Security
The security model behind public numbers, how to use them safely, how to report problems, and responsible disclosure.
The public-number security model
The most important security fact about SMSX is also the simplest: every number in the directory is public. Any message sent to a listed number can be read by anyone who opens that number's page, including you and complete strangers. There is no private inbox, no ownership, and no expectation of confidentiality. Understanding this is the foundation of using the service safely.
Where the boundary is
- Public by design. Incoming SMS on a listed number is shown publicly. Treat everything sent to one as if it were posted openly on the internet, because effectively it is.
- Codes are credentials. A one-time verification code grants access. Because codes on public numbers are visible to everyone, they provide no security for any account you care about.
- We minimise site data. Details of what we collect when you browse the site itself, and how it is handled, are described in our Privacy Policy.
How to use public numbers safely
- Never use a public number for a real account. Do not use it for banking, email, primary social accounts, or anything you cannot afford to lose. Use it only for throwaway tests, research, and learning.
- Never share a code with someone who contacts you. Legitimate services do not ask you to read a code back to "support". That is a hallmark of account-takeover scams.
- Do not send private data. Never transmit financial details, government identifiers, or personal messages to a public number.
- Assume messages are not verified. Content arrives from third parties and may be spoofed, misleading, or malicious. See our Disclaimer.
Reporting a security or privacy problem
If you discover a message that exposes someone's personal information, report it immediately through Report an Issue or request takedown via Content Removal Requests. For abusive, harmful, or unlawful content, the Safety & Reporting Center explains how serious cases are escalated.
Responsible disclosure
If you believe you have found a technical vulnerability in the site itself — as opposed to the expected public nature of the numbers — please contact us privately through Contact & Support before disclosing it publicly. Describe the issue and the steps to reproduce it, and give us a reasonable opportunity to investigate and respond. Please do not access, alter, or destroy data that is not yours while testing.
Honest limitations
We take practical measures to keep the site itself sound, but we make no claim of formal certification and we cannot secure content that is public by design. The safety of your accounts always depends on using private, controlled numbers for anything that matters — not the shared numbers listed here.