SMS, OTP and WhatsApp Messaging in Dubai (2026): Real AED Costs, TDRA Sender ID Rules and the 31 March 2026 OTP Deadline
The UAE has 22.18 million mobile subscriptions and the Central Bank kills SMS OTP for banking on 31 March 2026. Real AED per-message costs, TDRA sender ID rules and what to build instead.
- PUBLISHED
- 24 SEPT 2026
- READ TIME
- 11 MIN
- AUTHOR
- AQUARIUS · DUBAI
- UNIT
- REV 2026.09
Short answer: Sending A2P SMS to a UAE number costs roughly AED 0.08–0.12 per message direct from e& or du, or AED 0.05–0.10 through an aggregator at volume, plus a registered sender ID with both carriers. WhatsApp is a different economy: AED 0.15–0.20 per utility message, AED 0.30–0.40 per authentication message and AED 1.20–1.45 per marketing message in the UAE. And the channel most Dubai products were built on is being switched off — CBUAE Notice 2025/3057 requires licensed financial institutions to stop using SMS and email OTPs for digital banking authentication by 31 March 2026.
Here is what most Dubai businesses get wrong. They treat messaging as a line item on a vendor invoice — a per-SMS rate to negotiate down. It is not. It is a regulated channel with a registration process at two separate carriers, a legally enforced sending window, a consent record you must be able to produce, and now a national regulator actively deprecating the dominant use case. The per-message price is the cheapest part of the decision.
The stakes: the most saturated mobile market on earth, and a shrinking channel
Start with the reach, because it explains why every Dubai product ships an SMS field.
- The UAE has more than 22.18 million mobile subscriptions against a population of roughly ten million — about 203 subscriptions per 100 residents, second in the world by that measure.
- 5G covers 97.03% of the populated area, and mobile network coverage is effectively 100%.
- Which is exactly why the channel became a fraud surface. OTP fraud cost UAE victims around USD 87 million in a single reported year, SIM-swap attacks grew 38% in 2025, and the average loss per UAE consumer hit by payment fraud reached USD 884 — up 270% on earlier surveys.
- Abu Dhabi Police alone handled 15,642 cybercrime cases and recovered AED 140 million from online fraud across two years. The average cost of a cyber incident to a UAE business is put at USD 2.9 million.
Those two facts — near-total mobile penetration and an SMS channel that keeps leaking money — are why the Central Bank moved. Under CBUAE Notice 2025/3057, banks, finance companies, exchange houses, insurers and payment service providers must retire SMS and email OTP for digital banking by 31 March 2026, replacing it with biometrics, FIDO2 passkeys and in-app push confirmation. The transition window opened on 25 July 2025, and Emirates NBD began pushing customers onto app-based approval from November 2025.
The part that changes behaviour is not the deadline. It is the liability shift: if a customer’s OTP is intercepted through SIM swap or phishing and money moves, the institution reimburses the loss. SMS OTP stopped being a cost centre and became a balance-sheet exposure.
If you are not a licensed financial institution, the notice does not bind you. It still tells you where the market is going. Every Dubai fintech, marketplace, clinic portal and delivery app currently spending on SMS OTP is spending on a mechanism the national regulator has formally classified as inadequate.
The TDRA rules nobody reads until the messages stop arriving
A2P messaging in the UAE is governed by the Telecommunications and Digital Government Regulatory Authority under its A2P regulatory policy, enforced through the two carriers. The rules are specific.
1. Your sender ID is registered twice, not once
Every organisation sending A2P SMS to UAE numbers must register its sender ID with e& (Etisalat) and du separately — approval from one carrier does not carry to the other. The ID is a maximum of 11 alphanumeric characters, must plainly represent your brand (generic IDs get rejected), and numeric long codes are not permitted for commercial A2P traffic. Expect to supply a trade licence or certificate of incorporation, passport copy of the authorised signatory, a letter of authorisation, sample messages for every use case, and every URL you intend to send so it can be whitelisted.
Timelines reported for 2026: 5–10 business days for UAE-registered companies, 20–25 business days for international entities, and around 2–4 weeks for full dual-carrier approval in practice. Build that into the launch plan, not the week before go-live.
2. Promotional messages carry the AD- prefix
Promotional sender IDs must be prefixed AD- — mandatory since 3 November 2020. Transactional and service categories do not carry it. Mislabel a marketing blast as transactional to dodge the prefix and you are not being clever; you are giving the carrier a reason to suspend the ID.
3. There is a legal clock on marketing
Promotional SMS may only be delivered between 07:00 and 21:00 Gulf Standard Time. Messages submitted outside that window are queued to the next permitted period. Transactional messages — OTPs, delivery alerts, appointment reminders, account notices — run 24/7.
4. International senders cannot send UAE promotions at all
TDRA rules prohibit international senders from delivering promotional SMS to UAE recipients. Only transactional traffic is permitted from offshore routes. If your growth stack runs from a European or US account, your marketing messages are not underperforming — they are non-compliant.
5. Consent is a record you have to produce
Consent for promotional messaging cannot be inferred from an existing customer relationship. It must be explicit, timestamped, attributed to a source, and retained. That is also a Federal Decree-Law No. 45 of 2021 (UAE PDPL) obligation, not merely a telecom one — see our PDPL compliance checklist for websites and apps. Opt-out must honour the STOP keyword and its Arabic equivalent إلغاء, processed within 24 hours, with no re-enrolment absent fresh consent.
Penalties reported for unsolicited commercial messaging run to AED 400,000–500,000 per violation depending on the instrument applied, and PDPL exposure on the data-protection side is materially larger. The everyday consequence is quieter and more expensive: unregistered sender IDs get blocked or overwritten by the carrier, so your OTPs simply never arrive and your support queue absorbs the cost.
What it actually costs in AED
Per-message rates as quoted into the UAE in 2026, before your own volume negotiation.
| Channel / route | AED per message | Notes |
|---|---|---|
| e& Business Direct SMS | 0.08–0.12 | Direct carrier, best deliverability, contract and minimums |
| du Business Direct SMS | 0.08–0.12 | Separate contract and separate sender ID approval |
| Regional aggregator SMS | 0.05–0.10 | Cheapest at volume; check the route is direct-to-carrier |
| Global CPaaS (Twilio class) | ~0.15 | USD-billed, add 2–3% forex margin |
| Global CPaaS (Vonage class) | ~0.18 | USD-billed, add 2–3% forex margin |
| WhatsApp — utility | 0.15–0.20 | Order, delivery, booking updates |
| WhatsApp — authentication | 0.30–0.40 | Costs more than SMS OTP, not less |
| WhatsApp — marketing | 1.20–1.45 | 10–18x an SMS; justified only by conversion |
| WhatsApp — service reply | Free | Within the 24-hour customer-initiated window |
| In-app push / passkey | ~0.00 | No per-authentication carrier fee at all |
Then the fixed costs. Sender ID registration is quoted at roughly USD 90 one-time plus USD 45 per month for UAE-registered entities and USD 225 plus USD 115 per month for international ones — about AED 330 + AED 165/month and AED 825 + AED 425/month respectively. Enterprise BSPs bundle it higher, commonly AED 1,500–3,000 one-time and AED 500–1,500 per month per ID. Enterprise platform fees add AED 1,500–4,000 a month, agent inbox seats AED 90–280 per agent per month, and Arabic template approval AED 50–200 per template at some providers.
Volume discounts are real and worth structuring for: roughly 5–10% above 50,000 messages a month, 10–15% above 100,000, 15–20% above 500,000, and 20–30% above one million. Multiply before you pick a vendor. At 100,000 OTPs a month, the gap between AED 0.05 and AED 0.15 is AED 120,000 a year — more than the build that would remove the messages entirely.
WhatsApp deserves one correction, because Dubai teams routinely get it backwards. Since Meta moved to per-message pricing on 1 July 2025, WhatsApp authentication is around three to four times the cost of an SMS OTP, and BSP markup adds another USD 0.003–0.010 on top. WhatsApp wins on utility and conversational commerce, not on cheap OTP delivery. The full channel economics are in our WhatsApp Business API cost guide for Dubai.
The 31 March 2026 deadline, and what replaces the OTP
For licensed institutions this is now an execution problem. CBUAE accepts fingerprint and facial recognition, FIDO2-compliant passkeys and app-based push confirmation. Each removes the interceptable shared secret that makes SIM swap profitable.
For everyone else, three practical moves carry most of the benefit:
- Passkeys for account login. Device-bound, phishing-resistant, and free per authentication. The marginal cost of your millionth login is zero.
- In-app push approval for high-value actions. Payment confirmation, payout changes, beneficiary additions — anything worth a fraudster’s effort belongs in the app, not the SMS inbox.
- UAE PASS for identity-grade verification. Where you genuinely need to know who the person is rather than that they hold a handset, the national digital identity does it properly. See our UAE PASS integration guide.
Keep SMS. Just demote it: fallback for users who cannot or will not install the app, plus the transactional notifications where a one-way message is the correct medium. Your volume drops, your per-message negotiation gets easier, and your worst fraud vector gets much narrower.
What a build costs, and the number that pays for it
Our 2026 AED bands for the work involved.
| Scope | AED range | What you get | Timeline |
|---|---|---|---|
| SMS/OTP gateway integration + compliance layer | 18,000–40,000 | Dual-carrier sender ID paperwork, templated transactional sends, rate limiting, delivery-receipt logging, retry and fallback | 2–4 weeks |
| Multi-channel messaging service | 45,000–110,000 | SMS + WhatsApp + email with per-channel routing, bilingual templates, PDPL consent ledger, STOP handling, cost dashboard | 4–8 weeks |
| Passkey / FIDO2 + in-app push authentication | 70,000–180,000 | WebAuthn registration and recovery flows, device binding, push approval service, step-up rules, audit trail | 6–12 weeks |
| Full customer messaging platform | 150,000–350,000 | Segmentation, campaign scheduling inside the legal window, A/B testing, attribution, consent audit export, Arabic-first templates | 3–6 months |
Budget 15–20% of build cost per year for hosting, support and maintenance — the same run-rate we apply to every custom software build in Dubai.
Now the conversion case. A Dubai platform sending 200,000 authentication messages a month at a mid-market AED 0.10 spends AED 240,000 a year on the privilege of using the weakest available factor. Move 70% of that traffic to passkeys and in-app push and roughly AED 168,000 a year of pure operating cost disappears — against a passkey build in the AED 70,000–180,000 band. Payback lands inside the first year on message fees alone, before counting a single avoided fraud reimbursement in a market where the average payment-fraud loss per consumer is USD 884 and SIM-swap attacks grew 38% in a year.
The cost of inaction is easier to state. For a regulated institution, missing 31 March 2026 means a supervisory finding plus full liability for every OTP-linked fraud. For everyone else it means paying a per-message tax, forever, on a security control the national regulator has already ruled insufficient.
How Aquarius builds these
We build messaging channel-agnostic and consent-first. One internal send API, one templating layer, and routing decided per message by cost and urgency — so switching an aggregator or adding WhatsApp is a configuration change, never a rewrite. Consent, source, timestamp and opt-out state live on the customer record as first-class fields, because that is the artefact a regulator asks for. Templates are authored in Arabic and English together, with the 07:00–21:00 promotional window and the AD- prefix enforced in code rather than left to whoever schedules the campaign. Delivery receipts and cost-per-message are logged and dashboarded, so the spend is visible before the invoice. Where authentication is in scope we ship WebAuthn passkeys with real recovery flows, since a passkey rollout without an account-recovery path just converts a fraud problem into a support problem. Everything runs on your own cloud tenancy with full source handover, and our build bands are published up front.
Frequently asked questions
How much does bulk SMS cost in the UAE in 2026?
Direct from e& or du Business Direct, roughly AED 0.08–0.12 per message. Regional aggregators quote AED 0.05–0.10 at volume, while global CPaaS providers run around AED 0.15–0.18 with a 2–3% forex margin on USD billing. Volume discounts of 5–10% start above 50,000 messages a month and reach 20–30% above one million. Add sender ID registration and monthly maintenance on top, charged per ID per carrier.
Do I need to register a sender ID with both Etisalat and du?
Yes. Registration is per carrier and approval from one does not cover the other. The sender ID is a maximum of 11 alphanumeric characters, must represent your brand, and numeric long codes are not permitted for commercial A2P traffic. Expect 5–10 business days for a UAE-registered entity and 20–25 business days for an international one, with around 2–4 weeks typical for full dual-carrier approval.
What is the AD- prefix and when do I need it?
Promotional sender IDs in the UAE must carry the AD- prefix before the brand name, mandatory since 3 November 2020. Transactional and service messages — OTPs, delivery alerts, appointment reminders — do not use it. Promotional messages may only be delivered between 07:00 and 21:00 Gulf Standard Time; transactional traffic sends 24/7.
Is WhatsApp cheaper than SMS for OTPs in the UAE?
No. Since Meta moved to per-message pricing on 1 July 2025, a WhatsApp authentication message in the UAE costs roughly AED 0.30–0.40 against AED 0.08–0.12 for an SMS, plus BSP markup. WhatsApp is strong on utility messages at AED 0.15–0.20 and on conversational service replies, which are free inside the 24-hour customer-initiated window. It is not the cheap OTP channel.
Does the CBUAE OTP phase-out apply to my non-financial app?
Not directly. CBUAE Notice 2025/3057 binds licensed financial institutions — banks, finance companies, exchange houses, insurers and payment service providers — which must retire SMS and email OTP for digital banking authentication by 31 March 2026. Any UAE business handling payments or sensitive customer data should read it as the direction of travel, because the fraud techniques it responds to are not bank-specific.
What replaces SMS OTP?
Biometric verification, FIDO2-compliant passkeys and in-app push confirmation are the methods CBUAE names. Passkeys are device-bound and phishing-resistant with no per-authentication cost; in-app push suits high-value action confirmation; UAE PASS covers cases needing identity-grade verification rather than device possession. Keep SMS as a fallback for users without the app.
The bottom line
The UAE carries 22.18 million mobile subscriptions across roughly ten million people, which made SMS the default channel for a decade — and made it the most profitable thing in the country to attack. The Central Bank has set 31 March 2026 as the date SMS OTP stops being acceptable for digital banking, and shifted fraud liability onto the institution. Meanwhile the per-message economics reward anyone who bothers to model them: the same 100,000 monthly messages cost AED 60,000 or AED 180,000 a year depending purely on route and contract. Both problems have the same fix — own the messaging layer instead of renting it one SMS at a time. Talk to Aquarius and we will map your volumes, channels and authentication flows to an architecture and a fixed AED band in one session.
