Guide

Transactional SMS & OTP Best Practices

8 min read

Everything you need to send reliable OTP and transactional SMS — message templates, expiry rules, fraud prevention, and BTRC-compliant sending.

Transactional SMSOTPSecurityCompliance

Short answer: Transactional SMS is automated, event-driven messaging sent because a user took an action — login, payment, order, or signup. OTP SMS is the most common type. It must arrive fast, read clearly, and follow security rules so codes cannot be intercepted or abused.

What Is Transactional SMS?

Transactional SMS differs from marketing SMS in both intent and regulation. Users request or trigger transactional messages; they do not opt in to a promotional list.

Transactional SMS examples

  • OTP / verification codes
  • Login alerts
  • Order & delivery updates
  • Payment confirmations
  • Password reset links
  • Appointment reminders

Not transactional

  • Promotional offers & sales
  • Newsletter blasts
  • Cold outreach campaigns
  • Unsolicited product ads

In Bangladesh, transactional SMS typically uses non-masking routes for OTP (lower cost, fast delivery) or masking routes when brand recognition matters (e.g. bank alerts showing your company name as sender).

How OTP SMS Works

One-time passwords prove that a user controls a phone number. The flow is always server-controlled:

  1. User submits phone number on your app or website.
  2. Your server generates a random numeric code (typically 6 digits).
  3. Server stores the code with expiry (Redis, database, or session).
  4. Server calls the SMS API — the mobile app never sees the API key.
  5. User receives SMS and enters the code.
  6. Server compares submitted code with stored value; on match, issue session/token.

Delivery time matters: OTP SMS should reach the handset within seconds. Choose an SMS provider with direct operator routes in Bangladesh and monitor delivery reports for failed OTP attempts.

OTP Best Practices

Security

  • Generate server-side — use random_int(100000, 999999) or cryptographically secure equivalents. Never let the client suggest the OTP.
  • Never log OTP values — log message_id and phone hash, not the code itself.
  • Expire quickly — 5 minutes is standard; delete from storage after use.
  • Limit attempts — lock after 3–5 wrong guesses; require cooldown or CAPTCHA.
  • Rate-limit sends — cap OTP requests per phone and per IP per hour.
  • Keep API keys server-side — mobile apps, SPAs, and public repos must not contain SMS credentials.

Deliverability

  • Use a dedicated OTP sender ID approved for your account.
  • Keep messages under 150 characters when possible to stay in one segment (remember non-masking adds a [SenderID] prefix).
  • Avoid URL shorteners and spam trigger words in OTP messages.
  • Store message_id from the API response and check delivery status in SMS logs.

User experience

  • State your brand name in the first few words so users recognize the sender.
  • Include expiry time ("Valid for 5 minutes").
  • Add "Do not share this code" — reduces social engineering losses.
  • Offer resend with visible cooldown timer (e.g. 60 seconds between resends).

OTP Message Templates

These templates work well for Bangladesh OTP flows. Replace placeholders with your brand and code.

YourBrand: Your verification code is {code}. Valid for 5 minutes. Do not share this code.

{code} is your YourBrand login OTP. Expires in 5 min. If you didn't request this, ignore this message.

Bengali and emoji characters still count as one character each under SMS Provider's 150-character segment rule — but longer scripts fill segments faster, so English OTP text is usually cheaper.

Compliance in Bangladesh

SMS traffic in Bangladesh is regulated by BTRC. Transactional and OTP routes must use approved sender IDs and approved use cases. Standard routes cover login OTP, order updates, and payment alerts.

  • Request sender IDs through your SMS Provider dashboard before going live.
  • Do not send gambling, betting, or restricted content on standard OTP routes without prior approval.
  • Honor user opt-out for any marketing overlap — keep transactional and marketing lists separate.

Need a non-standard use case? Contact support on WhatsApp before integrating — we can review BTRC requirements for your specific flow.

Frequently asked questions

What is transactional SMS?

Transactional SMS is automated, user-triggered messaging — OTP codes, order confirmations, payment alerts, and account notifications. It is not promotional bulk marketing. Recipients expect these messages because they initiated an action.

How long should an OTP be valid?

Industry standard is 5–10 minutes. Shorter expiry (3–5 min) reduces brute-force risk. Always invalidate the OTP after successful verification or after max failed attempts.

Should I include the OTP in the SMS sender name?

No. The OTP belongs in the message body. Use a recognizable sender ID (masking) or numeric sender (non-masking) so users trust the message. Never put secrets in the sender field.

How many OTP SMS can I send per user?

Limit to 3–5 OTP requests per phone number per hour. Apply IP-based rate limits on your send-otp endpoint. This prevents SMS pumping attacks and protects your balance.

What is the best OTP message format?

Include: brand name, the code, expiry time, and a 'do not share' warning. Example: 'YourBrand: Your verification code is 482910. Valid for 5 minutes. Do not share this code.'

Is OTP SMS different from marketing SMS in Bangladesh?

Yes. OTP and transactional messages require non-masking or approved masking routes and must follow BTRC guidelines. Marketing SMS has stricter sender ID rules and should only go to opted-in recipients.

Ready to integrate? Read the full API documentation, create a free account, or contact us on WhatsApp.