Newsletter

India’s spam call crisis and why even the most sophisticated anti-spam system can’t stop your phone from ringing.


In September 2024, LocalCircles, a Delhi-based community platform that runs large public-opinion surveys, polled over 71,000 people across 371 districts and found that 95% of Indian mobile users get an unwanted call every single day, and 77% get three or more. A follow-up survey pushed the daily number to 97%.

It's a strange number to process given that India runs what TRAI (Telecom Regulatory Authority of India) itself describes as a world's first blockchain based system built specifically to stop this. It's been live since 2019. And clearly, it hasn't worked.

To understand why, you have to follow your own phone number, because it doesn't leak from just one place.

You give it at the Zara counter to 'link it to the bill'. You give it to the chemist for the medical record. You punch it into the Zomato order, the society gate register, the free airport Wi-Fi, the 'fill this form to get the brochure' desk at a property launch.

Each of these is a separate collection point, and from each one, your number can travel into a database that gets shared, sold, or scraped, often without you ever reading the fine print that allowed it.

From here, a single phone number travels into one of the two pipelines.

The first is the legitimate one.

Under TRAI's Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018, any company that wants to message or call you at scale has to register as a Principal Entity, or PE, on a Distributed Ledger Technology (DLT) platform, essentially a blockchain-based ledger maintained by the telecom operators.

The PE registers its sender ID, called a header, and every single message template it plans to send, word for word, with only specific variable fields like OTPs or amounts left open.

Before any message reaches you, it gets scrubbed against the exact registered template. If the content doesn't match, it's blocked outright, even for something as routine as an OTP.

TRAI tightened it further from January 2026, requiring every variable field to be pre-tagged by type so a company can't quietly stuff a promotional line into what's registered as a service template.

Brands register as Principal Entities on the DLT system, often using aggregators, essentially bulk-messaging middlemen like Gupshup, Kaleyra, Karix, or Route Mobile to handle their messaging.

Underneath all of this sits the actual blockchain infrastructure. Tanla Platforms, a Hyderabad based listed company, built a communication stack called Trubloq that alone processes an estimated 60 to 70% of India's commercial SMS traffic for Vodafone Idea and BSNL, while Airtel runs its own DLT layer with IBM and Jio runs one with Tech Mahindra. This is, by most measures, one of the most serious anti-spam infrastructure builds anywhere in the world.

Infographic: How India's DLT Anti-Spam System Works

So why does it fail so visibly? Because the second pipeline runs entirely outside it.

Data brokers and lead-sellers – some operating as registered "verified lead" businesses and some not – buy and resell contact information gathered from property portals, insurance inquiry forms, and job sites, often flipping the same lead to five or six competing agents.

The DLT system governs how a message gets sent once a sender already has your number and a 'claimed' reason to contact you. It was never built to ask how that sender got your number in the first place.

TRAI's own numbers show where the real damage sits. In mid-2026, the regulator said publicly that over 80% of unsolicited marketing calls originate from ordinary 10-digit mobile numbers, not from the registered 140 series at all. The honest system is mostly working. The dishonest one is where the volume comes from.

India now has two dedicated number ranges so you can tell who's calling before you pick up.

Infographic: 140 Series (Promotional) vs 1600 Series (Service/Transactional)

A bank is legally required to hold both and can't cross the streams. If a 1600 number tries to sell you something, that's a violation you can report and the number traces straight back to a specific regulated entity.

As of August 2026, TRAI has started extending this framework with a 1601 series now being rolled out for service calls from utilities and courier companies, keeping them separate from the financial and government calls on 1600.

But, even this cleaner system has a soft spot.

For years, consent was largely recorded and maintained by the sender and TRAI never verified it.

A company just has to assert that you consented, once, somewhere, to receive category-relevant messages. That's a low bar. It's why a real estate developer you've never spoken to can plausibly claim implied consent because you inquired about a property once through a portal that resold your details.

The system only checks that the message matches an approved template. It was never designed to check whether you personally agreed to receive it.

TRAI knows this is the weak link. In December 2025, it launched a joint pilot with the RBI that lets consumers review and revoke consents recorded against their number by eleven major banks. It's a start.

This gap is also why the Do Not Disturb registry, formally the National Customer Preference Register (NCPR), doesn't help as much as you'd expect either.

You can register through the TRAI DND app, by calling or SMSing the number 1909, or through your telecom operator, and choose to block entire categories like banking, real estate, or education.

But DND only binds registered senders. It does nothing against the unregistered numbers responsible for most of the volume, and, in a counterintuitive twist, it can't touch 1600 calls either, because TRAI's rule is that 1600 series calls cannot be tagged, blocked, or filtered by anyone – consumer or app – since the entire point of the series is that it's meant to be presumptively trustworthy.

That rule is at the centre of a live regulatory fight.

Truecaller, the caller-ID app most Indians use to screen unknown numbers, has been flagging both 140 and 1600 calls as "frequently blocked" in its app, on the grounds that its own users are reporting large volumes of spam from both ranges, reportedly around 5.25 lakh calls a day.

TRAI has pushed back hard, calling this misleading and seeking authority from the Ministry of Electronics and Information Technology to act against apps that tag or block calls from the two designated series. It's an unresolved tension between a regulator protecting the credibility of its own trusted-number system and a spam-filtering app reporting what its users are actually experiencing on the ground.

While Truecaller pushes TRAI for the right to flag regulated numbers as spam, its own "Verified Business" green badge, a paid feature that marks a caller the way a blue checkmark marks a social media account, has become a 'verified' visibility tool for companies that want their promotional calls answered.

The real progress, though, is happening at the network level.

In September 2024, Airtel launched India's first network-based, AI-powered spam detection tool, built in-house, that scans every call and SMS against roughly 250 behavioural parameters in about two milliseconds and tags suspicious ones as "Suspected SPAM," automatically, for every customer, with no app to download. Vi followed with a similar in-network tool called Vi Protect, and Jio has rolled out its own version too.

Since the launch, these tools have become a common point of confusion, as they only alert and don't block the call.

By April 2025, Airtel said it had flagged over 27.5 billion calls as spam and cut spam call volume by 16% since launch, though it also noticed a 12% rise in overseas-routed spam calls in the same period, suggesting spammers are adapting rather than disappearing.

TRAI has separately approved Calling Name Presentation (CNAP), a network-level feature that shows a caller's telco-verified registered name rather than a crowdsourced guess, which is being rolled out across all major operators through early 2026.

In practice, CNAP has added confusion before it's added clarity. The user now sees Truecaller's crowdsourced name AND the telco-verified CNAP name; they often don't match (especially when SIMs have changed hands), and the result is two conflicting labels instead of one clear identity.

Enforcement has picked up too. Following a TRAI order in August 2024, telecom operators disconnected around 2.75 lakh numbers and blocked 50 entities, and consumer complaints reportedly fell 20% within two months. Through 2025, TRAI issued over 7.3 lakh notices to unregistered telemarketers and disconnected more than 1.84 lakh telecom resources, taking the cumulative total since August 2024 past 21 lakh disconnections.

India isn't alone in this. The UK and the US have both run do-not-call registries for over two decades, and both still drown in spam. The telecom side catches the senders who register. The volume comes from the ones who don't. That's true everywhere.

India built genuinely serious infrastructure to police its phone lines, and it's making a visible dent. It just hasn't caught up with how easily a number given at one counter ends up in a database three industries away, passed around with consent that isn't being verified.

You must be thinking — is this it? Do we just live with it? Is the government taking further steps to tackle it? Can you, individually, do something today to make your phone ring less? More on all of that, next issue.

Until then...


If this changed how you think about the calls and messages flooding your phone, share it on WhatsApp or LinkedIn.

This story was shaped by feedback from Kushal Kothari, whose experience navigating India's spam-call ecosystem as a Truecaller subscriber and DND-registered user sharpened several sections of this piece.