During a pricing review at a Tier-2 MNO, Southeast Asia, ~18M subscribers, the wholesale team had a familiar contradiction on the table: enterprise A2P SMS volumes were rising, yet international termination receipts were not. The investigation centred on A2P SMS firewall policy, but the harder question was commercial: which traffic should be blocked, rerated or allowed through without degrading OTP delivery and driving legitimate senders to alternative channels.
The traffic gap was visible before the route was proven
At the Tier-2 MNO, Southeast Asia, ~18M subscribers, the initial evidence was financial rather than forensic. Enterprise messaging activity had expanded across banking, payments and platform accounts. The wholesale forecast therefore assumed a corresponding increase in international A2P termination income. Receipts remained broadly flat. Neither the firewall dashboard nor aggregate SMS volumes explained the divergence. The working hypothesis was grey-route exposure, but the operator first had to establish which messages were commercially addressable, which were already covered by domestic arrangements and which could be attributed to a bypass route with sufficient confidence to support enforcement.
Headline volume was a poor proxy for recoverable revenue. P2P-masked traffic could resemble ordinary subscriber messaging. Domestic SIM-based injection could terminate successfully without entering the expected international charging path. Hub routing could obscure the original commercial source, while sender-ID manipulation and handset-farm activity produced delivery records that appeared locally valid. A long-number OTP was not necessarily fraudulent, just as an alphanumeric sender was not necessarily contracted. The issue was not whether the message reached the handset. It was whether the route, sender and charging treatment aligned with the operator’s commercial policy.
The investigation therefore joined evidence that usually sat in separate systems. SMSC and firewall logs established submission, filtering and delivery events. Originating GT and SCCP metadata, where retained, helped map signaling origin to contracted routes. Sender-type distribution showed whether traffic was moving from registered alphanumeric identities into long numbers or rotating domestic identities. Route-specific delivery rates exposed paths whose performance was inconsistent with declared use. SIM-level concentration identified unusually productive subscriptions. MNP outcomes tested whether routing decisions reflected current network ownership. Settlement records then showed whether the traffic classification had reached an invoice.
This evidence stack separated route proof from risk scoring. A sudden increase in alphanumeric traffic, high OTP velocity or concentrated delivery to a narrow destination range justified scrutiny. None proved bypass on its own. Blocking on isolated indicators would have converted uncertainty into a customer-impact event. The stronger cases combined signaling origin, sender behaviour, delivery history and a missing or inconsistent settlement path. That standard mattered because any rerating decision could be challenged by a hub, aggregator or enterprise account with its own message records.
A Tier-2 head of wholesale recently observed that the argument is never about whether traffic exists; it is about whether we can classify it well enough to charge it without harming delivery.
Control design must protect revenue, deliverability and settlement integrity together
Grey-route containment becomes more reliable when sender validation, firewall policy and commercial enforcement operate as one governed process. Sender validation should create accountable traffic classes: registered enterprise senders, approved aggregators, bilateral partners, domestic application routes and unknown or anomalous sources. The purpose is not to declare every unregistered sender illegitimate. It is to give each class an owner, an expected route, a pricing treatment and an escalation path. Without that structure, the firewall can block traffic, but wholesale cannot consistently convert the action into recognised revenue.
Policy should combine sender identity, signaling origin, message velocity, destination concentration, SIM behaviour and historical delivery patterns. A registered sender arriving through an undeclared route may require rerating or partner escalation rather than rejection. A domestic long number generating sustained OTP traffic across thousands of destinations may justify throttling while the associated account is examined. An unknown sender with stable volumes and a contracted aggregator path may require registration, not interruption. Multi-signal policy gives the operator more control than a broad rule that treats all A2P-like traffic outside a sender registry as hostile.
The enterprise constraint is material. Banks, fintechs and platform partners often use shared messaging infrastructure, multiple sender identities and variable route selection. Traffic can move during congestion, maintenance or supplier failure without advance notice reaching the MNO’s firewall team. A rigid sender policy may improve the apparent block rate while reducing authentication completion and increasing account escalations. Where delivery becomes unpredictable, legitimate senders can divert volume to another operator, a push channel or OTT bypass. The operator then loses both the disputed traffic and the opportunity to regularise it.
Technical policy must therefore sit inside enforceable commercial controls. Bilateral agreements should state A2P rates, permitted sender categories, route declarations and audit rights. Hub and aggregator contracts should assign responsibility for sender registration, downstream sourcing and traffic reclassification. Invoice reconciliation should compare billed classes with firewall-observed classes rather than relying only on aggregate message counts. Route-level evidence should remain available for disputes over origin, delivery and rate application. A block that cannot be linked to a contractual provision may stop traffic temporarily, but it rarely produces durable recovery.
The required operating model crosses wholesale, interconnect, fraud, messaging operations and enterprise account teams. Wholesale owns the rate and partner consequence. Fraud and messaging operations control detection and policy execution. Enterprise teams supply sender context and assess delivery impact. Changes need staged implementation, measured exception handling and post-change monitoring by route, sender and delivery outcome. The relevant metric is not the proportion of messages blocked. It is the improvement in recognised A2P revenue after deducting false-positive costs, dispute exposure, partner attrition and legitimate volume lost to alternative channels.
Evidence and exception ownership determine whether recovery holds
The control model weakens if evidence disappears before the commercial dispute begins. Firewall events, SMSC records, signaling metadata, sender-registration history, policy versions and settlement extracts often follow different retention schedules. By the time an invoice is challenged, the operator may retain a block decision but not the route context that justified rerating. Evidence retention should therefore reflect billing and dispute windows, not only operational troubleshooting needs. Each enforcement event should be reproducible: what the operator observed, which rule applied, what exception was considered and how the resulting traffic class reached settlement.
Exception ownership is equally important. Temporary allow-listing can preserve OTP delivery during failover, but an exception without an expiry, accountable approver or commercial follow-up becomes a standing bypass. Conversely, a technically justified block can remain in place after a sender has corrected its route because no function owns restoration. Operators need one decision record covering the exception scope, expected traffic, expiry condition and revenue treatment. The owner must be able to coordinate wholesale, operations and the enterprise account rather than passing the case between separate queues.
An MVNE servicing 12+ tenants in EMEA faces an additional governance problem. Shared firewall and messaging infrastructure can detect common route patterns, while sender ownership, retail commitments and settlement terms differ by tenant. A policy that is economically correct for one tenant may be contractually wrong for another. Evidence must preserve tenant attribution, and exception authority must remain aligned with the relevant wholesale agreement. Otherwise, the host may improve network-level blocking while creating tenant-level reconciliation disputes.
Grey-route control is becoming a margin-protection discipline rather than a standalone fraud exercise. The operators most likely to recover revenue are not those reporting the highest block rate. They are those that can explain why a message was classified, priced or rejected, show the supporting route evidence and reconcile that decision through settlement. That combination protects A2P income without making enterprise delivery less predictable. It also turns the firewall from a blunt blocking layer into a governed revenue and delivery-control system.
