HomeBlogNew SMS Regulations in Spain: What Is the CNMC Alias Registry and What Changes
API Insights

New SMS Regulations in Spain: What Is the CNMC Alias Registry and What Changes

How the CNMC Alias Registry works in Spain and how to register or update Aliases to avoid SMS delivery blocks

The telecommunications market in Spain is undergoing a major regulatory shift aimed at combatting deceptive messaging, SMS phishing (smishing), and sender spoofing. 

The CNMC (Comisión Nacional de los Mercados y la Competencia) has introduced the Registro de Alias, an official and mandatory registry that catalogs all alphanumeric identifiers (Sender IDs) associated with SMS, MMS, and RCS messages sent to Spanish phone numbers.

In this regard, the CNMC urges companies to register their aliases and respond to the agency's communications on the matter by September 15 to avoid interruptions in their communications.

Below, we explain how the Spanish regulation works and the steps to take to comply and prevent any service disruption to your messaging services.

How the CNMC SMS Registro de Alias Works

The new regulation mandates that no promotional or transactional SMS with a customized alphanumeric Sender ID (e.g., brand name) can be delivered in Spain without formal approval.

The key operational points are:

  • Legitimacy Requirement: Every Alias must be linked to a legitimate owner (via a registered trademark, corporate name, web domain, or documented professional use).
  • Blocking of Unauthorized SMS: Spanish telecom operators automatically filter and block all messages originating from an unregistered or unauthorized Alias.
  • Universal Scope: The rule applies to any sender, regardless of whether the message is sent from within Spanish territory or as an international transmission targeting users in Spain.

What Changes: Complete Alias Management and Registration via API 

To comply with the new regulation introduced by the CNMC in Spain, Openapi enables the complete registration of the Alias and the submission of the required documentation directly via API.

The update to corporate endpoints allows users to programmatically manage the entire onboarding process, including the upload of identification details and required files (LOA and Responsible Declaration). 

The procedures to follow depend on the status of the Alias.

New Customers or Initial Configuration of an Alias for Spain 

If you need to launch an SMS campaign targeting Spanish numbers or have never registered a Sender ID for this country, the procedure involves a new registration via the endpoint “POST /senders/alias”. Alternatively, the entire process can also be conveniently managed via the graphical interface, using the configuration tool available in the Dashboard under the API section “SMS v2”, within the “Configuration” tab. 

The Spanish regulator CNMC requires that the Alias must be strictly alphanumeric and that the Alias holder (alias holder) is explicitly declared. The holder is the person or company owning the Alias, which may be the Openapi account holder or a third party.

The data entered into the API must match the information reported in the two signed documents (esLoA and esResponsibleDeclaration) exactly. Any discrepancy will lead to the automatic rejection of the request by the CNMC.

Mandatory Data to Submit

During the call, you must provide the identification parameters of the Sender ID as well as the personal/corporate and tax details of the Alias holder:

Sender ID and Service Details:

  • countryCode: The 2-letter ISO code of the destination country (e.g., “ES”).
  • senders: The Alias you wish to register. It must be between 3 and 11 alphanumeric characters long (spaces allowed) and contain at least one letter; it cannot be purely numeric (e.g., MyBrand).
  • companyWebsite: The full website URL of the Alias holder (e.g., https://www.mycompany.com). The CNMC checks whether the Alias matches this domain to validate the claimed relationship; submitting a website not owned by the holder jeopardizes the validity of the declaration.
  • senderCompanyRelationship: A description of the relationship between the Alias and the holder (max 60 characters, e.g., brand, trade name, company name, product name). If the Alias does not match the corporate name or registered domain, this text is submitted directly to the CNMC as the holder's justification for using the alias; therefore, it must describe the holder's own relationship with the alias, not that of the entity performing the registration.
  • industry: The company's industry sector (max 50 characters, e.g., e-commerce).
  • trafficType: The type of SMS traffic being sent (e.g., transactional or promotional).

Holder Entity Type and Personal/Corporate Details (Alias Holder)

  • aliasHolderType: Specifies whether the Alias holder is a legal entity/company (LE) or a natural person (NP). The selection of this value determines which profile fields must be filled:
    • If Legal Entity (LE): Declare the official Company Name in aliasHolderName and leave surnames blank.
    • If Natural Person (NP): Declare the first name in aliasHolderName and complete the field for the first surname (holder1stSurname).
  • aliasHolderTaxId: Tax Identification Number of the Alias holder (max 20 characters, e.g., B12345678). The corporate tax ID for a legal entity, or the personal tax ID (NIF, NIE, or equivalent in the holder's home country) for a natural person. It must strictly match the number on the signed documents.
  • aliasHolderName: Official company name (if “LE”, e.g., TERCERO EJEMPLO, S.L.) or the first name of the natural person (if “NP”).

Postal Address of the Alias Holder

  • holderMailingAddressStreetAvenue: Street name/thoroughfare of the holder's registered office or residence, without street number (max 40 characters, e.g., Calle Gran Via).
  • holderMailingAddressStreetNumber: Street number (max 8 characters). For properties without a number, use the standard Spanish designation S/N (Sin Número).
  • holderMailingAddressPostalCode: Postal code (max 10 characters, e.g., 28013).
  • holderMailingAddressCountry: The 2-letter ISO country code of the holder (e.g., “ES”). This parameter determines which authorized representative is declared to the CNMC and must match the esLoA template used (holders in Spain sign the IB_ES form, while foreign holders sign IB_UK).

Mandatory Documents to Attach

Documents must be attached as Base64-encoded PDF files (maximum size 5 MB each), choosing the appropriate template for your corporate structure and relationship to the Alias.

esLoA: Letter of Authorization (Carta de Autorización)

A letter signed by the Alias holder authorizing the aggregator to represent them before the CNMC. There are 4 distinct templates based on the entity type and location of the holder:

  • Natural person residing in Spain (or with legal residence)
  • Company with registered office in Spain
  • Natural person outside Spain
  • Company with registered office outside Spain

Signing a template that does not correspond to the declared country or entity type will result in the rejection of the request.

esResponsibleDeclaration: Responsible Declaration (Declaración Responsable)

A formal self-declaration in which the holder certifies the legitimate use of the Sender ID. It is available in 4 templates, structured according to the nature of the entity (natural person or company) and the presence of an official link (connection):

  • With connection: The alias matches, or is an abbreviation or extension of, the holder's registered corporate name, or a registered Internet domain listed as the company's website.
  • Without connection: The alias is used solely de facto as part of commercial activities, without any supporting registry entry.

The 4 available forms:

  1. Natural Person — With connection
  2. Company — With connection
  3. Natural Person — Without connection
  4. Company — Without connection

The connection between the alias and its holder is derived from registration details and reported to the CNMC; therefore, declaring an incorrect variation contradicts submitted data and will result in request rejection.

IMPORTANT: The sender must clearly refer to the company or one of its registered trademarks and must not be generic: generic aliases (e.g., Info, Alert, Notify, SMS, Verify, Support) are at risk of being rejected by reviewers and mobile network operators. Instead, using your company or brand name is strongly recommended (e.g., Openapi, OpenapiOTP, OpenapiInfo).

If You Have Already Configured an Alias for Spain

If you already have an active Sender ID for Spain within the Openapi platform, you do not need to create a new Alias. You simply need to supplement the existing registration data.

The endpoint to use is “PATCH /senders”.

Through this call, you must submit the new mandatory fields required by Spanish regulations, paying close attention to:

  • LOA (Letter of Authorization): The duly completed Letter of Authorization (esLoA).
  • Responsible Declaration: The formal documentation certifying the legitimate use of the Alias (esResponsibleDeclaration).

This procedure will ensure service continuity for SMS messaging to Spain while maintaining full compliance with directives established by the CNMC. 

Approval Timeline and Preemptive Message Blocking

Planning your compliance well in advance is essential due to the timelines expected by the Spanish regulatory authority.

Verification through the Spanish Registro de Alias can take up to 30 days for final request approval.

Until completion and formal approval of the Alias, sending SMS to Spanish numbers will not be possible.

This block applies to requests submitted via the Spain-specific endpoint as well as transmissions initiated via the global endpoint directed to a Spanish recipient number.

Furthermore, before proceeding with implementation or system updates, it is always advisable to consult the official technical documentation. As infrastructure changes alongside industry regulations, API specifications may evolve, introducing new parameters or deprecating old ones. Reviewing up-to-date documentation guarantees proper request formatting and helps prevent errors during transmission. 

How to Monitor Request Status

To monitor the approval status of your Sender ID in real time, Openapi provides two main tools:

  • Automatic Callback: You can specify a callback URL directly during initial registration via the “POST /senders/alias” endpoint to receive notifications as soon as the status changes.
  • API Querying: You can manually check request status at any time by calling the following endpoints:
    • GET /senders” (for a list of senders and details)
    • GET /senders/{id}” (to check the status of a specific Alias)
Spain SMS Alias Registry: Complete Guide to Avoid Blocks
Share on