
SMS is a carrier-routed short-text service. Its encoding, delivery status, consent requirements, and security limits matter as much as the message bubble.
SMS stands for Short Message Service. It is the carrier-based service used to send and receive short text messages between compatible phone numbers and devices. An SMS may appear in the same app as iMessage, RCS, or MMS, but the underlying service, features, security, and billing can differ.

What happens when you send an SMS

- Your phone or application submits the text and destination address to a mobile network or messaging provider.
- The message is encoded and may be split into segments.
- A message center or gateway determines where to route it.
- The destination network attempts delivery to the recipient’s device.
- The sending system may receive a delivery status, depending on network and service support.
This store-and-forward design means SMS does not require both people to maintain a live session. A temporary delivery failure may be retried, but routing, roaming, filtering, number validity, device status, and carrier policy can still prevent delivery.
Why an SMS is often 160 characters
A single GSM-7 SMS segment can contain up to 160 characters. The transport carries 140 bytes, and GSM-7 uses seven bits for characters in its set. Longer messages are usually divided and reassembled. A concatenated GSM-7 message commonly has 153 usable characters per segment because part of each segment stores reassembly instructions.
Characters outside GSM-7—including many non-Latin scripts, emoji, and some smart punctuation—can trigger UCS-2 encoding. Twilio’s current documentation gives a 70-character limit for a single UCS-2 segment and 67 per concatenated segment. One curly quote can therefore change a message’s segment count and cost.
| Encoding | Single segment | Concatenated segment |
|---|---|---|
| GSM-7 | Up to 160 characters | Usually 153 characters |
| UCS-2 | Up to 70 characters | Usually 67 characters |
These are segment limits, not a promise that every carrier, country, phone, or provider behaves identically. Check the provider’s segment calculator and destination rules before a bulk send.
SMS vs MMS vs RCS

- SMS carries short text over carrier messaging infrastructure.
- MMS is designed for multimedia such as images, video, or other attachments.
- RCS supports richer chat features such as higher-quality media, typing indicators, and other capabilities when compatible services are available.
- Internet messaging apps use their own accounts, protocols, and data connections rather than automatically being SMS.
A phone may fall back from a richer service to SMS or MMS. Before relying on a feature—media size, group behavior, read receipts, encryption, or sender identity—confirm which transport was actually used.
Common personal and business uses
People use SMS for ordinary conversations, appointment reminders, delivery updates, emergency notices, two-factor codes, customer support, and marketing. Software can send or receive SMS through an API and gateway that bridges a web application with telecommunications networks.
For operational messages, include the sender identity and the action the recipient needs. Do not treat a carrier delivery status as proof that a human read or understood the text. Also provide another route for users who cannot receive or safely use SMS.
Consent is part of business SMS
Sending a message to a customer is not authorized merely because the business has a phone number. Requirements depend on the country, message type, sender, recipient relationship, and applicable law and carrier rules. In the United States, CTIA’s messaging principles say non-consumer senders should obtain consent before messaging and honor opt-out requests.
Keep the consent record, state what messages the person agreed to receive, identify the sender, disclose expected frequency and charges where applicable, make opt-out instructions clear, and process revocation promptly. Marketing consent should not be hidden inside an unrelated transaction. Obtain legal review for the actual campaign and destination markets.
SMS security limits
A text can be spoofed, forwarded, shown on a lock screen, accessed after a SIM swap or number reassignment, or used for “smishing” links. Do not send passwords, full payment details, medical records, or other sensitive content as ordinary SMS. A legitimate organization should not ask a recipient to disclose a one-time code back to an unsolicited sender.
NIST’s current digital-identity guidance requires risk-aware controls around telephone-network authentication and recognizes risks such as device or SIM changes and number porting. For higher-risk accounts, prefer phishing-resistant authentication options when available instead of treating an SMS code as the strongest possible proof.
Evaluate an SMS platform
| Question | Why it matters |
|---|---|
| Which countries, carriers, and sender types are supported? | Availability and registration rules vary |
| How are encoding and segments shown before send? | Unexpected Unicode can change cost and delivery |
| How are consent and opt-outs stored? | Compliance needs auditable state, not a note in a spreadsheet |
| What do delivery statuses actually mean? | Accepted, sent, delivered, and read are different events |
| What filtering, rate limits, fraud controls, and logs exist? | Protects recipients, the account, and sender reputation |
| What fallback channel exists? | SMS is not guaranteed or universally accessible |
In short, SMS is a widely reachable short-text transport with strict encoding, consent, delivery, and security boundaries—not a guaranteed private chat channel.