Phishing Simulation

SMS Templates

Overview

SMS templates let you run SMS-based security-awareness simulations. The message and its tracked link work the same way regardless of which SMS connection your administrator configured in Channels — the connection is chosen for you at send time based on the campaign's default, a pinned connection, or the recipient's numbering region.

There are two kinds of SMS connection, and they change how you author the template:

  • Free-text connections. You write the message freely. Used for most international routes.
  • Approved-template connections. The message must match a template you registered with the operator in advance, sent from a registered sender header. Some countries require this by law (see Regional compliance).

If you are unsure which kind you have, ask the PhishGrid administrator who set up your SMS connection — each connection is marked Free text or Approved templates.


Writing an SMS template

  1. Open Template Studio and create an SMS template.
  2. Sender ID. The name or number shown as the sender. On approved-template connections this must be the registered sender header.
  3. Message. Write the body. Insert recipient fields as variables, e.g. {{learner.first_name}}, and the tracked link as {{click_link}}. PhishGrid turns {{click_link}} into a short tracked URL per recipient (see Link shortening below).
  4. Send a test to your own number, then use the template in a campaign.

Link shortening. In the template's Links section choose:

  • Shorten — Channel default, Nothing (links are sent as written), Tracked links only (just {{click_link}} and the other tracking placeholders), or All links in the message (literal URLs too).
  • Short-link domain — a verified serving domain. When you pick one it is used for every link in the template, whatever serving domain the campaign uses. Leave it as Same as serving domain to follow the campaign.

Shortened links look like https://<short-link domain>/s/?<code>; each code maps to the recipient's tracked link, so clicks are still recorded. For approved-template routes (e.g. India DLT), pick the domain your template was registered with so the delivered text matches.

Keep messages short — SMS is billed and split into 160-character segments (70 for non-Latin scripts). Template Studio shows a live character and segment count.


Regional compliance

SMS is regulated differently by country. PhishGrid supports these rules through the connection and template settings; the specifics come from the operator you (or your administrator) registered with.

Common requirements:

  • Registered sender header — a pre-approved sender name or ID, rather than an arbitrary one.
  • Registered message template — the exact wording approved in advance, with per-recipient parts expressed as variables.
  • Sender/link registration — some regulators require the sending identity and link domains to be registered before delivery.

Where a connection is approved-template, PhishGrid records the registered template ID on the SMS template (Template Studio → Channel settings → Template ID) and only sends when it is present.

The Template ID field is generic — enter whatever ID your provider issued for the approved template:

  • a registered template ID such as India's DLT template ID — PhishGrid sends the message text, and it must match the approved template exactly;
  • a provider-hosted template ID (some providers call these flows) — the approved text lives with the provider, and PhishGrid sends only the ID plus the values for its variables.

India (DLT)

India's TRAI framework requires SMS to go through the DLT (Distributed Ledger Technology) registration system. In short:

  • Your organisation, sender header and message template are registered on an operator's DLT portal in advance, and the template is issued a DLT template ID.
  • Registered templates express every per-recipient part (including links) as a variable, and there are limits on the number and length of variables.
  • Link domains used in messages must be registered/allow-listed on the DLT portal.

For a simulation, register the template through your normal DLT process, then in PhishGrid set the Sender ID to your registered header and enter the DLT template ID in the template's Template ID field. The message body must match the approved template exactly, with variables in place of the registered {#var#} slots. Optionally turn on Strict DLT matching so a message that no longer matches its registration is rejected rather than sent.

This is an operational summary, not legal advice. Follow your operator's DLT documentation and your organisation's compliance process for the authoritative steps.


What happens at send time

Result When
Sends Free-text connection, or an approved-template connection whose template has a registered template ID.
Held Registration is still pending and the campaign opted to hold rather than fail.
Blocked The connection requires approved templates but the template has none. Nothing is sent.

If approved-template messages are accepted but not received, the registration usually needs attention: the message text no longer matches the approved template, the sender/template IDs don't belong to the same registration, or a link domain isn't registered. Check these with whoever manages your SMS registration.


Tips

  • Dry-run first. Point a test campaign at the Simulator connection to preview the flow and the report without sending anything externally.
  • Plan ahead where registration applies. Approved-template registration (e.g. DLT) can take days.
  • Test with a small group before a full launch to confirm delivery on your route.