AIT Protection

What is Artificially Inflated Traffic (AIT)?

Artificially Inflated Traffic (AIT) is a type of SMS fraud in which threat actors use bots and automated scripts to generate large volumes of fake or fraudulent SMS traffic, creating unexpected financial costs for your organization.

Vonage AIT Protection monitors your SMS traffic in real-time, automatically blocking or alerting on suspicious activity depending on the protection level you select.

Important: AIT Protection is included with Fraud Defender Advanced. Eligible customers can self-upgrade directly from the Fraud Defender Dashboard, or contact your Account Manager.

Protection Levels

AIT Protection allows you to define a Global Protection Level and optionally override it on a per-country basis. There are three levels:

Level Behavior Fraud Alerts Generated? Best For
None No automatic blocking. Potentially fraudulent traffic passes through. Yes, per-country Monitoring only; manual review workflows
Standard Automatically blocks high fraud-risk traffic. Lower-risk traffic is allowed through. Yes, for unblocked traffic Balanced protection; minimizing false positives
High Blocks all potentially fraudulent traffic, including numbers in close range of high-risk numbers. No, all blocked automatically Maximum protection; higher tolerance for false positives
AIT Protection Overview.png

Level Details

None

The None level does not block any potentially fraudulent traffic. A Fraud Alert is raised per country once fraudulent unblocked traffic is detected. Use this level when you want visibility into potential fraud without interrupting traffic flow. Once you have reviewed the alert, you can escalate to Standard or High, or add manual blocks via Traffic Rules.

To receive email notifications for these alerts, you must configure an Alert Action for 'AIT Protection'.

Standard

The 'Standard' AIT Protection level blocks only traffic flagged as high fraud risk, reducing the chance of false positives. Traffic with a non-high fraud risk score is allowed through, and a per country Fraud Alert is raised showing how much traffic would have been blocked under 'High' protection. This is the recommended starting point for most customers.

High

The 'High' AIT Protection level blocks all potentially fraudulent traffic, including numbers in close proximity to confirmed high-risk numbers. This provides the strongest protection but may result in false positives (i.e. legitimate traffic being blocked). Because all suspicious traffic is stopped automatically, no Fraud Alerts are generated at this level.

Rejected SMS messages from AIT Protection return error code 23.

Enabling AIT protection

Via the Dashboard

  1. Go to your Fraud Defender Dashboard.
  2. Locate the AIT Protection tile.
  3. Click 'Review' to open the AIT set up page.
  4. Select your preferred Global Protection Level (High, Standard, None).
  5. Add per country exceptions (if needed).
  6. Move the 'Enable' toggle to activate AIT Protection.

Via the API

You can configure AIT Protection programmatically using the Fraud Defender API. Country codes must follow the ISO 3166-1 alpha-2 format.

Endpoint:

PUT https://api.nexmo.com/v0.1/fraud-defender/configurations/protections/ait/sms

{
   "data":{
      "protection_enabled":true,
      "default_protection_level":"standard",
      "protection_level_per_country":[
         {
            "country":"AF",
            "protection_level":"high"
         },
         {
            "country":"AL",
            "protection_level":"none"
         }
      ]
   }
}

The following table describes the fields in the request body:

Field Type Description
protection_enabled boolean Enables or disables AIT Protection globally
default_protection_level string Global default: "high", "standard", or "none"
protection_level_per_country array Optional list of per-country overrides
country string ISO 3166-1 alpha-2 country code (e.g. "AF")
protection_level string Per-country level: "high", "standard", or "none"

Setting Up Email Notifications

AIT Fraud Alerts are generated automatically when potentially fraudulent SMS messages are not blocked (i.e., under None or Standard protection levels). Each alert represents the number of unblocked SMS within a 15-minute window.

To receive email notifications when an alert is triggered:

  1. Subscribe to Fraud Notifications:
    • If you are the account primary user, go to API Settings → Notifications tab and enable Fraud Notifications.
    • If you are not the primary user, contact your account primary user to get subscribed.
  2. Set up an Alert Action:
    • Navigate to the Alert Actions page.
    • Verify that an Alert Action of type “AIT Protection” exists with the notification action set to “Notify”.
    • If it does not exist, create one.
  3. Configure a threshold (recommended):
    • Set a threshold value so that email notifications are only triggered when a certain number of SMS messages are unblocked within a 15-minute window. This reduces alert noise for low-risk events.

Analytics are aggregated per account and include data from all API Keys associated with your account.

Managing False Positives

The AIT fraud landscape is constantly evolving: new destination numbers become fraudulent every day, and numbers that were previously associated with fraud can return to legitimate use. Because AIT Protection evaluates traffic against a continuously updated intelligence database, there will be moments where a number's classification does not yet reflect its current state: a recently cleaned number may still carry a residual risk signal, or a legitimate number may fall within the range of an active fraud cluster. These transitions are an inherent characteristic of fraud detection, not a system error. If you or your customers experience unexpected error code 23 responses, there are two complementary tools to prevent further incorrect blocks.

Option 1: Trusted Numbers

Trusted Numbers is a feature that flags specific phone numbers as safe. Any number marked as trusted is exempt from AIT Protection blocks entirely: it will never be blocked regardless of its risk score or proximity to flagged numbers.

When to use it: You have a known, recurring set of users whose numbers should always be allowed through.

To add a trusted number:

  1. Go to the Fraud Defender Dashboard.
  2. Navigate to Trusted Numbers and add the phone number(s) you want to exempt.

Trusted Numbers is available on Fraud Defender Advanced and higher.

Option 2: Create an Allow Rule (Traffic Rules)

A Traffic allow rule explicitly permits traffic to a specific phone number or prefix, bypassing AIT Protection for that destination.

When to use it: A specific destination number has been wrongly blocked and you need an immediate fix.

  1. Go to the Fraud Defender Dashboard.
  2. Navigate to Traffic Rules → Create Rule.
  3. Set the rule type to Allow and enter the affected destination number or prefix.
  4. Save the rule. It takes effect immediately and overrides the AIT block for that number.

You can also manage allow rules via the API. See Traffic Rules for the full reference.

Allow rules are best suited for one-off or short-term fixes. For numbers that should permanently bypass AIT Protection, use Trusted Numbers instead.

  • Use Trusted Numbers for your established, recurring users: customers who regularly interact with your service and whose numbers you have confidence in. This gives them permanent, frictionless protection from false positives.
  • Leave new or unknown users untagged so that AIT Protection can evaluate their traffic normally. New users represent higher fraud risk and should go through the full protection flow until behavior is established.
  • Use allow rules for targeted, temporary exceptions. For example, when a specific number is blocked during an incident and you need an immediate workaround while you investigate.

Error Reference

When AIT Protection blocks an SMS, the sending API returns error code 23 (Enforcer reject due to AIT intelligence DB). This is your primary signal that a destination number has been blocked.

Error Code Meaning When it occurs
23 SMS rejected by AIT Protection Returned synchronously on the API response whenever AIT Protection blocks a message

Using Error Code 23 to Identify Blocked Destinations

Every blocked message returns error code 23, which means you can use your delivery receipt (DLR) callbacks or message logs to build a clear picture of which destination numbers are being blocked:

  • DLR callbacks: Look for status=failed with error-code=23 in your webhook payload. The to field contains the destination number that was blocked.
  • Message Logs (Dashboard): In the Fraud Defender Dashboard, navigate to AIT Performance Analytics to see blocked traffic by country and volume. Use this alongside your own logs to drill down to specific numbers.
  • API Logs: Filter your message delivery records for error-code=23 to extract a list of blocked destination numbers over any time period. This is useful for identifying patterns (e.g. sequential number ranges being targeted) or for raising false positive exceptions via Traffic Rules.

Monitoring AIT Savings & Performance

The AIT Performance Analytics dashboard gives you a clear view of how much your protection is saving. From the dashboard you can see:

  • The total volume of traffic blocked by AIT Protection.
  • The estimated cost savings generated from blocked fraudulent traffic.
  • A map view showing the geographic destination of blocked traffic.
AIT Performance analytics