AIT Protection
What is Artificially Inflated Traffic (AIT)?
Artificially Inflated Traffic (AIT) is a type of SMS fraud in which threat actors use bots and automated scripts to generate large volumes of fake or fraudulent SMS traffic, creating unexpected financial costs for your organization.
Vonage AIT Protection monitors your SMS traffic in real-time, automatically blocking or alerting on suspicious activity depending on the protection level you select.
Important: AIT Protection is included with Fraud Defender Advanced. Eligible customers can self-upgrade directly from the Fraud Defender Dashboard, or contact your Account Manager.
Protection Levels
AIT Protection allows you to define a Global Protection Level and optionally override it on a per-country basis. There are three levels:
| Level | Behavior | Fraud Alerts Generated? | Best For |
|---|---|---|---|
| None | No automatic blocking. Potentially fraudulent traffic passes through. | Yes, per-country | Monitoring only; manual review workflows |
| Standard | Automatically blocks high fraud-risk traffic. Lower-risk traffic is allowed through. | Yes, for unblocked traffic | Balanced protection; minimizing false positives |
| High | Blocks all potentially fraudulent traffic, including numbers in close range of high-risk numbers. | No, all blocked automatically | Maximum protection; higher tolerance for false positives |

Level Details
None
The None level does not block any potentially fraudulent traffic. A Fraud Alert is raised per country once fraudulent unblocked traffic is detected. Use this level when you want visibility into potential fraud without interrupting traffic flow. Once you have reviewed the alert, you can escalate to Standard or High, or add manual blocks via Traffic Rules.
To receive email notifications for these alerts, you must configure an Alert Action for 'AIT Protection'.
Standard
The 'Standard' AIT Protection level blocks only traffic flagged as high fraud risk, reducing the chance of false positives. Traffic with a non-high fraud risk score is allowed through, and a per country Fraud Alert is raised showing how much traffic would have been blocked under 'High' protection. This is the recommended starting point for most customers.
High
The 'High' AIT Protection level blocks all potentially fraudulent traffic, including numbers in close proximity to confirmed high-risk numbers. This provides the strongest protection but may result in false positives (i.e. legitimate traffic being blocked). Because all suspicious traffic is stopped automatically, no Fraud Alerts are generated at this level.
Rejected SMS messages from AIT Protection return error code 23.
Enabling AIT protection
Via the Dashboard
- Go to your Fraud Defender Dashboard.
- Locate the AIT Protection tile.
- Click 'Review' to open the AIT set up page.
- Select your preferred Global Protection Level (High, Standard, None).
- Add per country exceptions (if needed).
- Move the 'Enable' toggle to activate AIT Protection.
Via the API
You can configure AIT Protection programmatically using the Fraud Defender API. Country codes must follow the ISO 3166-1 alpha-2 format.
Endpoint:
PUT https://api.nexmo.com/v0.1/fraud-defender/configurations/protections/ait/sms
{
"data":{
"protection_enabled":true,
"default_protection_level":"standard",
"protection_level_per_country":[
{
"country":"AF",
"protection_level":"high"
},
{
"country":"AL",
"protection_level":"none"
}
]
}
}
The following table describes the fields in the request body:
| Field | Type | Description |
|---|---|---|
protection_enabled |
boolean | Enables or disables AIT Protection globally |
default_protection_level |
string | Global default: "high", "standard", or "none" |
protection_level_per_country |
array | Optional list of per-country overrides |
country |
string | ISO 3166-1 alpha-2 country code (e.g. "AF") |
protection_level |
string | Per-country level: "high", "standard", or "none" |
Setting Up Email Notifications
AIT Fraud Alerts are generated automatically when potentially fraudulent SMS messages are not blocked (i.e., under None or Standard protection levels). Each alert represents the number of unblocked SMS within a 15-minute window.
To receive email notifications when an alert is triggered:
- Subscribe to Fraud Notifications:
- If you are the account primary user, go to API Settings → Notifications tab and enable Fraud Notifications.
- If you are not the primary user, contact your account primary user to get subscribed.
- Set up an Alert Action:
- Navigate to the Alert Actions page.
- Verify that an Alert Action of type “AIT Protection” exists with the notification action set to “Notify”.
- If it does not exist, create one.
- Configure a threshold (recommended):
- Set a threshold value so that email notifications are only triggered when a certain number of SMS messages are unblocked within a 15-minute window. This reduces alert noise for low-risk events.
Analytics are aggregated per account and include data from all API Keys associated with your account.
Managing False Positives
The AIT fraud landscape is constantly evolving: new destination numbers become fraudulent every day, and numbers that were previously associated with fraud can return to legitimate use. Because AIT Protection evaluates traffic against a continuously updated intelligence database, there will be moments where a number's classification does not yet reflect its current state: a recently cleaned number may still carry a residual risk signal, or a legitimate number may fall within the range of an active fraud cluster. These transitions are an inherent characteristic of fraud detection, not a system error. If you or your customers experience unexpected error code 23 responses, there are two complementary tools to prevent further incorrect blocks.
Option 1: Trusted Numbers
Trusted Numbers is a feature that flags specific phone numbers as safe. Any number marked as trusted is exempt from AIT Protection blocks entirely: it will never be blocked regardless of its risk score or proximity to flagged numbers.
When to use it: You have a known, recurring set of users whose numbers should always be allowed through.
To add a trusted number:
- Go to the Fraud Defender Dashboard.
- Navigate to Trusted Numbers and add the phone number(s) you want to exempt.
Trusted Numbers is available on Fraud Defender Advanced and higher.
Option 2: Create an Allow Rule (Traffic Rules)
A Traffic allow rule explicitly permits traffic to a specific phone number or prefix, bypassing AIT Protection for that destination.
When to use it: A specific destination number has been wrongly blocked and you need an immediate fix.
- Go to the Fraud Defender Dashboard.
- Navigate to Traffic Rules → Create Rule.
- Set the rule type to Allow and enter the affected destination number or prefix.
- Save the rule. It takes effect immediately and overrides the AIT block for that number.
You can also manage allow rules via the API. See Traffic Rules for the full reference.
Allow rules are best suited for one-off or short-term fixes. For numbers that should permanently bypass AIT Protection, use Trusted Numbers instead.
Recommended Approach
- Use Trusted Numbers for your established, recurring users: customers who regularly interact with your service and whose numbers you have confidence in. This gives them permanent, frictionless protection from false positives.
- Leave new or unknown users untagged so that AIT Protection can evaluate their traffic normally. New users represent higher fraud risk and should go through the full protection flow until behavior is established.
- Use allow rules for targeted, temporary exceptions. For example, when a specific number is blocked during an incident and you need an immediate workaround while you investigate.
Error Reference
When AIT Protection blocks an SMS, the sending API returns error code 23 (Enforcer reject due to AIT intelligence DB). This is your primary signal that a destination number has been blocked.
| Error Code | Meaning | When it occurs |
|---|---|---|
| 23 | SMS rejected by AIT Protection | Returned synchronously on the API response whenever AIT Protection blocks a message |
Using Error Code 23 to Identify Blocked Destinations
Every blocked message returns error code 23, which means you can use your delivery receipt (DLR) callbacks or message logs to build a clear picture of which destination numbers are being blocked:
- DLR callbacks: Look for
status=failedwitherror-code=23in your webhook payload. Thetofield contains the destination number that was blocked. - Message Logs (Dashboard): In the Fraud Defender Dashboard, navigate to AIT Performance Analytics to see blocked traffic by country and volume. Use this alongside your own logs to drill down to specific numbers.
- API Logs: Filter your message delivery records for
error-code=23to extract a list of blocked destination numbers over any time period. This is useful for identifying patterns (e.g. sequential number ranges being targeted) or for raising false positive exceptions via Traffic Rules.
Monitoring AIT Savings & Performance
The AIT Performance Analytics dashboard gives you a clear view of how much your protection is saving. From the dashboard you can see:
- The total volume of traffic blocked by AIT Protection.
- The estimated cost savings generated from blocked fraudulent traffic.
- A map view showing the geographic destination of blocked traffic.
