Summary

  • ARIN closed Suggestion 2022.29 on 24 August 2026, saying limited supported mobile numbers outside its service region had become a costly attack vector and that it would not enable new non-region codes for SMS authentication.
  • The current control is a maintained destination list, not a clean geographic border: some locations in the ARIN region are unsupported, while Trinidad & Tobago is listed as a supported exception outside it.
  • ARIN has not published the attack method, volume, destinations or cost. A proportionate next step is a privacy-safe decision receipt for list changes and alternative-method outcomes, not public attack telemetry or telephone data.

The exception became the policy question

In November 2022, Andy Beverly asked ARIN to let administrators use mobile numbers outside the ARIN service region for SMS two-factor authentication. The request was about access convenience. ARIN's answer in August 2026 was about cost and attack exposure.

The change in vocabulary matters. ARIN's closing note says that experience with the limited out-of-region numbers it already supported revealed a “costly attack vector”. Because of that real cost and the availability of other authentication options, ARIN said it had no plans to enable any new non-region mobile codes for SMS.

That is a product decision with a security basis. It is not a public incident report. ARIN does not identify the attack technique, the affected destinations, the number of attempts, the messaging provider or the bill. It does not report a compromised account or altered number-resource record. Giving the unknown mechanism a familiar fraud label would add certainty that the source does not contain.

The narrower fact is still consequential. Before an SMS code can help authenticate anybody, ARIN Online decides whether it will accept the destination and attempt delivery. A country-code list has therefore become an admission-control surface. It controls an exposure to message delivery and abuse, while also determining which users may choose the most familiar of ARIN's methods.

Region and delivery are three different maps

The current SMS MFA guide shows why “inside” and “outside” are too crude. It lists countries and geographical areas rather than applying one invisible regional switch.

Public list state Examples in ARIN's current guide What it establishes
In-region and supported Canada, United States, Puerto Rico, many Caribbean locations ARIN currently permits an SMS setup attempt for a listed code
In-region and unsupported Saint Barthelemy, U.S. Minor Outlying Islands, several remote outlying areas Service-region membership does not guarantee SMS availability
Outside the region and supported Trinidad & Tobago The live list retains at least one non-region exception

The list is not proof that a permitted message will arrive. ARIN's MFA FAQ says that a user's service provider may fail to deliver the messages even in a location shown as supported. Admission, carrier delivery and authentication success are three different transitions.

Geography is not an identity factor either. A country code can be a practical input to pricing, routing and abuse controls. It does not prove where the user is, who controls the telephone or whether the account action is authorised. The password, delivered one-time code and the rest of the account-authority model do the authentication work. The list decides whether the SMS path is offered.

This distinction also prevents the decision from being misread as a claim that every out-of-region message is dangerous. ARIN describes experience with limited supported numbers and says it will not add new codes. It does not publish a universal security ranking of countries, carriers or users.

The evidence changed between 2023 and 2026

ARIN's January 2023 consultation said 13% of web-user accounts listed phone numbers outside its service region. That figure described account records at the time. It did not say that 13% of users needed SMS, could not use another method or were trying to sign in from outside the region.

The consultation result two months later recorded mixed feedback. ARIN said several out-of-region customers had asked about SMS, and staff had redirected them to time-based one-time-password applications. It knew of no instance in which a customer could not complete 2FA because SMS was unavailable. Its stated trigger for revisiting the decision was hearing from customers who could not use the alternatives.

That was a reasonable statement of the evidence ARIN said it had in March 2023. It cannot be carried forward as proof about every user in 2026. Nor does the August 2026 attack-cost statement reveal whether the earlier user-access trigger was remeasured. The public record has moved from “alternatives appeared sufficient” to “the exception imposed a real cost”, without publishing a joined account of access outcomes and abuse exposure.

The alternative set has improved. ARIN made 2FA mandatory in February 2023 and documented authenticator applications, SMS and security keys. Its May 2026 release expanded MFA to industry-standard passkeys, and the current passkey guide names hardware and software options. SMS and passkey users receive 16 single-use recovery codes. Those are meaningful alternatives; their existence is not a measurement of successful setup, continued access or recovery.

Publish the decision receipt, not the attack playbook

ARIN need not disclose telephone numbers, carrier-sensitive signatures, live blocking thresholds, invoices or account identifiers to make the boundary reviewable. The useful public object is smaller: a versioned receipt whenever the supported-code list materially changes.

Such a receipt could state the effective date; whether a code was added, removed or temporarily suspended; a broad reason category such as unavailable delivery, sustained abuse cost, vendor constraint or reviewed product choice; and the next review trigger. Where safe and available, aggregate bands could show rejected setup attempts, redirection to another method, completion of an alternative setup and support demand. A correction route should exist for a destination classified incorrectly or newly supportable.

The receipt should also keep permission and performance separate. “Supported” means ARIN accepts the setup path. It does not promise carrier delivery. “Not supported” means the SMS option is unavailable; it does not mean the person is outside ARIN's community or unfit to control an account. TOTP, passkey and recovery remain separate paths with their own custody requirements.

This would preserve ARIN's ability to respond to abuse without turning security operations into public instructions for an attacker. It would also give users and customer organisations enough notice to understand when convenience, cost and continuity have been rebalanced.

Sources