Blog
Stuck staring at a screen with no OTP in sight? Here are the 15 real, researched reasons SMS verification codes fail to arrive - from weak signal and SIM swaps to carrier filtering and the fraud defenses platforms now run - and what actually fixes each one.
September 13, 2026 · 8 min read
Nearly everyone who has signed up for anything online in the last few years has hit this moment: you enter your phone number, the screen says "code sent," and then... nothing. Thirty seconds pass. A minute. You hit resend. Still nothing, or the code finally lands nine minutes later, long after the platform stopped accepting it.
A missing OTP (one-time passcode) feels like a mystery, but it almost never is. SMS delivery for verification codes runs through a specific, well-understood pipeline - your phone and SIM, the number's registration and history, the carrier's spam and compliance filters, and the sending platform's own anti-fraud logic. A failure at any one of those four layers looks identical from where you're sitting: no text. Below is what's actually happening at each layer, grouped so you can rule things out fast, plus the two structural reasons this problem has gotten more common industry-wide, not less.
1. Weak or no signal. SMS still rides on the same signaling channel as calls. If you're in a basement, an elevator, or an area with poor carrier coverage, the message queues at the carrier and may arrive minutes late - well past most OTPs' 1-2 minute expiry window - or not at all if it times out first.
2. An inactive, newly-activated, or freshly-ported SIM. A SIM that's been dormant, just swapped into a new phone, or recently ported from one carrier to another isn't always immediately reachable. Number-portability databases (Local Number Portability, or LNP, in the US) can take anywhere from minutes to a day or two to fully propagate to every carrier's routing tables. During that window, some networks still route SMS to the old carrier, where it silently disappears.
3. Do Not Disturb, call/text blocking apps, or a full message store. Some carrier apps and third-party spam blockers filter texts from unrecognized short codes by default. Older phones or ones with very little free storage can also silently drop incoming SMS once local storage is full.
4. A typo in the number. The single most common cause, and the easiest to miss: one wrong or transposed digit, or a missing country code, sends the code to a real phone that simply isn't yours.
5. Airplane mode or a momentary service gap. Codes sent in the seconds after landing, exiting a tunnel, or reconnecting to a network are frequently the ones that get lost, since the carrier attempted delivery during the gap and didn't automatically retry once service returned.
6. The number is VoIP or a virtual/app-based line. This is the big one, and it's structural rather than accidental. Google Voice, Skype numbers, and many app-based "second number" services route SMS differently than a real carrier line, and a growing number of platforms - banks, exchanges, dating apps, most major social and messaging apps - actively detect and block verification sends to known VoIP ranges. It's not that the SMS fails to send; the platform never sends it in the first place, or sends it and it's silently dropped by a carrier-side filter designed to catch exactly this kind of traffic. See VoIP vs non-VoIP numbers for how that detection works.
7. The number has a spam or reuse history. Numbers that get recycled across many services and many prior owners can accumulate a reputation - carriers and platforms both maintain scoring on numbers that have been reported, flagged, or associated with abuse. A "clean" number with no verification history behaves completely differently from a heavily-reused one, even if both are technically real US mobile numbers.
8. The number was just ported and hasn't finished syncing. Related to point 2, but from the sending side: platforms and SMS aggregators cache which carrier owns which number range. Right after a port, that cache can be stale industry-wide for a day or more, so messages get routed to the wrong network and vanish.
This is where most of the invisible failures happen, and it's gotten stricter recently for a specific reason. In the US, business SMS sent from a standard 10-digit number is governed by a framework called A2P 10DLC (Application-to-Person messaging over 10-Digit Long Codes). Since early 2025, carriers have moved to blocking unregistered A2P traffic outright rather than just deprioritizing it - if the sender hasn't registered their messaging campaign with the carriers, the OTP can be blocked before it ever reaches your phone, with no error shown to either you or the platform that sent it.
9. The sender isn't properly registered under A2P 10DLC, or their registered "campaign" doesn't match what they're actually sending (e.g. a campaign registered for order-confirmation texts starts also sending marketing blasts). Carriers can throttle or fully suppress that sender's traffic, and legitimate OTPs get caught in the same net.
10. Aggressive, opaque spam filtering. Carrier filters scan message content, sender patterns, and even things like the presence of a link shortener, and these filters vary by carrier and change without notice. A perfectly legitimate OTP can occasionally trip a filter tuned for something else entirely.
11. Short-code vs. long-code routing differences. Some platforms send from five- or six-digit short codes, which have different delivery guarantees, throughput limits, and regional restrictions than standard 10-digit numbers. A short code that isn't properly provisioned for your carrier or region can fail silently.
Here's the part most people never see, and it's a major reason platforms have become noticeably more conservative about sending OTPs at all: SMS pumping fraud (also called toll fraud or Artificial Inflation of Traffic). Attackers use bots to trigger huge volumes of "send code" requests to premium-rate or attacker-controlled numbers - the platform pays for every message sent, and the attacker profits from the telecom payout on the other end. Industry estimates put this at 4.8% of global international SMS traffic in 2023 alone, worth an estimated $1.16 billion in fraudulent costs to businesses that year, and global SMS fraud losses are projected north of $70 billion in 2026. Twitter/X has publicly disclosed losing an estimated $60 million a year to exactly this kind of abuse before tightening its defenses.
The direct consequence for you: every platform sending OTPs now runs velocity and fraud checks on top of the message itself.
12. Rate limiting and velocity checks. Request a code too many times in a short window, from a number or IP with an unusual pattern, or right after a failed attempt, and many platforms will silently suppress the send rather than show an error - from your side it looks identical to a lost message.
13. Automatic invalidation of old codes. If you request a second code before using the first, most systems invalidate the earlier one immediately. Entering an old code you're still holding onto will always fail, and it's easy to mistake that for "the SMS never arrived" when actually a newer one is the only valid one.
14. Tight expiry windows colliding with any delay above. Most OTPs expire in 60-180 seconds specifically to limit the fraud window. Any single point of latency from layers 1-3 - a slow carrier route, a signal gap, a filtering delay - is often enough on its own to push delivery past the deadline, even when the message does eventually arrive.
15. SIM swap fraud. In the more serious case, the code isn't failing to arrive - it's arriving on someone else's SIM. Attackers who successfully social-engineer a carrier into porting your number to a device they control receive your OTPs instead of you. If codes stop arriving on a number that previously worked fine, with no porting or carrier changes on your end, treat it as a security event: contact your carrier immediately and check for unauthorized account activity.
A meaningful share of "missing OTP" complaints trace back to layer 2: the number itself is virtual, shared, or freshly reassigned, and no amount of retrying fixes that. That's exactly why services built specifically for verification - as opposed to a spare number in a messaging app - use real, non-VoIP mobile numbers issued by major US carriers, one number per customer per verification, never reused. There's no reputation baggage, no VoIP filter to trip, and no shared-pool history that a stricter platform might flag.
If you're hitting this wall on a specific service right now, see what SMS verification actually is and how it works, or go straight to a verification for the service you need with a fresh US number.
Further reading: What is A2P 10DLC? and Infobip's guide to SMS fraud detection cover the carrier-compliance and fraud-prevention side of this in more technical depth.
Ready to verify? Browse all services · More posts