Unable to deliver SMS to "VOIP" phone using some services

Status
Not open for further replies.

Felicia King

Silver Partner
Advanced Certified
Joined
Jun 13, 2019
Messages
88
Reaction score
24
I have encountered a number of services that are using restrictions that contradict business continuity efforts. A business continuity effort is to use a phone number that is owned by the business and can be accessed by a number of individuals. For example, a SMS-enabled Twilio phone number or a Google Voice number. I attempted to help a client setup a Hunter.IO account for their marketing efforts for their business. The account needs to be owned by the customer and accessible to more than one person in the marketing department. During the initial account setup, Hunter.IO requires attachment of a SMS-enabled phone number. I tried using a Twilio SMS-enabled phone number and a Google Voice number. In both cases, the service says that a VOIP number is not allowed and a mobile phone number must be used. I have encountered this before with Microsoft and Google in general.

The Twilio number we are using has been verified and certified by Twilio as tied to the customer's business. This is part of the shaken/stir initiative.

DeliveryFailed.png

Have any of you encountered this also and do you know what the real back end mechanism is that is occurring? From my viewpoint, Hunter.IO has no real desire to SMS their customer because they are not allowing any SMS-enabled phone number. What it appears they are trying to do is to engage in an intrusive level of spying where they are doing a phone number look up to a number that has been "know your customer" identified through the legal restrictive process that is used to provision mobile phones.

It is not legal for a mobile phone provider to provision a mobile phone and a phone number with it where they have not engaged in "know your customer" where they have obtained driver's license or other highly intrusive inspection.

Right now we are at an impasse for being able to sign up for any service that requires it be tied to a personal cell phone number. That does not lead to business continuity for our clients. Is there a solution to this which does not involve using a cell phone number tied to an individual? And we do not want to go to the expense of paying $100/mo for a cell phone owned by the business. The clients have business-owned phone systems and provide employees with phone services through their desk phones and their 3CX mobile apps with the company owned 3CX phone system.
 
I've seen that happen with a Text Now number, being refused, as valid as it is "not a Mobile number". Unless there is government legislation preventing this sort of thing, or pressure put on certain providers, I expect they will continue as they see fit. I've seen Google Voice refuse to forward to a number they don't consider a mobile. Perhaps that has now changed.
 
  • Like
Reactions: YiannisH_3CX
I've seen that happen with a Text Now number, being refused, as valid as it is "not a Mobile number". Unless there is government legislation preventing this sort of thing, or pressure put on certain providers, I expect they will continue as they see fit. I've seen Google Voice refuse to forward to a number they don't consider a mobile. Perhaps that has now changed.
Google definitely still refuses to forward to anything not deemed as "mobile".
 
You can get business mobile service if this is really that big of an issue.. But yes, everyone has dealt with the issue you described and there's not much you can do about it.
 
I got into a deeper exchange with Hunter.IO. They are playing games in this area with the mobile number in an effort to try to stop abuse of their service by people signing up for a bunch of free accounts. I suggested to them that they stop requiring a gmail account as the only integrated auth and look into enabling Azure AD enterprise OAUTH integrated authentication. If they are trying to stop abuse by people creating a bunch of free accounts, they should make it easier for legit businesses to use their service. Considering that a significant percentage of companies that maintain authentication databases on users and collect data end up failing to properly secure that data, the last thing we want is more accounts and more authentications that are disparate.
If they would allow Azure AD integrated authentication like using their service as an OAUTH integrated app, then they would not feel that they need to be asking for information that has nothing to do with their service, such as personal cell phone numbers.
They told me they would take it under advisement.

Business mobile service still requires the driver's license of the business owner to be associated with the account. It is treated the same as opening a bank account with "know your customer" laws. It is vey intrusive and the companies that collect and use this data tend to fail to protect it adequately and abuse the information. We stopped doing business with ATT entirely because of this.

We should start pushing back more on service providers on why they think they need this type of information such as a mobile number. Hunter.io seemed open to the feedback and allowed me another method for account activation validation when challenged.
 
I got into a deeper exchange with Hunter.IO. They are playing games in this area with the mobile number in an effort to try to stop abuse of their service by people signing up for a bunch of free accounts. I suggested to them that they stop requiring a gmail account as the only integrated auth and look into enabling Azure AD enterprise OAUTH integrated authentication. If they are trying to stop abuse by people creating a bunch of free accounts, they should make it easier for legit businesses to use their service. Considering that a significant percentage of companies that maintain authentication databases on users and collect data end up failing to properly secure that data, the last thing we want is more accounts and more authentications that are disparate.
If they would allow Azure AD integrated authentication like using their service as an OAUTH integrated app, then they would not feel that they need to be asking for information that has nothing to do with their service, such as personal cell phone numbers.
They told me they would take it under advisement.

Business mobile service still requires the driver's license of the business owner to be associated with the account. It is treated the same as opening a bank account with "know your customer" laws. It is vey intrusive and the companies that collect and use this data tend to fail to protect it adequately and abuse the information. We stopped doing business with ATT entirely because of this.

We should start pushing back more on service providers on why they think they need this type of information such as a mobile number. Hunter.io seemed open to the feedback and allowed me another method for account activation validation when challenged.
Mobile phone verification is the worst kind of security and fraud prevention.

I don't know why companies still consider this a viable way.
 
Business mobile service still requires the driver's license of the business owner to be associated with the account. It is treated the same as opening a bank account with "know your customer" laws. It is vey intrusive and the companies that collect and use this data tend to fail to protect it adequately and abuse the information. We stopped doing business with ATT entirely because of this.
Correct but your post topic and this statement seem to indicate a different priority:

Right now we are at an impasse for being able to sign up for any service that requires it be tied to a personal cell phone number. That does not lead to business continuity for our clients. Is there a solution to this which does not involve using a cell phone number tied to an individual? And we do not want to go to the expense of paying $100/mo for a cell phone owned by the business. The clients have business-owned phone systems and provide employees with phone services through their desk phones and their 3CX mobile apps with the company owned 3CX phone system.
I didn't read this far done If $100/month is stopping you, then it doesn't seem to be that big of an issue. I can certainly understand your concerns, but at the end of the day, there are solutions currently available for continuity which seems to be the primary concern.. I assume you charge money for your services and I would imagine you've already spent several months of service in your discussions with Hunter.io. Heck, I would say with COVID pretty much all of my customers save over $100/month for things like paper because no one is in the office printing anything.

I do imagine things will change at some point. As more business transition to VoIP this is going to become more and more of an issue so something will have to change.
 
There are bigger issues at play. If you use a phone number that is demarked into an IMEI in a mobile device, that device and its contents are only accessible in one place to one person. That is the antithesis of business continuity unless it is one's intent to buy every employee that does a function a cell phone.

I know IT service providers that were doing this kind of silliness when everyone worked in the same office. There was still zero accountability as to who was accessing that content and if they were using that number for SMS MFA validation or what they were enrolling. We require identity and access management systems for compliance, audit, accountability, and role-based access control, that is accessible from all authorized locations.

We have a company policy that employees are not to use their personal cell phones for anything other than use of an authenticator app. I have no ability comply with company recording of phone call policies or even reporting on call volume, call handling, and similar call stats when calls are being funneled through devices that do not facilitate that functionality. 3CX does. So if one is to get the value from their PBX, they need to actually use it.
And that can be SMS integration as well. We currently SMS with clients via Twilio numbers that plug into 3CX that connect to a call queue. The chat functionality works well. It facilitates business continuity.

Then there is the rest of the security issue.
If you get a "business" cell phone, it is generally going to appear as the name of the person who opened the account on ALL lines, all outgoing calls, and certainly this information will be published everywhere on every people finder website there is. So then you are into more expense. It is also an operational security risk.

The cell phone providers profit from the sale of name, telephone number, HOME address which they DEMAND for every line, and then they allow this information to be posted all over the internet on every people finder website there is. People I know have been SWATTED and stalked because this information has been publicly sold and is not kept private. So the cost is way past another $100/mo.
 
There are bigger issues at play. If you use a phone number that is demarked into an IMEI in a mobile device, that device and its contents are only accessible in one place to one person. That is the antithesis of business continuity unless it is one's intent to buy every employee that does a function a cell phone.
Yes. Many companies do provide company cell phones to each and every employee. For them it makes business sense.


I know IT service providers that were doing this kind of silliness when everyone worked in the same office. There was still zero accountability as to who was accessing that content and if they were using that number for SMS MFA validation or what they were enrolling. We require identity and access management systems for compliance, audit, accountability, and role-based access control, that is accessible from all authorized locations.

We have a company policy that employees are not to use their personal cell phones for anything other than use of an authenticator app. I have no ability comply with company recording of phone call policies or even reporting on call volume, call handling, and similar call stats when calls are being funneled through devices that do not facilitate that functionality. 3CX does. So if one is to get the value from their PBX, they need to actually use it.

Ok. So are we talking about you/your company, or your client? Because your original post was about setting up a hunter.io account for your client. So is it 'we require' and 'we have a company policy' or 'they require' and 'they have a company policy'. And they are already getting value from their PBX, so having one number that doesn't go through the PBX is not going to change that. But you said hunter.io wanted a SMS enabled number, and now you are talking about calls. You could simple forward the calls to a number on your PBX if that's really the concern here.

Then there is the rest of the security issue.
If you get a "business" cell phone, it is generally going to appear as the name of the person who opened the account on ALL lines, all outgoing calls, and certainly this information will be published everywhere on every people finder website there is. So then you are into more expense. It is also an operational security risk.

So you don't have a cell phone I take it?

Yes, you need to use real information to open an account. Yes companies everywhere store and sell information. We are all very much aware of this. Which is why you have all these new privacy regulations like GDPR, CCPA, etc. I don't see the 'more expense' though unless your client has previously paid money to have information scrubbed from the internet. And if they have, I'd be curious as to how much that costs. Asking for a friend.. :)

The cell phone providers profit from the sale of name, telephone number, HOME address which they DEMAND for every line, and then they allow this information to be posted all over the internet on every people finder website there is. People I know have been SWATTED and stalked because this information has been publicly sold and is not kept private. So the cost is way past another $100/mo.

You missed the cost of medical treatment from the cancer caused by 5G!

Seriously though, I'm sorry someone you know has been SWATTED and stalked. But that happened before cell phones as well. I'd bet nice lunch that if your client's marketing department wants hunter.io or some other service, and you tell them they risk getting swatted if they sign-up I'm they will say 'thank you for the advice, now go get us signed up'.

Bottom line is you asked if others have had this issue and the answer is yes. You yourself mentioned running into this with Microsoft and Google so clearly, it's a thing and everyone has run into it. Even Twilio won't do SMS for another VoIP number via their hosted SMS in many cases due to provider restrictions.

Good luck!
 
  • Like
Reactions: [email protected]
Our clients tend to have similar business policies and practices to what we do. There is overlap. So I am talking about both use cases.
Forwarding the phone number into 3CX will not work because if the phone number is required for SMS, then the SMS stops there. This is not about voice call. If it was, there would be no issue.

Abine has a service called DeleteMe that is quite good. I have used it for years. If you are interested to know how much publicly available information there is about you, there are $40/mo unlimited search sites that have no commitment. So it is possible to sign up, get a ton of information on everyone you wanted info on, and then cancel the subscription.

The more expense comes in not only paying for scrubbing services, but then paying for and working to remove data that should not have been leaked to begin with. GDPR and privacy regulations achieve nothing in real effect. Every piece of data that is posted comes with a cost. As a result, our general approach is to make sure that information is not being disclosed and shared in ways in which it can be abused because whether the information is with a big company or the government, they have proven to not be able to secure the data and prevent it from being abused.

So there is one solution. Don't use services that think that SMS to a cell phone is authentication.
I thought maybe things would be getting better with the standards that are being implemented for phone number ownership validation.
 
Status
Not open for further replies.

Forum statistics

Threads
111,992
Messages
590,171
Members
164,929
Latest member
Cloudstar