An OTP is often the first SMS a customer gets from you, and it guards their account and money. A good OTP message is short, clear and hard to misuse.
The ideal OTP message
“482915 is your BRAND verification code. It expires in 5 minutes. Never share it — BRAND staff will never ask for it.”
- Code first so it shows in the notification preview.
- Brand name so the customer knows who sent it.
- Expiry so they act quickly.
- A warning not to share it.
- No links — links in OTP messages look like phishing.
Code design
- Six digits is a good balance of security and ease of typing.
- Generate codes with a secure random generator, never sequentially.
- Store only a hash of the code, with its expiry time.
- Expire codes after 5–10 minutes and after one successful use.
Protect against abuse
- Limit attempts: lock verification after 3–5 wrong codes.
- Limit sends: cap OTP requests per number and per IP, with a cooldown before “resend”.
- Watch for pumping: sudden OTP requests to unusual or international numbers can be fraud aimed at running up your SMS bill.
- Tell the customer what the code is for when it matters: “to confirm a payment of KES 5,000”.
Delivery
- Use a registered sender ID in the transactional category — see transactional vs promotional SMS.
- Keep the message in GSM-7 so it’s one SMS.
- Use delivery reports to spot failures, and offer a voice-call fallback for customers who don’t receive the SMS.
Learn more on our SMS OTP page and in the Node.js tutorial.
Get started
Create a Connect Media account — SMS from KES 1.0, no minimum top-up, credit that never expires, and one account for Safaricom, Airtel and Telkom. Call +254 707 339 945 or email info@connectmedia.co.ke.