Skip to content
مرسال
Log in Try free
Phone Verification: A Guide to OTP Codes over WhatsApp and SMS

Every new signup raises one question: is this number real? A verification code (OTP) is the cheapest, fastest answer, and it solves two problems at once — it blocks fake accounts, and it leaves you with a list of working numbers you can legitimately market to later.

When to require verification, and when not to

Verification isn't free — it costs you a message and costs the customer an extra step. Ask for it where it earns its place:

  • Worth it: account creation, changing a number or password, first purchase, withdrawing a balance, confirming a large cash-on-delivery order.
  • Not worth it: every routine login, newsletter signup, or browsing products.

The rule: verify at risk points, not at every step. A site that demands a code every time loses more customers than it prevents fraud.

Which channel should carry the code?

  • WhatsApp: cheapest and fastest to arrive in the Egyptian market, and it supports buttons and one-tap code copying. The catch: not every number has WhatsApp.
  • SMS: reaches any number, even without internet. Best as a fallback, or for older demographics.
  • Email: a safety net for when neither of the others works.

The practical setup: WhatsApp first, SMS as fallback, email last. In Mersal you set the default channel per scenario and the gateway that backs each channel.

Numbers that make the experience better

  • Short validity: 5–10 minutes. Longer widens the abuse window with no benefit to the user.
  • Six digits: the right balance between security and being easy to type.
  • Attempt limits: lock after 5 wrong tries to prevent guessing.
  • Resend limits: a countdown before a new code can be requested — this protects your credit balance.

The wording of the code message

Customers read this message in the notification without opening it, so word order matters:

  • Company name first: "Mersal: your code is 481920" beats "Your code is 481920 from Mersal".
  • Code on the first line: so it's visible in the notification without opening.
  • Validity window: "valid for 5 minutes" reduces attempts to reuse an expired code.
  • A short warning: "never share this code" — one line that prevents an entire category of fraud.
  • No links: other than a one-tap confirmation link, any URL raises the odds of spam filtering.

The phone field itself

Most verification codes fail before they're even sent, because the user typed their number wrong. An international phone field with country selection and auto-formatting sharply reduces those errors — which is exactly what the Mersal OTP plugin gives WordPress sites out of the box.

The two most frequent errors: a leading zero kept alongside the country code (+20 010…), and numbers typed with spaces or dashes. Automatic normalisation fixes both before sending.

Protecting your balance from abuse

An unprotected signup form can be exploited to drain your credit or spam other people's numbers. The limits to set:

  • A cap on codes per number per hour (3 is plenty).
  • A cap per IP address per hour.
  • A mandatory countdown before the resend button activates.
  • A captcha after two failed attempts from the same device.
  • Weekly monitoring: a sudden jump in codes requested with no matching rise in new accounts means someone is abusing the form.

Beyond verification: login by code

If the number is already verified, why ask for a password at all? Code-based login removes "forgot password" from your life and your customer's. And one step further: a one-tap confirmation link — the customer taps instead of typing.

Higher security: the authenticator app

For sensitive accounts, the Mersal Authenticator app generates offline TOTP codes with no network, and supports one-tap sign-in approval. That's stronger than message-based OTP because it can't be intercepted in transit.

Common mistakes

  • Sending the code from a different number each time — it confuses customers and looks like fraud.
  • A code message with no company name — the customer can't tell who is asking for what.
  • No fallback channel — one gateway outage then stops signups entirely.
  • An excessively long validity window (an hour) — it defeats the point of verification.
  • Writing the code to an error log — a complete security leak you'll never notice.

Frequently asked questions

What if the customer never receives the code? Check the country code first, then try the fallback channel. If the gateway itself is down, a test send from the Mersal dashboard makes that obvious in seconds.

Is WhatsApp verification safer than SMS? Relatively, yes — SMS can be intercepted in rare cases, and WhatsApp is encrypted. But an authenticator app is safer than either.

Do codes come out of my balance? Yes, like any message — which is why putting WhatsApp ahead of SMS makes a clear cost difference at volume.

Share this article:
share work chat