Create form communications with the SMS method to send the registrant a text message when there’s a waitlist update, at a certain time before an event, or when the event is cancelled.
Before you begin
Before using SMS in Slate:
Complete the setup in Text Messaging (SMS) Overview.
Purchase Slate Credits.
Collect a valid mobile number.
Confirm that the recipient has agreed to receive text messages.
Public form submissions should not trigger SMS messages
🔔 Important!
Do not let the submission of a public form alone trigger the delivery of an SMS message. Doing so puts your institution at risk for SMS pumping fraud.
What is SMS pumping?
Public-facing forms that require little information and send a text immediately after submission are especially attractive targets for an SMS pumping fraud, during which bots can submit a form thousands of times in a short period.
The goal of this fraud is typically not to steal information from you or the submitter. Instead, fraudsters generate SMS traffic to phone numbers or networks from which they can receive a share of the revenue. Each form submission’s text message consumes Slate Credits when it triggers a message, leaving you responsible for the cost.
A typical SMS pumping scenario involves:
A public form or event is configured to send an Upon Registration SMS after submission.
A bot or an individual repeatedly submits the form using fake or fraudulent registrations.
The submissions include phone numbers controlled by the fraudsters. These numbers are often international phone numbers.
Each submission triggers an outbound SMS message
The institution pays for the messages through Slate Credits, even though the registrations are not legitimate.
The fraudsters benefit.
Impacts of SMS pumping fraud
Should your institution fall victim to an SMS pumping fraud, you may deal with:
Unexpected SMS Costs: The cost of an SMS pumping fraud can run into the tens of thousands of dollars.
Sender Reputation Damage: High volumes of suspicious, failed, or unwanted messages can damage sender reputation. Carriers may begin filtering or blocking messages from the sender, which can reduce deliverability for legitimate communications later.
Inaccurate Reporting: The data is now obfuscated by fake spam data which can impact accurate reporting for communications, events, and more.
Audit your forms for vulnerability with our example query
We’ve created an example query to identify any form or event that is:
Person-scoped
Doesn’t require a login
Contains an SMS
Upon ConfirmationorUpon Updatecommunication.
Copy this Suitcase ID and paste it in Database → Suitcase Import to import the query:
632914f4-0538-4400-9f03-cbf3b2c3664c:slate-examplesIf the query turns up any forms or events in your database, see the tips below for ways you can mitigate risk.
Reduce your risk
Form spam protections can reduce this risk but cannot eliminate it. Use an email form communication or send SMS to a controlled recipient list when possible.
If a public form must trigger SMS messages, use several safeguards:
Avoid immediate delivery: Do not use the public form submission as the only requirement for sending an SMS message.
Limit eligible phone numbers: If your intended recipients use numbers in the North American Numbering Plan, add a communication condition that requires the +1 country calling code.
Add a validation step: Require the submitter to enter the phone number twice and confirm that the entries match, or use a second form to confirm the number before triggering the SMS message.
Set registration limits: Configure realistic limits on forms and templates. In addition to matching operational capacity, a limit can reduce the number of fraudulent registrations that trigger communications.
Block repeated spam indicators: When fraudulent submissions reuse an identifiable email domain, use Translation Codes and submission conditions to block it. Review Avoiding Form Spam Submissions for other safeguards.
Monitor usage: Monitor Slate Credit usage and deactivate the communication when it is not needed.
Creating an SMS form communication
Go to Forms.
Select an existing form, or create a new one.
Select Edit Communications.
Select New Mailing.
Configure the following settings:
Name: Enter a clear internal name.
Trigger: Select when the message should be sent. See Form and Event Communications Triggers & Groups.
Group: Select the submission group that should receive the message. The group labels use email terminology, but the Method setting determines that Slate sends an SMS message.
Status: Select Inactive while configuring and reviewing the communication.
Method: Select SMS.
Hide from Timeline: Select this option only if the message should not appear on the recipient's timeline.
Select Save.
Select Edit Message, and configure the following settings:
Sender: Select a provisioned sender number.
Recipient: Enter the merge field that resolves to the recipient's mobile number, such as
{{sys-mobile}}.Message: Enter the message and add merge fields as needed. Include a recipient-specific merge field, such as
{{sys-first}}, and review the character and Slate Credit count shown in the editor.Optional Image: Add an image only when necessary. Images use additional Slate Credits and may increase filtering by mobile providers.
Select Save.
Review the pre-flight results and resolve any errors. Use Edit Conditions when the message should send only to registrants who meet additional criteria, such as a locally configured consent field.
Testing and activation
Test environments do not send communications. In production, keep the communication inactive while reviewing it, then use Send Test / Ad-Hoc with an authorized mobile number to review the message. Confirm the recipient, message segments, and Slate Credit usage before changing the communication to Active.