Is it safe to use a virtual number?
Virtual numbers are safe for most sign-ups, with real limits. What's safe, what isn't, when a service blocks one, and how to use one without getting burned.
Pre-launch — you can read everything, but ordering isn't open yet. Where we are
A verification code passes through at least four owners, and only one of them will admit when something goes wrong. Hence a category full of confident percentages and empty inboxes. Here is the chain, the five places it breaks, and how to read a success claim — including ours.
You press “send code”. Between that click and your screen the message crosses four hands, each with its own rules and its own reasons to drop it.
You see hop one, because it tells you when it refuses, and hop four, because that's your inbox. Hops two and three are invisible to you, to the service, and often to each other. That asymmetry is where nearly every complaint in this category starts.
SMS has a status mechanism — the delivery receipt — and it is weaker than it sounds. A receipt says the message was accepted by the next hop. It does not say a person saw it, and a carrier can accept a message, report it accepted, then discard it.
So when a service says it sent your code, it usually believes that — it has a receipt, and no view of the last hop.
A number-type lookup returns “VoIP” or “virtual”, or the range sits on a blocklist built after past abuse, and the service declines before generating anything. You see it at once: “enter a valid mobile number”. The only failure here that tells you the truth on the spot.
Markets increasingly require senders of application-to-person SMS to register the brand and campaign behind their traffic; the US regime is the best known, not the only one. Unregistered or over-limit traffic is throttled or dropped by policy — as is hammering resend.
A verification code looks exactly like the spam carriers filter all day: short, automated, high volume from one sender, carrying a code or a link. Filters are heuristic, unpublished and adjusted without notice, and a filtered message is dropped silently. This is the most common way a code vanishes with no error anywhere.
Phone numbers are finite and get recycled. If somebody verified the same service on yours before you, you get “already registered” instead of a code. Shared free public numbers are the extreme case — through every popular platform many times over, which is what makes them fine for a throwaway signup and useless otherwise.
A SIM goes offline, a range moves between providers mid-rental, a gateway backs up. Rare individually, real collectively, and — from where you sit, staring at an inbox — indistinguishable from filtering. You can't diagnose it from outside, and neither can whoever sold you the number.
Line the chain up and the conclusion is arithmetic, not opinion. A provider owns hop four and buys a partial view of hop three. Hops one and two belong to the service you are joining and to an aggregator neither of you chose. Any promise about arrival is a promise about three parties the promiser cannot observe. The shorter list it can stand behind: price, whether a number is buyable now, what happens when no code comes, and what it measured on that route.
You'll see success percentages all over this category. Most aren't fiction; they're unqualified, which has the same effect — a figure that can't be wrong because it never said anything falsifiable. Three questions sort evidence from decoration.
Then a free fourth test: come back next month. Real measurements move — samples grow, routes drift, good weeks follow bad. A figure identical months later was never a measurement; it was a constant somebody typed once. Check what a site does when it has no data, too: a confident figure on every one of hundreds of routes claims sample everywhere, and traffic does not distribute like that.
We publish route state in three labelled forms. Measured: counted from our own completed orders on that route, with sample size and window inline. Supplier-reported: a named supplier's figure, marked as theirs. Or the third state, written out rather than shown as a dash or a zero:
We don't have data for this route yet
That's what most of our routes say today, popular ones included — Germany, Poland, Portugal. A new site with a confident percentage everywhere would be a site inventing them; better conspicuously empty than quietly wrong. The labelling rules are on the trust page, and every price and route state is readable without an account on pricing.
There's no universal answer, and we won't publish a figure we haven't measured on your route. Use the service's own resend timer as the benchmark — it encodes what that service expects from its sender. Filtering is not cured by waiting.
Sometimes, once: a resend can take a different path through the aggregator layer and land where the first didn't. Repeated resends work against you — rate limits discard attempts, and some services lock the number temporarily.
Because failure is per route, not per number. Different services use different senders, hold different views of which ranges are virtual, and carry different filtering histories with the same carrier. A number invisible to one platform is ordinary to another.
The route-level view of the same problem — what a route is, how supply pools go stale, how to read a route page — is in how SMS verification routes fail. For a country example, the US number guide covers +1 ranges and why the range matters more than the country code.
Every route shows its price and its data state up front — and where we have nothing yet, it says so.
Every route below is one click away. Open a country to see its services, or jump straight to a service hub.