Stop paying for
SMS fraud you never sent.
One HTTP call before you hand a message to Twilio, Vonage or MessageBird — Verifence answers allow/deny in single-digit milliseconds.
- A deny costs you $0. The message never reaches your provider, so it's never billed.
- Sub-10ms decisions. Fast enough to sit inside your signup flow without users noticing.
- Catches what your provider can't. Account rotation, farms and pumping — the attack the send path is blind to.
No card required. Four protection layers on the free plan.
Each returns its verdict on the first run · 2 runs per scenario per hour
↳ a deny is a message never handed to your provider · never billed
Live decisions from the production engine. History is seeded — catching account rotation takes history your SMS provider never sees, which is the whole point. Nothing you type is stored.
The send is the attack
SMS pumping drives verification codes to numbers an attacker profits from. There's nothing to steal and no account to break into — every request looks like an ordinary signup. Most teams discover it the way it was discovered here: as a line item, weeks later.
What does not having it cost?
Every pumped message is one you pay your SMS provider for and never should have sent. Move the sliders to your traffic.
Premium-rate international ranges — the ones fraud farms target — commonly bill $0.10–$0.50 each.
Illustrative estimate. A deny happens before the send, so blocked traffic costs you nothing at your SMS provider. Actual pumping rates spike far higher during an active attack.
Four layers, cheapest first
First rejection wins. Each layer catches what the ones before it structurally cannot.
Destination shape
Malformed numbers, impossible lengths, and premium-rate ranges that bill you per message. Free, no state.
Velocity
Rolling windows keyed on account, number, address and network at once — so rotating any single key never trips.
Network reputation
The one an attacker can't fake: did anyone ever type the code in? Real users complete. Farms never do.
Plan quota
Per-account monthly limits you control, metered in real time with a clear signal when it's time to scale.
Drop-in SDKs
Official, open-source clients — one call before you send. All MIT-licensed and on github.com/verifence.
Building with an AI assistant? Point it at /llms-full.txt — a full, machine-readable integration guide it can follow in one shot.
Free · no account
Are you already paying for SMS pumping?
Legitimate one-time-passcode traffic converts at 70–95%. Pumped traffic converts at near zero. Eight questions, about two minutes, and you get an estimate of what the gap is costing you — plus the method, so you can check it against your own logs.
Run the Exposure CheckSimple, volume-based pricing
Every plan runs all four layers. Pay for the volume you check, not the fraud you block.
Starter
$19/mo
$16/mo
$190 billed yearly
5,000 checks/mo
- 5,000 checks / month
- All four protection layers
- 3 API keys
- Up to 3 team members
- Configurable caps + IP allowlist
Pro
$79/mo
$66/mo
$790 billed yearly
25,000 checks/mo
- 25,000 checks / month
- All four protection layers
- Unlimited API keys
- Up to 10 team members
Business
from $1,500/mo
Talk to us
Custom volume
- Custom volume
- Shadow-mode audit + policy tuned per country
- Custom rules and reason-code export
- SLA & priority support
- SSO & audit log
- Dedicated onboarding
Frequently asked questions
- What is SMS pumping (AIT)?
- SMS pumping — also called artificially inflated traffic (AIT) — is fraud where attackers trigger large volumes of one-time-passcode texts to premium phone-number ranges they profit from. You pay your SMS provider for every send while the attacker collects a revenue share from the destination carrier.
- How does Verifence stop SMS pumping?
- Your backend makes one HTTP call to /v1/check immediately before sending each verification SMS. Verifence scores the request across four layers — destination shape, velocity, network reputation, and plan quota — and returns allow or deny in single-digit milliseconds. A deny is a message you never send and never pay for.
- Does Verifence store phone numbers?
- No. Phone numbers are hashed before they are ever used as keys, and Verifence never logs phone numbers, client IP addresses, or API keys.
- How fast is a check?
- Single-digit milliseconds. The velocity layer runs as a single Redis Lua evaluation because it sits directly in your signup path, where latency matters.
- What happens if Verifence is unavailable?
- It fails open. If the cache is unreachable, requests are allowed (flagged as degraded) rather than blocking your signups — your availability never depends on Verifence being up.
- How much does Verifence cost?
- Plans are volume-based: a free tier, Starter at $19/month, Pro at $79/month, and Business from $1,500/month for multi-provider senders who need policy tuned per country, an SLA, and reason-code export. You pay for the checks you make, not the fraud you block.
Put a firewall in front of your SMS spend.
250 checks a month, free. Add a key and make your first call in minutes.
Get started free