come from an unexpected country, trigger an alert for a manual review.

An analysis of the DLRs received from smsmode© may enable you to block the service if you suspect one or more numbers.

What should you do if you suspect fraud on your smsmode account?

Send an e-mail to smsmode
with the following details:

Account ID:

Channel(s) concerned:

Date and time range:

Destination countries SMS :

Business Description:

Create your free account

Try out our SMS platform and benefit from 20 free test credits, with no obligation.

Need more info?
We look forward to hearing from you.

NOTICE

SMS notification trends and performance

- PDF AVAILABLE IN FRENCH -

Discover the major trends and the evolution of SMS OTP in the strategies of French and European brands, through this comprehensive study based on 745 million SMS mailings.

SMS notification trends in 2024

Download the study

Need more info?
We look forward to hearing from you.
July 19, 2024 - 7 min read

Qualify your leads automatically with SMS OTP

Image by Elsa Paparone
Elsa Paparone

Elsa Paparone

lead qualification by SMS

Share :

Introduction

Lead qualification is the technique that enables a company to focus on the right prospects to develop its business. It's an essential step in your marketing strategy.

In the digital age, when competition is fierce and consumers are increasingly solicited, it's essential to implement effective methods to capture the attention of your target audience.

While the lead generation process is the key to business success, it's not enough to simply arouse the interest of your prospects! You need to qualify them , then convert them to achieve your goal: selling your products and/or services.

smsmode© tells you everything you need to know about lead qualification unique technique for automatically qualifying leads from a form. 💡

Definitions

What is a lead?

A "lead" (or prospect) is a term commonly used in marketing and sales to designate any entity (natural or legal person) that has expressed an interest in a company's products or services. In other words, a lead is someone who could potentially become a customer.

Leads can be classified into different categories according to their level of interest in your product/service and their proximity to the purchase decision:

  • Cold lead: the prospect has shown initial interest, but has not yet interacted much with the company.
  • Hot lead: the prospect has shown significant interest and is more likely to become a customer than the cold lead.
  • Qualified lead: the prospect has been evaluated and deemed ready for a direct sales approach.

What is lead qualification?

Lead qualification is the process of determining which contacts are most likely to be converted into customers. This is a crucial step, enabling your sales and marketing teams to focus their efforts on the most promising prospects for your business.

This allows you to optimize resources and increase your conversion rate.

With a certain budget, CRM (Customer Relationship Management) and marketing automation solutions often play a key role in the process of qualifying your prospects, by automating data collection, scoring and nurturing actions. They ensure more efficient and systematic management of the people you need to convert.

Why do I need to qualify my prospects?

According to Hubspot's "State of marketing report 2024"*, 61% of marketing experts see lead generation as their biggest challenge.

Lead qualification will enable you and your team to determine which group of contacts is the most promising and will lead straight to sales. It will also enable you to set up more precise and effective communication based on their expectations and needs.

Above all, qualifying your prospects enables you to manage the use of your resources, both in terms of time and money. You'll be able to weed out uninterested leads more quickly, passing on the most mature contacts to your sales force and focusing more attention on the most promising opportunities. In short, you gain in performance and increase your sales.

SUCCESS STORY
How did Meilleurstaux increase its sales with SMS ?
increase sales with SMS

Pre-qualification strategies

Preliminary work: defining the buyer persona

Before you start qualifying or generating leads, you need to define your buyer personas. The buyer persona is the profile of the ideal buyer for your solution, product or service.

Have you ever asked yourself: "who is my ideal customer?", "what do they want from my/our product/service?". Then you've already done the work. The buyer persona is the person who will buy your products or services. He's your target.

Define two or three target personas. Their characteristics and behaviors will determine the expectations they have of your products/services. This will enable you to effectively qualify and nurture your leads, turning them into ambassadors.

This work is essential, since it's at the very heart of your marketing strategy. Once you know exactly who you're going to address, it's time to generate your first leads.

Lead generation before qualification

Leads can be generated by various means, such as landing pages and online forms. When someone fills in a form on your website to download a white paper, for example, or subscribes to your newsletter, or requests further information on a particular product or service, you're collecting data (and effective CTAs will be your best allies). Events such as participation in trade shows, webinars or other events where participants leave their contact details can complete your harvest. As can online advertising, which involves generating clicks on paid ads via search engines (Google Ads) or social networks on which you can sponsor certain content (Facebook, Instagram, LinkedIn, Twitter). Or SEO: visits to your website from natural search results.

Of course, the only limit is your imagination. Be creative!

Lead qualification: the theory

The notion of the qualified lead was theorized as early as the 1960s by a B-to-B sales technique known as the BANT method. This lead qualification technique is used to evaluate the lead's potential and priority.

BANT is an acronym for Budget, Authority, Need, and Timeline. The prospect is evaluated on these 4 aspects to determine whether a buying decision is possible.

Budget : Does the prospect have the financial resources to buy your product or service? How much is the prospect willing to invest? Is their budget in line with your price?

Authority : Does the person (lead) with whom you're negotiating have decision-making power? Or should other company players take part in the negotiation?

Need : Does your product or service meet the prospect's specific need? Does it solve an important problem for the prospect, to the point of justifying the purchase?

Timeline : What's the timeframe for the buying decision? Knowing when the prospect plans to make a decision helps you plan your sales process and prioritize your efforts.

If your contact meets these 4 criteria, then he or she qualifies as a genuine potential customer. With the BANT method, salespeople can better target their efforts, save time and maximize the chances of closing sales.

Lead qualification in practice

SMS OTP: automatic and ultra-efficient

Lead qualification and the use of SMS OTP (One-Time Password) are basically two separate concepts, but can be used together to automatically qualify a lead and improve the effectiveness of marketing and sales campaigns.

The OTP is a one-time password sent by SMS to verify a user's identity.

It is widely used to strengthen your security for high-risk operations such as transactions, connections or verifications.

The password sent to the user's cell phone is entered to confirm identity. This adds an extra layer of control, particularly useful for preventing fraud and securing personal data. What's more, SMS OTP is universal. Who doesn't own a cell phone?

SUCCESS STORY
How Trovimap qualifies its incoming contacts with an OTP code sent by SMS
lead qualification

Integrate Lead Qualification by SMS OTP into your marketing strategy

Lead validation

The SMS OTP can be used to verify the authenticity of leads at the time of registration or following a request for information form. This step enables you to ensure that the contact details provided are valid and that your leads are genuine. This drastically reduces the risk of falsification (potentially false leads or leads automated by bots).

 

Lead engagement

Confirm your leads' registrations when they interact with your content (downloads, newsletter subscriptions, etc.) Sending a SMS OTP can be automated to confirm the lead's action. Once again, this procedure increases the commitment and reliability of the data collected. In fact, if a prospect agrees to give you their telephone number, they're not just curious - they're ready to take action.

💡

Once the lead number is in your pocket, you can still use SMS to send out important updates or special offers, with the assurance that the messages will reach the leads directly.

Effective post lead qualification strategies

Lead nurturing

Your leads are qualified, it's time to bring them to maturity. According to Hubspot's annual report*, 83% of prospects/customers surveyed are in favor of sharing their data in order to access a personalized experience.

It's time to implement a contact nurturing strategy to help your leads mature. Lead nurturing consists of maintaining and engaging your prospects throughout their journey in order to gradually guide them towards a decision to purchase your product or service.

What's more, you now have your prospects' phone numbers. Being able to contact prospects/customers via SMS or WhatsApp messaging gives you a strategic advantage. Automated marketing campaigns via SMS can increase your conversions by 21%! (Hubspot - State of Marketing Report).

The use of SMS is therefore not limited to SMS OTP, but can be extended to include SMS marketingwhich increases your chances of delivering the right message at the right time!

NEED MORE EXAMPLES?
All our examples of promotion, sale, private sale, welcome messages...

Customize your prospecting to your personas

Offer your prospects personalized content tailored to their needs. Tailor your message to different media (e-mail, phone calls) to highlight your expertise. Your content, blogs, articles and white papers, which answer your leads' most frequently asked questions and provide valuable information, can help bring about that long-awaited conversion!

This content can be shared via automated e-mail or SMS workflows, triggered by a specific action on the part of your prospect/lead, or directly by your sales team during the closing.

Lead scoring

A feature offered by certain CRM or marketing automation tools, lead scoring enables you to assign points to your contacts based on their interactions with your company. Lead scoring will enable your sales teams to focus their efforts on high-scoring leads, as these are the ones closest to converting and should be given priority by your teams.

Campaigns to re-engage dormant leads

Some leads are inactive? To encourage them to come back to you, don't hesitate to program re-engagement campaigns. Push special offers or free trials to attract the attention of less engaged prospects.

Analyze and adjust your strategies

Keep in mind that it's regular analysis of the performance of your nurturing campaigns that will enable you to identify what's working well, and what still needs to be improved. Adjust your strategies according to the data and feedback you gather, to maximize the effectiveness of your nurturing efforts.

Choose smsmode© to send SMS OTP

Conclusion

The success of your business depends on the implementation of a number of methods, which must be skilfully coordinated to achieve your objectives.

By integrating qualification via SMS OTP with your existing levers (forms, landing pages, referencing...), your marketing/sales strategy is enriched and the quality of your leads is significantly improved. Not only can you verify the authenticity of leads in real time, but you can also reinforce data security and facilitate the engagement of potential customers. By remaining attentive to the needs and behaviors of your leads, you can move them forward in their purchasing journey and increase their chances of becoming loyal customers or even brand ambassadors.

* Source :

Create your free account

Try out our SMS platform and benefit from 20 free test credits, with no obligation.

Need more info?
We look forward to hearing from you.
July 17, 2024 - 5 min read

The use of SMS in Fintech

Image by Elsa Paparone
Elsa Paparone

Elsa Paparone

Fintech messaging

Share :

Introduction

Fintech, the fusion of finance and technology, is disrupting the traditional banking sector through technological innovations. Among the solutions used by this sector, the strategic use of mobile messaging is a powerful tool for improving protection, communication and customer experience. Find out how finance companies are integrating short messaging to build strong relationships with their customers and protect their data.

SMS to streamline banking operations

Short Message Service plays an essential role in strengthening interactions within start-ups and innovative banks. As a direct and instantaneous communication channel, it enables companies to communicate effectively with their customers. From payment or contract reminders to transaction notifications, messages are of paramount importance in keeping customers informed in their financial activities. Many companies in the innovative banking sector, such as microcredit specialist Finfrog, use our solutions on a daily basis.

Text messaging is also a channel that greatly simplifies financial processes. By providing users with instant access to their financial information, SMS speeds up all interactions.

Whether for :

SUCCESS STORY
How does Leetchi secure its banking transactions with SMS ?
secure banking transactions with SMS

Our sending solution, also available via API, can help you reduce barriers to accessing financial services. By eliminating delays, oversights and friction, messages improve the fluidity of banking operations.

Security: the pillar of financial platforms, supported by the SMS

Beyond its communication function, the short message is a strategic protection tool that is particularly effective in the financial sector. It can be found in many different situations.

Two-factor authentication (2FA)

Users receive a unique authentication code (One Time Password) by SMS which they must enter in addition to their password to access their account. The 2FA by SMS adds an extra layer of assurance by verifying the user's identity, and blocks over 99.9% of account compromise attacks.

COMPARATIVE
Sensitive access security: 2FA or SSO?
Comparing 2FA and SSO authentication methods

Transaction confirmation

This well-known method for online payments has been replaced in Europe by 3D Secure, but is still widely used by online financial platforms generating virtual cards. When large payments are initiated, a SMS OTP is sent to the account holder to confirm the transaction and prevent fraudulent transactions.

Electronic signature

The One Time Password is very useful in electronic signatures, as it provides a legal guarantee of the signatory's identity and the integrity of the signed document. An OTP is generated for 1 signatory and 1 contract. The signatory re-enters this code received by message on the contract. This action is the legal basis of consent for a remote signature.

Suspicious connection alerts

If a suspicious connection is detected on a user's account, an alert message is sent to inform the user and enable them to take rapid action to secure their account.

Notification of an important change to the account

If a user changes their password or personal data, a short message can be sent to confirm the change. This ensures that the account holder is aware of any changes to their information.

Balance or activity alerts

Customers can receive alerts to be informed in real time of any activity on their account, such as a large payment or a change in balance.

Password reset

This is a more secure alternative to sending a password reset link by e-mail. A telephone number is a better guarantee of identity than an e-mail.

Identity verification for customer support

When a user contacts customer service with account-related questions, an identity verification message may be sent to ensure that the user is the account holder.

This extra layer of protection guarantees the confidentiality and security of transactions and sensitive data. Messages thus become a reliable shield, helping to build trust among users of online financial services.

GOING FURTHER
All you need to know about SMS for banking security

Understanding dual authentication ? How to deploy an authentication process? Which technologies and methods?

2FA Guide

SMS for customer experience in Fintech

The use of mobile messaging in online financial platforms also offers other significant functionalities for improving the user experience. Here are just a few of them!

Personalization and proximity

Thanks to customizable variable fields and segmentation of the contact base, mobile messaging allows you to play the proximity card effectively. This is particularly valuable in the banking sector.

By tailoring messages to users' profiles and preferences, companies canstrengthen ties and create a unique experience for their customers. This personalization generates a sense of appreciation and involvement that helps build a solid climate of trust.

SUCCESS STORY
How does CNP Assurances make authentication more accessible with voice OTP?
make authentication more accessible with voice OTP

Proactive information

With its record open rate, text messaging is the perfect channel for notifying and informing, with the assurance of being read. Companies can therefore take a proactive approach by sending out information on new offers, policy changes and more. It's an excellent way for a brand to demonstrate its commitment to transparency and customer satisfaction, while sparing them any unpleasant surprises. This strategic approach strengthens loyalty and guarantees a positive experience.

Mobile messaging as a financial education tool

It can also be a good channel for an educational approach. Banking companies can provide their customers with information and advice tailored to their specific needs throughout their investment journey. This approach makes it easier to assimilate financial concepts and encourages informed decision-making.

Consumers can also be guided through these learning stages by a chatbot SMSThe short message becomes a strategic awareness-raising tool, leading individuals towards greater control of their financial situation and loyalty to your solution. The short message becomes a strategic awareness-raising tool, leading individuals towards greater control of their financial situation and loyalty to your solution.

In addition, they can include links to reliable external resources, such as government articles or reference guides on financial management. This strategy enables users to deepen their knowledge and acquire the financial skills essential for using banking products.

GOING FURTHER
Optimized customer relations in Fintech.
10 tips for notifying and building loyalty with SMS

In this guide, identify the touch points where SMS improves the customer experience.

 

SMS in the banking sector: driving behavioral change

The use of mobile messaging in this specific sector is therefore not limited to distributing information or validating payments, but also encourages responsible financial behavior. The short message encourages users to put what they've learned into practice, using all the available functions. These include budgeting, financial balance sheets and savings planning. Periodic reminders and financial tips delivered by message act as catalysts for positive action. This encourages consumers to take concrete steps to improve their financial well-being. In this way, the mobile medium becomes a driver of behavioral change, transforming financial empowerment into an interactive and dynamic process.

In conclusion, the strategic integration of Short Message Service into the financial innovation industry has opened up new perspectives for security, customer experience and communication. By using it in a targeted way, financial companies are at the origin of a virtuous circle that leads customers and companies to success.

Create your free account

Try out our SMS platform and benefit from 20 free test credits, with no obligation.

Need more info?
We look forward to hearing from you.
June 28, 2024 - 7 min read

2-factor authentication, the security solution

Image author

Romain Didelot

2FA SMS, double authentication by SMS

Share :

Introduction

Security on the web is an issue for everyone. Protecting your company's sensitive information, and that of your customers, is a vital task for which the simple duo of login and password is no longer sufficient. The compromise of a single credential can lead directly to the success of a cyber attack. For this reason, dual authentication is the ideal tool for securing connections. Find out why 2FA (two-factor authentication) is so essential to protecting your business, and why the SMS OTP (one-time-password) is the best way to implement double verification.

What is two-factor authentication?

Double authentication, commonly known as 2FA or two-step verification, is a method of protecting a personal account by means of a second identification step, usually a code called an OTP, or verification number, sent by message with maximum priority and valid for a few minutes. This code, received on your cell phone via your telephone number, can also be sent by authentication software such as Microsoft Authenticator or Google Authenticator, by push notification or by e-mail.

Information

2FA by SMS lets you manage OTP code generation on your own. This gives you complete control over code creation, validity times and the security of the entire authentication system.

This method enhances web security by adding an extra layer of protection against unauthorized access: the recipient's telephone number.

Dual authentication differs from multi-factor authentication in the number of elements used. With MFA (Multi-factor authentication), three elements are used:

COMPARATIVE
Sensitive access security: 2FA or SSO?
Comparing 2FA and SSO authentication methods

What are the authentication factors?

Multi-factor authentication is divided into 3 distinct proofs of identity corresponding to 3 validation steps:

In practical terms, on an online account, logging in with a username and password is the first trigger. The second is the smartphone in your possession, to which the SMS OTP is sent, a text message containing the code to be typed in, proving that the phone is indeed yours.

GOING FURTHER
All you need to know about SMS for 2FA

Understanding dual authentication ? How to deploy an authentication process? Which technologies and methods?

2FA Guide

Use cases of the 2FA

While this method is well known for validating online payments (still in use in Europe until the introduction of DSP2 regulations), it is becoming increasingly popular for other applications:

Examples of security request messages :

[SenderID]

To access your account, please complete the two-factor identification by entering the security code sent to your device. 

[SenderID]

To increase the security of your account, please configure 2FA authentication via SMS to reduce the risk of hacking. 

NEED MORE EXAMPLES?
All our examples of authentication and electronic signature messages...
examples sms notification

Why your company needs 2FA

A first factor - login or email + password - can easily be hacked.

Using two-step validation - on 2 separate devices - reduces the risk of cyber-attack, and limits the theft or loss of personal or business information.

An asset to enhance your customers' protection

Some people already use 2FA in their daily lives, to secure their online banking activities, clouds, shopping or email platforms, social networks or password managers. Being proactive in this field by offering your customers a solution that enhances their online security is bound to be an asset.

By introducing 2FA, merchants are helping to provide a secure experience that strengthens the customer relationship.

Users obviously want their online solutions to be simple and transparent, but that doesn't mean they'll tolerate security loopholes. The rise in fraud and the increased use of digital payments mean that an additional authentication solution is needed for sensitive information.

A real additional security barrier for your online business services

A simple password is no longer enough. Access to personal information by malicious individuals can be devastating, and most businesses are no better protected against cyber-attacks than private accounts.

A corporate email account can be compromised by phishing or identity theft, and become an entry point for stealing strategic information or even money. If a password can be reset by email, access to your platform is child's play.

Passwords already used elsewhere and made public can be used to access a business account. 73% of passwords are used for more than one account, which is just as many chances for a successful hack.

Two identification factors: the solution to 99.9% of your security problems

Many attacks can indeed be thwarted by training employees in cyber security, using strong, unique passwords or anti-phishing training. But this kind of process has a cost for companies, and we're all human, so we're all susceptible to inattentiveness. What's more, with the democratization of teleworking, connection to professional accounts outside the company is on the rise, increasing the chances of errors and therefore cyber-attacks.

SUCCESS STORY
How does CNP Assurances make authentication more accessible with voice OTP?
make authentication more accessible with voice OTP

With two-factor authentication, you don't have to put the security of your business solely on the shoulders of your employees.

With 2FA, cracking or recovering a password will no longer be enough to gain access. This strong authentication gives you an additional security barrier that blocks more than 99.9% of account compromise attacks. (1). Whether it's phishing, bots or leaking credentials to another site.

To avoid breaches, some organizations go so far as to do away with the traditional password, relying on the last two factors or using TOTP (a key that uses the time stamp to create a sequence of characters, shared by the user and a server).

The 2FA in figures

Why sending OTP messages is the best way to implement 2FA

Simple, agile, reliable, inexpensive and fast, SMS is the universal solution that everyone knows how to use.

2FA is certainly possible with an instant messaging application, push notifications or an authentication application, but you need to be sure that your employees or customers have these applications, or can afford them. Also, this type of solution relies on the security of the application used. So it's best to be sure of your partner.

SMS has the huge advantage of being natively present on all mobiles, and can be received by everyone, from the latest smartphone to the oldest mobile. There's no need to download, create an account on an application or pay for a package to benefit from authentication services.

Easy to set up, the cost of OTP can be adapted to your budget, making it applicable to everyone, from SMEs to major corporations. It enables you to reach all profiles without limiting your action to a single community, such as users of a single instant messenger or an external application that generates TOTPs (Time-based One-Time Password).

With SMS :

SMS is also ideal for password recovery. A third of all online purchases are abandoned because of a forgotten password, so providing your customers with a quick and easy way to recover their account can benefit you both financially and in terms of customer experience and brand image.

Why choose smsmode© to implement 2FA

Two-factor identification is essential to secure access to web services, adding an extra layer of protection after the password has been entered.

Access to personal data must be fast and secure, so SMS must work every time.

With smsmode©️, your OTP codes have priority. Our status as a telecom aggregator with ARCEP offers you :

Consumers and employees alike can't wait to receive their codes. Employees may become impatient and deactivate the 2FA system, putting themselves at risk. As for customers, they could also abandon their purchasing action for lack of codes, so getting them back is essential. This is why the 2FA method is important, as is the solution chosen to implement it.

REPORT
Digital security at smsmode© ?
Discover our data protection and privacy measures designed with RGPD compliance in mind.
safety report smsmode

2FA with smsmode© in 3 points

A telecom operator ARCEP

Recognized as a mobile service provider telecom operator with ARCEPyou benefit from direct connection to operators through the services smsmode©. So you can be sure that we won't be using no roamingwhich offers a high quality And reliability for your send SMS OTP.

Personal data protection

In accordance with our agreement with the CNIL and our ISO 27001 & 27701 certifications, all data imported into our services is confidential, and we guarantee that our contact files will not be used by third parties.

A long-standing player in messaging

Since 2004the mobile messaging provider smsmode© offers tools forsending and receiving SMS via API. The company is constantly improving the services it offers, and is looking forward to more than 10,000 customers for a volume of more than 100 million SMS sent per month.

Get a free demo

Try out our SMS platform and benefit from 20 free test credits, with no obligation.

June 16, 2024 - 3 min read

Authentication via SMS with One Time Password (OTP)

Image author

Romain Didelot

authentication by SMS

Share :

Introduction

Reducing the risk of fraud without hindering users in their login or account creation processes is a concern for many companies. The most common method for ensuring user security within an application is verification at login, i.e. authentication. Several solutions exist, but how do you adopt the one that will be the most effective and secure, while minimizing costs?

What are the different forms of authentication at SMS ?

Simple authentication using SMS

Simple authentication via SMS allows the user to connect to an account without providing a username or even a password. Once the login address has been entered, an SMS OTP (One Time Password) is sent to the cell phone of users who enter the code to connect to the application. It's a fast and easy way to verify that you have a cell phone, so there's nothing to remember. However, the phone is the only authentication factor, which makes this method more fragile. 

COMPARATIVE
Sensitive access security: 2FA or SSO?
Comparing 2FA and SSO authentication methods

Two-factor authentication (2FA)

Two-factor authentication via SMS is the most widely used method. It allows you to reinforce your existing security system while benefiting from easy and inexpensive implementation. Users enter their logins (name and password), and SMS including OTP codes are sent to provide additional verification at login. With this two-step authentication, you benefit from enhanced security for all connections to your applications.

Multi-factor authentication (MFA) with SMS

Multi Factors Authentication (MFA) is a multi-step (usually 3) verification method before granting access to a system, application or data. The aim of MFA is to reinforce security by ensuring that the person attempting a connection is who they claim to be.

This authentication is based on :

In practice, when connecting to an online banking application, for example :

This method is the most reliable, as it is very difficult to forge/submit 3 verification factors at once. On the other hand, MFA represents a major development effort and can be complex to activate, especially for simple connection operations where 2 separate factors are more than sufficient.   

When should SMS OTP be used for authentication?

This type of SMS containing codes has gained notoriety for its use in securing online credit card payments. But SMS "One Time Password" can be used for many other purposes:

GOING FURTHER
All you need to know about SMS for 2FA

Understanding dual authentication ? How to deploy an authentication process? Which technologies and methods?

2FA Guide

The applications for these codes are virtually endless in the web and mobile world! smsmode© recommends that all companies using personal accounts with private data for their users implement authentication via SMS. You can really increase secure connections to your application or to unsecured networks with SMS OTP by sending temporary passwords.

Similarly, when registering a new customer, you can check their phone number with a code per message and ensure thatthe information is correct.

This process not only enables you to connect for the first time, but also guarantees you a certified database, enabling you to qualify your leads.
It is also possible to certify an electronic signature, enabling you to validate contracts remotely thanks to the codes generated.

SUCCESS STORY
Oodrive secures and accelerates electronic signature processes with SMS 2FA
oodrive, sms and digital signatures

What are the advantages of authentication via SMS ?

A significant convenience for the end-user: the use of cell phones in the account security process means that a code can be received very quickly on a medium that's close at hand. With immediate reception, the transmission of a unique unique code by SMS secures operations while making connections more fluid.

A universal medium that works on all mobile terminals and all global networks, giving all users a feeling of security, whatever their cell phone. Everyone will be aware of the security system protecting their personal data. And you won't need to develop an additional application to activate verification.

Certified collection of your customers' cell phone numbers to enrich your contact database with quality data: thanks to OTP, when a customer registers on your website, they can enter their phone number. This number is not always valid, and your database is therefore inaccurate. When they register, a code transmitted by SMS enables them to validate their number directly on your application or website.

Seamless integration and easy administration: this service is completely free of charge, and you will only be billed for SMS .

Why adopt the solution smsmode© ?

How to implement the SMS "One Time password"?

When you use ourstrong authentication solutionat SMS, you benefit from :

A powerful, documented REST API to implement SMS OTP. An alphanumeric code is automatically generated by your application or website. The OTP code is single-use, and its expiry date is defined in advance by your team. The SMS OTP routing implemented via the API is responsible for transmitting this code as quickly as possible via a high-priority channel dedicated exclusively to this type of transmission.

The routing of SMS 2FA or OTP to France, DOM-COM or international destinations is carried out on a dedicated, priority channel that is constantly monitored by our monitoring tools. The use of our web services also guarantees maximum security and total confidentiality of your data (encryption and hashing of user data).

GOING FURTHER
Pay by Link

Diversify your payment methods, offer the payment link sent by SMS

pay by link par SMS

Create your free account

Try out our SMS platform and benefit from 20 free test credits, with no obligation.

Need more info?
We look forward to hearing from you.

Appointment reminders and enhanced security at the heart of Doctolib's success

The Doctolib success story is a case study. How did the e-health platform manage to achieve the performance we all know about? Partly relying on SMS and its advantages right from the start. Let’s have a look at the 3 ways in which SMS has contributed to the success of France’s first unicorn.

80 million

PATIENTS IN EUROPE

500 million

APPOINTMENTS PER YEAR

25 million

TEXT MESSAGES SENT PER MONTH

ABOUT

Founded in 2013, French startup and unicorn Doctolib has celebrated its 10th anniversary. The medical appointment scheduling and management platform has revolutionized healthcare, with the aim of improving the daily lives of healthcare professionals and facilitating access to care.

SECTOR OF ACTIVITY

Healthcare

COMPANY SIZE

2,800 employees

CREATION DATE

2013

LOCATION

France
Germany
Italy
Netherlands

CHANNELS

- SMS

- OTP SMS

- TTS

INTEGRATION - API

USE CASES

- appointment reminder
- authentication

I particularly appreciate the relationship I have with smsmode© and being a pampered customer.

smsmode© keeps its product up to date and is proactive to legal disruptions or changes. We’re constantly talking to each other about monitoring and developments.
This is an important point. Because, over and above the criteria for choosing a provider, it’s important to make a long-term commitment, and that’s the case with smsmode©.
Thomas Grobost, product manager Doctolib

Routing performance

97,5%

OF SMS ISSUED

2,4 s.

AVERAGE TIME TO RECEIVE A TEXT MESSAGE

98%

OF SMS RECEIVED IN LESS THAN 5 SECONDS

Download the Doctolib success story

You may also, for legitimate reasons, object to the processing of your personal data. If you wish to exercise these rights, please send an e-mail to dpo(at)smsmode.com.

innovation and service excellence come first

Secure the application and accessibility of information via SMS

Doctolib undeniably disrupted the healthcare sector. What could be more normal today than to make a medical appointment online, 24/7, and to receive a reminder of the appointment a few hours beforehand?
Since its inception, Doctolib made SMS one of the axes for achieving its objectives to improve access to healthcare professionals. Activated at the friction points of one-to-one interactions, it makes the service more efficient, and adds that extra something to the Doctolib workflow that sets it apart: immediacy and accessibility.

First of all, there’s an appointment reminder, which is Doctolib’s most important use. Doctolib sends up to 4 reminders per appointment, either by email or push notification. Some of these reminders can be replaced by SMS for users who do not have a Doctolib account, do not use the mobile application or do not have push notifications activated (which is the case for almost 1 in 2 appointments). These SMS messages make it easier to read the information and, ultimately, help to reduce the number of appointments booked on Doctolib but not kept by up to 60%.

The second contribution of SMS is authentication. An OTP is systematically sent by SMS each time an account is created on the platform. It concerns not only patient account creation, but also on the professional side — even if other verification processes complete this first stage.
This authentication process is well tried and tested, as it has not been modified since its inception a few years ago. It also provides KYC — Know Your Customer — for new users, which is essential for any contact platform.
Voice messaging (with TTS) is the ‘accessibility‘ link in the Doctolib service. It deals with the issues of deliverability of the messages to landlines and accessibility for the visually impaired. What is the aim? To make their product accessible to as many people as possible.

SMS sent by Doctolib SMS sent by Doctolib Mensajes SMS enviados por Doctolib Von Doctolib gesendete SMS Messaggi SMS inviati da Doctolib

We still need SMS appointment reminders for people who don’t have the application and SMS OTP for new users...

data protection, security and performance, the shock trio

The figurehead of e-health

Another major challenge (and mission) facing Doctolib is to provide a high-performance and secure service that respects personal data. The SMS use must not only comply with the high standards of the healthcare sector, but also help the client to achieve them!

Data security and confidentiality are central to the Doctolib’s strategy. The importance of data protection and processing is a core of our integrity duty (and of the trust relationship we built up with our users). In addition to internal measures (encryption, HDS, audits, ISO/IEC 27001 certification, etc.), Doctolib’s partners are involved in meeting e-health requirements as subcontractors. They must offer a high level of security guarantees and certifications : data hosting exclusively on servers in Europe, RGDP Compliant, etc. And smsmode©  meets all these requirements.

For years, we’ve been working with the Doctolib team on a daily basis to ensure that we’re always ahead of the game when it comes to the legal security obligations.

The data requirement would be nothing without the monitoring of mobile message routing and performance. The Doctolib product team monitors deliverability rates, sending speeds and the availability of the routing service in real time. These KPIs are key to ensuring reliable routing and optimal management of the volumes of mobile messages sent, country by country, at all times. It’s a performance indicator that’s all the more decisive for SMS OTP because the service is based on immediacy. Close collaboration with the smsmode© technical team meant that the API calls for routes, channels and related prioritisation could be managed internally.

make way for the future...

Supporting Doctolib’s deployment and innovations

smsmode© has been supporting Doctolib since the very beginning. We have witnessed its hyper-growth: from a handful of SMS messages in 2013 to today 25 million SMS messages which are sent every month.

Doctolib has certainly grown with smsmode© and smsmode© has grown with Doctolib.

Beyond these figures, the SMS channel is accompanying Doctolib in its expansion, and its international expansion first and foremost. Even if the approach to healthcare is different in each country, the SMS channel plays the same key role in Germany, Italy and France, offering simplicity and convenience to patients who booked an appointment. It is also an important communication channel, to tell patients about the app’s new features...
... or to innovate and foreshadow the healthcare of tomorrow at the launch of the new markets. SMS is now available to healthcare professionals as a means of direct communication with their patients via the Doctolib interface. This new service for sending SMS and emails is available to practitioners in Germany, Italy and soon France, giving them the opportunity to send group communication to all their patients about the updates in their practice (office closures, holidays, etc.) or to send out prevention and vaccination messages to target patient groups (depending on their age, pathology, etc.).

Much more than just creating a close, privileged doctor/patient relationship, these new communication functions are the future face of the Doctolib brand: that of becoming a “health partner”.
The goal is to monitor our health throughout our lives, to become a cornerstone of prevention and... to have our health always at our fingertips (on our smartphone)!

Qualify incoming contacts with an OTP code by SMS

Spain's leading real estate portal,
Trovimap has integrated a
2FA (double-factor authentication) step into its estimation service.
A feature that has opened the doors to
lead qualification and
prospecting optimization.

+175 000

PROPERTIES FOR SALE OR RENT

-99%

OF UNQUALIFIED LEADS

ABOUT

As one of Spain's 3 leading real estate portals, Trovimap offers a simple and effective real estate experience for both private individuals and real estate professionals, with a property search based entirely on location.

SECTOR OF ACTIVITY Real estate

COMPANY SIZE

6 employees

CREATION DATE

2014

LOCATION

Spain

CHANNELS - SMS OTP
INTEGRATION - API

USE CASES

- authentication

Download the Trovimap success story

You may also, for legitimate reasons, object to the processing of your personal data. If you wish to exercise these rights, please send an e-mail to dpo(at)smsmode.com.

check the relevance of contacts at the start of the customer journey

Implement two-factor authentication on the property appraisal form

The Trovimap real estate portal features an estimation tool which, in just a few minutes, allows you to obtain the price of a property and market data (estimated sale and rental price, rental yield, price and market trends, cadastral report, etc.).

At the last stage of the form, the individual's contact details are requested to send the report. Validation of the user's mobile number by sending an One Time Password (OTP) to SMS has recently been activated.

We needed a very fast, simple and secure process that would enable us to validate the mobile number entered in the without too much friction.

The aim is tohave accurate, validated telephone contact details to enable the regional sales manager to contact individuals who want to sell their property at short notice.

SMS for the customer experience SMS for the customer experience SMS para la experiencia del cliente SMS für das Kundenerlebnis SMS per l'esperienza del cliente

an innovative lead generation strategy

SMS OTP as an essential tool in contact entry

Theactivation of two-factor authentication on the Trovimap platform is a recent change, after many years of non-validation. It also follows the observation that a significant proportion of accounts created were based on false information and fictitious identities. The technical departmenth gf Trovimap then evaluated several options (including the addition of a captcha). 

But it was SMS OTP, with a single-use numerical code sent by text message, that emerged as the quickest solution to implement (via API) and, above all, the most effective in achieving the desired result: verification of the surfer's identity.

Before the introduction of SMS OTP, we had around 20% of curious individuals or professionals who didn't want to show their identity. Today, we're almost at zero!

This authentication step counteracts 2 major and common problems encountered by SaaS (Software as a Service) platforms: either the telephone details are "accidentally" wrong due to a typing error, or the user intentionally enters false information.

By adopting a proactive, real-time verification of incoming contacts, carried out by Trovimap itself, it ensures the veracity of incoming contacts' mobile numbers before passing them on to the Sales team. This proactive approach underpins a crucial challenge for Trovimap: quality acquisition , which is closely linked to improving the efficiency of sales prospecting.

a high-quality prospect database

The benefits of lead verification

Because beyond the strict validation of telephone numbers, the qualification of incoming leads is the guiding principle behind Trovimap's approach. Collecting data - and relevant, reliable, usable data at that - is a basic principle that is essential for sales teams to make the most of it andimprove prospecting. Because, let's not forget, both a lack of information and erroneous data result in lost time, money and ROI.

The issue of lead quality and qualification is central: identifying SQL is now a decisive element in an inbound contact generation strategy.

By adopting lead nurturing using OTP and SMS - which removes and disqualifies the person from the outset - Trovimap has adopted a method that may be radical, but it' s frighteningly effective. From the moment they enter the database, Trovimap and its teams have access to only the most highly-qualified opportunities (MQLs, not SQLs), so that they can concentrate on those contacts with the highest intent and most likely to convert... all by sending a simple text message!

In short, this double authentication process via SMS OTP has been approved by the Trovimap team and is now proving to be their best lead capture asset. The only regret today is that they didn't implement it before, so they could have benefited from its advantages sooner!

THE smsmode© blog ©

THE SMS OTP (One Time Password) - The new utility for secure deliveries

August 3, 2022

The COVID19 crisis necessitated an adaptation of company operating methods, in particular the systematic practice of barrier gestures and the generalization of telecommuting. But there are also adaptations that have given rise to new practices that improve processes, such as today's topic: SMS OTP as a means of securing your deliveries.

Continue reading " SMS OTP for secure deliveries "

THE smsmode© blog ©

Reverse OTP: free authentication with SMS

July 18, 2022

Data security is a concern for many customers. To satisfy this need for reliability and gain a competitive edge, many solutions implement two-factor authentication (2FA), often via a SMS OTP. But implementing 2FA is costly, and each message sent is billed. But there's a way to guarantee strong authentication without the OTP messages costing you a single penny. Find out how to set up a free SMS OTP in this article.

Continue reading " How to set up free authentication on your application "

Reduce signing times with SMS 2FA

Oodrive Sign provides electronic signature solutions that guarantee full legal validity and evidential weight. It capitalises on the strength of SMS authentication to enhance, simplify, and expedite the transition of agreement and approval processes into digital workflows. A wealth of experience and innovative use of SMS OTP...

1 500

SATISFIED SIGNATORIES

4 min.

TO NOTIFY THE SIGNATORY

ABOUT

Oodrive is the European leader in sensitive data management for businesses. More than a million people use their software suite, which includes “Oodrive Sign”, which enables the automation of business processes involving electronic signatures with legal value.

SECTOR OF ACTIVITY

Corporate Services

COMPANY SIZE

400 employees

CREATION DATE

2000

LOCATION

France Germany Spain

CHANNELS

- OTP SMS

- SMS

INTEGRATION

- API

USE CASES

- authentication
- notification

Download the Oodrive success story

You may also, for legitimate reasons, object to the processing of your personal data. If you wish to exercise these rights, please send an e-mail to dpo(at)smsmode.com.

sign electronic documents swiftly in record time

Workflow acceleration as a priority

Notification to the signatory(ies) of the contract when a document needs to be signed. Identification and consent process of the signatories. Alert message when a document is countersigned by all parties.

For Oodrive Sign, all the key moments in the dematerialised signature process are associated with a scenario triggering the sending and/or receiving of an automated SMS messages via API requests implemented in their secure SaaS environment.

We have recently introduced SMS to push the contract to the signatory in addition to email to notify them more quickly that a document is available to sign.

The objective. To make remote approvals as smooth and time-efficient as possible, and to support the diversity of uses, particularly that of mobility.
Undeniable advantages for the dematerialization and digitization of business processes.

notification of a document to be signed by SMS notification of a document to be signed by SMS notificación de un documento que debe ser firmado por SMS Benachrichtigung über ein zu unterzeichnendes Dokument per SMS notifica di un documento da firmare via SMS

SMS makes identity verification 100% mobile

The power of dematerialised identification with SMS

Simple signature, advanced signature, qualified signature. The degree of identity verification of the signatory and the guarantee of the document differs between these different levels of security of an electronic signature.

A One Time Password sent by SMS is generated for ONE signatory and for ONE contract. The signatory must re-enter this code on the contract. It is this precise action that is the legal basis for consent in the case of a remote signature.

SMS 2FA — two-factor authentication — is a key component of remote signature authentication and is a necessary element of proof to elevate a “simple” signature to an “advanced” one.
Commonly used in the sector and particularly well accepted by users, this unique and temporary code ensures the second authentication factor of the signatory (after the email which integrates a secure link to the document to be signed), reinforces the legal proof file and links the person to the act.

Another application of double authentication by SMS implemented by Oodrive Sign is the “dialog signature”. This solution opens the door to a 100% mobile signature. For the signatory, there is no need to enter the OTP code received in the contract displayed on his web browser (which he will probably have forgotten in the meantime); everything takes place on the SMS message service. They simply reply to the SMS received by re-entering the code... and the signature is instantly approved on the Oodrive Sign application. An innovative and fluid technology that sweeps away the friction points of a classic One Time Password!

SMS ensures evidential value

The legal aspect of digital identification

In the context of the dematerialisation of documents, the SMS 2FA is a main asset to univocally guarantee the identification of the signatory and the integrity of the signed document. This method of remote digital identification is part of a strict legal framework defined by the European eIDAS regulation.
SMS is considered by these organisations as a secure and highly reliable authentication method.

The highly secure unique digital identity on which SMS 2FA is based is associated with the SIM card and the obligation of telecom operators to verify the identity of the subscriber.

This legal and evidential value of SMS cannot be provided by other mobile messaging channels (RCS, WhatsApp or Messenger), due to the absence of a verified identity associated with the opening of an account.

The future of the electronic signature lies in the progression of qualified digital signature modes to further limit the risks of identity theft. Always associated with a One Time Password received by SMS, they include a more advanced verification of the identity document — on photo, by video, by face scan to identify a signatory — or even signing face to face remotely thanks to augmented reality! Innovations on which Oodrive plays a pioneering role...