{"id":697,"date":"2026-07-24T04:22:00","date_gmt":"2026-07-24T04:22:00","guid":{"rendered":"https:\/\/text.email\/blog\/?p=697"},"modified":"2026-07-24T07:07:14","modified_gmt":"2026-07-24T07:07:14","slug":"authorized-from-addresses","status":"publish","type":"post","link":"https:\/\/text.email\/blog\/authorized-from-addresses\/","title":{"rendered":"Authorized Senders: Lock Down Who Can Send to Your text.email Address"},"content":{"rendered":"\n<p>It&#8217;s pretty tough for someone to send unauthorized email to SMS messages to you through your text.email address.<\/p>\n\n\n\n<p>We have our <strong>private subdomain system<\/strong> which makes it tricky (if not virtually impossible) for someone to guess your text.email address. (Five-second refresher: Your text.email address is <code>your-number@your-subdomain.text.email<\/code>. You pick that subdomain to keep your address secure and secret.) <\/p>\n\n\n\n<p>But&#8230; <strong>over time, your address winds up in various system configs, tickets, logs, and more<\/strong>. Which means it&#8217;s gonna be out there in the universe, at least a little.<\/p>\n\n\n\n<p>So <strong>if you want some extra protection<\/strong> in case your subdomain gets out (whether it&#8217;s to a bad actor or beyond), text.email now offers an optional <strong>Authorized Senders<\/strong> feature.<\/p>\n\n\n\n<p>(Yes, optional. If you never set this up, nothing about your account will change.)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Authorized Senders: Table of Contents<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"#set-up\">How to Set Up Authorized Senders in text.email<\/a>\n<ul class=\"wp-block-list\">\n<li><a href=\"#figure-out-systems\">Step 1: Figure out every system that&#8217;s emailing you<\/a><\/li>\n\n\n\n<li><a href=\"#set-up-senders\">Step 2: Set up your senders in the text.email settings<\/a><\/li>\n\n\n\n<li><a href=\"#test-this-out\">Step 3 (recommended): Test this out<\/a><\/li>\n\n\n\n<li><a href=\"#remove\">How to remove all restrictions<\/a><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><a href=\"#unauthorized\">What Happens When an Unauthorized Sender Tries to Send You a Message?<\/a><\/li>\n\n\n\n<li><a href=\"#get-going\">Ready to Get Going with Authorized Senders?<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"set-up\">How to Set Up Authorized Senders in text.email<\/h2>\n\n\n\n<p>Here&#8217;s how to set up your authorized senders.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"figure-out-systems\">Step 1: Figure out every system that&#8217;s emailing you<\/h3>\n\n\n\n<p>Take a quick inventory of all the systems that are sending you SMS alerts. These could include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Monitoring and uptime services<\/li>\n\n\n\n<li>Controller software<\/li>\n\n\n\n<li>Access control and security panels<\/li>\n\n\n\n<li>Servers and network equipment<\/li>\n\n\n\n<li>Database Mail out of SQL Server<\/li>\n\n\n\n<li>Website contact forms<\/li>\n\n\n\n<li>Cameras, smart-home devices, voicemail systems<\/li>\n\n\n\n<li>SaaS tools that send operational notices<\/li>\n\n\n\n<li>Gmail or Outlook forwarding rules<\/li>\n<\/ul>\n\n\n\n<p><strong>Open a recent alert <em>email<\/em> from each one and check the From address<\/strong>. Plenty of platforms send alarms from one address and account notices from another, and that only turns up in a real message.<\/p>\n\n\n\n<p><strong>It&#8217;s worth taking the five minutes to do this first step<\/strong> to make sure you&#8217;re authorizing all the addresses and domains that message you.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"set-up-senders\">Step 2: Set up your senders in the text.email settings<\/h3>\n\n\n\n<p>Head to the text.email settings for your account. Scroll down to the <strong>Authorized Senders<\/strong> section.<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a8ca6e3179bb&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a8ca6e3179bb\" class=\"wp-block-image size-large wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"598\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-optionsscreen-tinified-1024x598.png\" alt=\"\" class=\"wp-image-712\" srcset=\"https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-optionsscreen-tinified-1024x598.png 1024w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-optionsscreen-tinified-300x175.png 300w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-optionsscreen-tinified-768x449.png 768w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-optionsscreen-tinified-1536x897.png 1536w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-optionsscreen-tinified.png 2020w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p>And there, you can enter individual email addresses, entire domains, or both.<\/p>\n\n\n\n<p>For example, you could authorize:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>alerts@example.com<\/code><\/li>\n\n\n\n<li><code>monitoring@example.com<\/code><\/li>\n<\/ul>\n\n\n\n<p>Or you could just authorize the whole example.com domain, so any email from any address at that domain will be able to send to you (e.g., <code>alerts@example.com<\/code>, <code>notices@example.com<\/code>, <code>server@monitoring.example.com<\/code>, and beyond). <\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a8ca6e31814f&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a8ca6e31814f\" class=\"wp-block-image size-large wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"598\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-examples-tinified-1024x598.png\" alt=\"\" class=\"wp-image-713\" srcset=\"https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-examples-tinified-1024x598.png 1024w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-examples-tinified-300x175.png 300w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-examples-tinified-768x449.png 768w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-examples-tinified-1536x897.png 1536w, https:\/\/text.email\/blog\/wp-content\/uploads\/2026\/07\/authorized-examples-tinified.png 2020w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p>A few other notes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You can <strong>authorize individual emails <em>and<\/em> domains<\/strong>, you&#8217;re not limited to one or the other.<\/li>\n\n\n\n<li>Matching is <strong>not case-sensitive<\/strong>.<\/li>\n\n\n\n<li>You can <strong>enter the emails and domains in several different formats<\/strong> (separated by commas, spaces, semicolons, or new lines). text.email will detect the valid addresses and domains.<\/li>\n<\/ul>\n\n\n\n<p><strong>Once you add at least one authorized sender, restriction is live on your account<\/strong>. Every email sent to your private text.email subdomain must come from one of the addresses or domains on your list.<\/p>\n\n\n\n<p>The restriction applies to the visible <strong>From address<\/strong> in the email, not the underlying SMTP return address sometimes used for bounces and delivery handling.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"test-this-out\">Step 3 (recommended): Test this out<\/h3>\n\n\n\n<p>Since you&#8217;re now restricting who can send to your text.email address, it&#8217;s worth testing this out.<\/p>\n\n\n\n<p>If possible, initiate a test alert from all of your systems to make sure everything is still going through.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"remove\">How to remove all restrictions<\/h3>\n\n\n\n<p>Want to get your account back to its original, unrestricted behavior?<\/p>\n\n\n\n<p><strong>Just delete every entry<\/strong> from the Authorized Senders list.<\/p>\n\n\n\n<p>When the list is empty, the Settings page will show: All addresses\/domains are allowed to send to your subdomain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"unauthorized\">What Happens When an Unauthorized Sender Tries to Send You a Message?<\/h2>\n\n\n\n<p>If an email&#8217;s From address does not match anything on your Authorized Senders list, text.email will not send the SMS.<\/p>\n\n\n\n<p>Two things happen:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><p><strong>The original email bounces.<\/strong> The sending system receives a delivery failure indicating that the email was rejected because its From address is not authorized for that text.email account.<\/p><\/li>\n\n\n\n<li><p><strong style=\"font-size: revert; color: initial; font-family: -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, Oxygen-Sans, Ubuntu, Cantarell, &quot;Helvetica Neue&quot;, sans-serif;\">You (or whoever owns the account) will get a notification.<\/strong><span style=\"font-size: revert; color: initial; font-family: -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, Oxygen-Sans, Ubuntu, Cantarell, &quot;Helvetica Neue&quot;, sans-serif;\"> text.email periodically sends an email about rejected attempts to the account owner. It includes the rejected From address and the private text.email address it attempted to use.<\/span><\/p><\/li>\n<\/ol>\n\n\n\n<p>This bounce + notification pair lets automated systems detect the failure through the bounce while also making sure that the account owner knows legitimate alerts may not be getting through.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"get-going\">Ready to Get Going with Authorized Senders?<\/h2>\n\n\n\n<p>So, again, you don&#8217;t necessarily need to use authorized senders with text.email. If you&#8217;re pretty sure the private subdomain system provides enough protection for your use, then adding authorized senders is overkill.<\/p>\n\n\n\n<p>But <strong>if your text.email address is sitting in multiple configs<\/strong> \u2014 especially on systems that other people can access \u2014 <strong>then it&#8217;s probably worth the time to lock down who can send you messages<\/strong>.<\/p>\n\n\n\n<p>The whole process is quick and reversible, so not a big loss if you ultimately change your mind.<\/p>\n\n\n\n<p>If you&#8217;re a text.email subscriber, <strong>authorized senders are already <em>live<\/em> in your account<\/strong>. Just go to your text.email settings page to get them rolling.<\/p>\n\n\n\n<p>And if you&#8217;re not a text.email user yet, <strong>authorized senders is just one of our great security features<\/strong> (you&#8217;ll also probably like our <a href=\"https:\/\/text.email\/blog\/sms-encryption\/\">SMS encryption<\/a>).<\/p>\n\n\n\n<p>You can <strong>try out text.email for free<\/strong>, with no signup required. Just send an email to <code>your-number@text.email<\/code> and watch it come through to your phone as a SMS message moments later.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to set up authorized senders to restrict who can send email to SMS messages to your text.email address.<\/p>\n","protected":false},"author":1,"featured_media":716,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,8],"tags":[],"class_list":["post-697","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-to-sms","category-text-email-tips"],"_links":{"self":[{"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/posts\/697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/comments?post=697"}],"version-history":[{"count":4,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/posts\/697\/revisions"}],"predecessor-version":[{"id":711,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/posts\/697\/revisions\/711"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/media\/716"}],"wp:attachment":[{"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/media?parent=697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/categories?post=697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/text.email\/blog\/wp-json\/wp\/v2\/tags?post=697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}