Are smishing and vishing simulations legal in Spain?

Ilustración plana de una persona en un mostrador de correos entregando un sobre con un remitente que no le pertenece, mientras el empleado detiene el envío y compara el nombre con un registro abierto sobre el mostrador

Are smishing and vishing simulations legal in Spain?

Since 15 September 2026, Spanish carriers block any SMS whose alphanumeric sender ID is not listed in the Alias Registry held by the National Commission on Markets and Competition (CNMC). The short answer to the question in the title is that a smishing simulation impersonating a third party is no longer viable in Spain, and that a vishing simulation operates in a considerably narrower margin than most people assume.

For the purposes of this analysis, we will take a smishing simulation (text message fraud) or a vishing simulation (voice call fraud) to mean any awareness exercise that sends a message or places a call under an identity other than the real one, in order to measure how the people in an organisation react and what they actually know. For years that definition described a good practice. Today it also describes the very conduct that Spanish regulation targets.

What does Spanish regulation require carriers to block?

Order TDF/149/2025 of 12 February, published in the Spanish Official Gazette on 15 February 2025, sets out measures to combat identity-spoofing fraud carried out through phone calls and fraudulent text messages. It imposes four separate obligations on carriers, each with its own timeline. Conflating them is the most common mistake when assessing the impact on awareness exercises.

Obligation Article In effect since
Blocking calls with an empty CLI or with Spanish numbering not attributed, assigned or allocated Art. 4 7 March 2025
Blocking international calls presenting Spanish numbering, except roaming Art. 5.1 June 2025
Ban on mobile numbering for customer service and unsolicited commercial calls Art. 9 June 2025
Blocking SMS, MMS and RCS messages with unregistered aliases or sent by unauthorised providers Arts. 7.2 and 8 15 September 2026

The registration procedure is not in the Order itself. It is set out in Circular 1/2026 of 18 March, issued by the CNMC, published in the Official Gazette on 27 March and later amended by Circular 2/2026, which adjusted the timeline and the bulk upload regime for alias holders.

Worth clarifying that the 400 prefix does not come from this Order, even though the two are often cited together. It stems from Act 10/2025 on customer service and from the resolution of 14 April 2026 issued by the Secretariat of State for Telecommunications and Digital Infrastructure, which sets a six-month period from its entry into force that ends on 17 October 2026. From that date, commercial calls may only be placed from the 400 range.

Blocking calls that do not use it comes from the Ministry’s announcement when the resolution was approved; the text itself does not impose it on carriers.

The purpose behind all of this is legitimate and necessary, and curbing identity-spoofing fraud benefits any organisation operating in Spain. Worth noting, though, is what the rules did not do. Having been able to carve out an exception for messages whose purpose is end-user awareness, a legal possibility that was on the table, the regulator did not provide one. There is no training exemption to invoke.

Spain is not an isolated case. Italy went down the same road years earlier: its SMS alias database has been running since Delibera 12/23/CIR of May 2023, and the caller-ID spoofing filter introduced by Delibera 106/25/CONS has been blocking fixed-line calls since 19 August 2025 and mobile calls since 19 November.

AGCOM reported that between 19 and 30 November 2025 some 49.3 million calls using spoofed Italian mobile numbering were blocked, close to 56% of all calls received with that kind of numbering. The timetable shifts from one country to the next. The regulatory direction is the same.

Why can a smishing simulation not register its alias?

Article five of Circular 1/2026 requires proof, by way of a responsible declaration, of a legitimate link between the alias and one of the following: a trademark filed with the OEPM or the EUIPO, a trade name, the company name recorded in the Commercial Registry, a registered internet domain, or an equivalent public register.

That settles the discussion. Neither the organisation commissioning the exercise nor the provider running it holds any link to the brand of the banking institution, the courier company or the public body the scenario sets out to impersonate, however real the commercial relationship with that entity may be. Being a bank’s customer confers no right whatsoever over its name.

From that date on, sending a campaign could fall into one of these two scenarios, and neither is good.

  1. The message is blocked at the carrier before it reaches the recipient, which obstructs the exercise and leaves the measurement without meaning.
  2. The message reaches its destination under an unauthorised identity, exposing both the party running it and the party commissioning it to a dispute over trademark misuse or unfair competition.

We take the view that each organisation has to weigh for itself whether that level of legal, operational and reputational risk is acceptable. What does not seem reasonable is taking it on without knowing it exists.

Is vishing in the same position as smishing?

Not quite, and the difference matters. There is no voice equivalent of the alias registry. The filter is the calling line identification or CLI, which article three of the Order defines as the number belonging to the subscriber the call originates from, or whose use has been authorised by the Secretariat of State. A third party’s number presented without that authorisation does not fit the definition.

In practice, automatic blocking covers three cases: an empty CLI, Spanish numbering not attributed, assigned or allocated, and inbound international calls presenting Spanish numbering outside roaming scenarios. That last scenario covers a large share of vishing exercises, given that they are typically placed from platforms hosted outside Spain.

Impersonating, from Spanish territory, the real and already assigned number of a third party is not caught by that automatic filter. Nor does it amount to a legitimate CLI under the Order, and exposure to the impersonated entity over use of its brand is identical to smishing. The margin exists, but it is narrower than it is generally taken to be, and it rests on a legal assessment rather than a technical decision.

What can be done within the law?

Measuring how people respond to smishing and vishing remains a legitimate and worthwhile goal. The problem is not the assessment, it is the way it is carried out. Two viable routes remain within the current framework.

Use the organisation’s own identity. The rules allow an organisation to register its own alias, including a secondary one such as ACME HR or ACME SEC, and to authorise, within the registry, the provider that will send messages on its behalf, subject to the holder’s express authorisation. An alias accepts between 3 and 11 characters and cannot be purely numeric, which forces more abbreviation than most organisations expect.

The exercise keeps its credibility, since it arrives under the employer’s real name, and it stays within the law. Under this route, only simulations originating from the organisation itself can be sent.

Obtain express authorisation from the entity involved, where the scenario genuinely calls for it. This is the only way to faithfully reproduce a “your bank is calling” case, and it requires that entity’s direct cooperation rather than a commercial relationship with it. Without that authorisation, simulations cannot be delivered on behalf of third parties.

What to ask an awareness provider

If your organisation is buying or assessing smishing or vishing simulation services, these are the minimum questions to ask before signing.

  1. Under which alias or numbering will the simulation’s messages be sent or its calls be placed?
  2. Is that alias listed in the CNMC Alias Registry, and under whose name?
  3. If the scenario impersonates a third-party brand, is there express authorisation from that entity?
  4. What happens to the campaign and to the measurement if the carrier blocks it mid-run?
  5. Who bears legal responsibility if the simulation uses an unauthorised identity, the provider or my organisation?

If there are no clear answers to these five questions, the risk has not gone away. It sits with the commissioning organisation as a legal and compliance risk, and all that has happened is that it has not been made visible yet.

Where we stand

At SMARTFENSE we do not offer smishing or vishing simulations. This is not a technical limitation, but a decision taken in the face of a field where there is currently no way to guarantee both a realistic exercise and regulatory compliance without taking on legal risks we consider unnecessary for our clients. It is the same reasoning we applied when we looked at whether psychological profiling on awareness platforms is legal.

We remain committed to training and assessing people against phishing with the platform’s simulation tools, on the best practices we have argued for over the years, and with our own standard for what makes a phishing simulation safe.

The Alias Registry was not designed with awareness exercises in mind, and its effect on them is incidental. That registry nevertheless sets the terms of the field today. Anyone who wants to keep measuring by SMS or by phone in Spain will have to do so under their own identity, or under a borrowed identity with permission. Any other route has stopped being a technical decision and become a legal bet.

Marcelo Temperini

Abogado y Doctor en Derecho por la Universidad Nacional del Litoral, con tesis dedicada a delitos informáticos y cibercrimen. Especializado en Cibercrimen y Evidencia Digital (UIC, España), Derecho Informático (UNRN) e Informática Forense (UFASTA). Técnico Analista de Seguridad y Vulnerabilidad de Redes de Información (ESR). Socio Fundador de AsegurarTe y co-fundador del Proyecto ODILA (Observatorio de Delitos Informáticos de Latinoamérica). Docente de posgrado en UNL, UBP, UFASTA, UNSO, UNT, UCSE e IUSE en Protección de Datos Personales, Evidencia Digital y Delitos Informáticos. Director de la Village "A 1 bit de ir en cana" en Ekoparty desde 2020.

Leave a Reply