What is a Grey Route? A Field Guide from Live CDR Analysis

Grey routes are the quiet tax on every A2P message you send. They rarely make headlines, they never appear on an invoice by name, and they quietly convert application-to-person revenue into person-to-person pennies. This is the field guide: what a grey route is, why it exists, what it looks like in real CDR data, and what actually stops it.

What is a grey route?

A grey route is a delivery path that carries application-to-person (A2P) messaging traffic over channels that were priced and provisioned for person-to-person (P2P) use. The message still arrives, usually within seconds, so the sender often never knows. What changed is the economics: A2P termination is typically billed at commercial rates, while P2P traffic rides on interconnect agreements and subscription bundles that were never designed to carry marketing, OTP and notification traffic at machine scale.

The “grey” is deliberate. A white route is a licensed, declared A2P path through an aggregator or direct operator connection. A black route is outright illegal interception. Grey sits between: the traffic is legal in origin, but the delivery path misrepresents what it is.

Why grey routes exist: the price gap

Every grey route is an arbitrage of a price gap. When an aggregator charges a brand 0.03 EUR per message for A2P delivery into a country, and P2P termination into that same country settles at a fraction of a cent, the spread is an invitation. Someone will take it: SIM farms dressed up as local subscriber traffic, SMS gateways re-labelling traffic as P2P, or wholesale routes that quietly downgrade message class hop by hop.

The brand paying full price is the victim twice over. It pays A2P rates for P2P-grade delivery, and it inherits the reliability of an improvised path: no sender verification, no spam shielding, no delivery analytics worth the name.

What a grey route looks like in CDR data

You do not find grey routes by asking. You find them by reading traffic. The signatures we track corridor by corridor in our A2P SMS Bypass Observatory:

  • P2P channels moving A2P volume. A sender ID pattern that belongs to a bank, a platform or an OTP service, riding on routes declared as subscriber-to-subscriber traffic.
  • Throughput anomalies. Human beings do not send 200 messages per minute from one number, pause, and rotate to the next.
  • Sender ID inconsistency. The same alphanumeric sender arriving through different corridors with different masking behaviour.
  • Delivery patterns that defy geography. Traffic destined for one country terminating through detours that make no commercial sense, unless the point of the detour is the price.
  • Ratio drift. The P2P/A2P ratio of a corridor creeping up month over month. Grey routes grow, because arbitrage scales.

What grey routes actually cost

The industry-level numbers are loud. The CFCA estimates global telecom fraud losses in the tens of billions of dollars a year, with messaging bypass among the largest categories. But the number that matters is yours: your A2P volume, times the fraction that quietly downgrades to P2P economics, times twelve months. For a mid-size aggregator or an enterprise sending OTPs at national scale, that product is a seven-figure line item hiding inside a rounding error.

What protection actually looks like

Blocking is the reflex and it is not enough. Grey routes are adaptive; when one path closes, the traffic finds the next price gap. What works is layered and boring:

  • Traffic analytics per corridor, with baselines that know what normal looks like, so drift becomes visible in days instead of quarters.
  • Sender ID and fingerprint consistency checks across the delivery chain, not only at the edge.
  • Test traffic into your own campaigns, so you learn what path your messages really took.
  • Commercial consequences, because analytics without escalation is a museum. Partners whose routes downgrade traffic get caught, evidenced and repriced.
  • Quarterly recalibration, because grey routes are a moving target and last quarter’s thresholds are already aging.

The honest part

Machine flagging alone will produce a meaningful share of false positives; on bypass-flagged traffic, on the order of a third without expert review. That is not a reason to skip the machines. It is the reason the machines propose and engineers confirm. Detection is a discipline, not a product you install once.

If you want to know what your corridors look like under that lens, that is literally what we do: read the observatory or talk to the team.

Leave a Reply

Your email address will not be published. Required fields are marked *