Fraud Watch — Vendor Quality & Toll-Fraud Detection
Built-in fraud detection for your own vendors and downstream customers - FAS/quality signals and toll-fraud/IRSF protection, no extra tool or cost.
Fraud Watch is built into every 6X Switch account — it watches your own vendors and your own downstream customers for the same fraud signals 6X itself watches for, using nothing but the CDR data your traffic already generates. No separate tool, no extra login, no extra cost. Voice and SMS are watched, and enforced, independently on both the vendor side and the customer side — an SMS-only issue never touches voice routing or voice calling, and vice versa.
Vendor Quality Detection (FAS) — Voice
Fake Answer Supervision (FAS) is when a vendor's gateway reports a call as answered without a real connection actually being made — you get billed for a "successful" call that never really happened. Fraud Watch flags this by watching, per vendor and per destination country:
- Answer rate and average call duration against a floor you can set per vendor (or a sensible platform default if you don't).
- Peer comparison — if 3 of your other vendors average 45 seconds on calls to a country but one vendor averages 6 seconds on the exact same country, that's a much stronger signal than a fixed number alone, since some countries are legitimately short-duration (heavy voicemail, high no-answer rates) and a fixed floor either misses those or false-positives on them.
- Sudden quality shifts — a vendor's answer rate or call duration dropping sharply in the last 24 hours compared to its own 7-day baseline.
- Repeat short-call clusters — the same destination dialed repeatedly with near-identical short answered calls, a pattern consistent with test-call abuse.
- Cost anomalies — a vendor's cost-per-minute spiking without a corresponding rate-card change.
When enabled, a vendor that breaches its threshold is automatically pulled from voice routing (no more calls sent to it) and you're emailed immediately. You restore it yourself once it's fixed — nothing is permanent, and nothing happens without you being notified first.
Vendor Quality Detection — SMS
The SMS equivalent of the voice check above, watching for a vendor that accepts messages without actually delivering them (or rejects too many outright):
- Failure rate — the share of messages a vendor rejects outright, against a threshold you can set per vendor or a platform default.
- Delivery-confirmed rate — of messages a vendor doesn't reject, what share actually come back with a real delivery confirmation (DLR). Messages sent very recently are excluded from this so a DLR that just hasn't arrived yet isn't mistaken for a lost one. A vendor that accepts a message but it silently never delivers is the SMS version of a fake-answered call.
- Sudden quality shifts — a jump in failure rate or drop in delivery-confirmed rate versus that vendor's own 7-day baseline.
- Cost anomalies — a vendor's cost-per-message spiking without a corresponding rate-card change.
When enabled, a vendor that breaches its threshold is automatically pulled from SMS routing only — a vendor also carrying your voice traffic keeps that traffic uninterrupted. You're emailed immediately and restore it yourself once it's fixed, same as voice.
Customer Toll-Fraud / IRSF Detection — Voice
This protects your downstream customers from the most common and costly fraud pattern in wholesale telephony: a compromised account or hacked extension suddenly placing a burst of international/premium calls, usually overnight, draining a customer's wallet before anyone notices. Fraud Watch watches every one of your downstream customers for:
- Volume spikes — a sudden burst of call volume compared to that customer's own historical baseline.
- Off-hours activity shifts — calls landing outside a customer's normal calling pattern, checked in their own timezone, not a generic clock.
- High-risk destination hits — any call to a watchlisted premium/satellite/high-fraud-risk destination, flagged regardless of volume (even a single call to certain ranges is worth knowing about).
When enabled, a matching account is automatically frozen (voice calling stopped) and both you and the customer are emailed. You review and restore the account once it's confirmed safe.
Customer SMS-Fraud Detection
The same protection extended to your downstream customers' SMS sending — a stolen wallet used for a spam blast is just as real a risk as toll fraud. Fraud Watch watches every SMS-enabled downstream customer for:
- Message volume spikes — a sudden burst of SMS volume compared to that customer's own baseline.
- Off-hours SMS shifts — messages landing outside a customer's normal pattern, in their own timezone.
- High-risk destination hits — the same watchlist used for voice.
- Broadcast blasts — the identical message sent to a large number of distinct numbers in a short window, the classic spam/smishing signature.
- Failure-rate spikes — a sudden jump in messages failing to send, consistent with a compromised account probing or spamming numbers.
When enabled, a matching account has SMS sending only automatically disabled — their voice calling is never affected. Both you and the customer are emailed, and you review and restore SMS access once it's confirmed safe.
Where To Find It
Your own scoped Fraud Watch view — showing only your vendors and your downstream customers, never anyone else's — is available from your partner portal navigation under Fraud Watch, with separate sections for voice and SMS on both the vendor and customer side. Per-vendor voice and SMS quality thresholds, and restoring a suspended vendor on either channel, are managed right on that vendor's entry in My Vendors.
Detection runs automatically in the background — vendor quality (voice and SMS) checked every 30 minutes, customer toll-fraud and SMS-fraud checked every 15 minutes — there's nothing to configure to get visibility. Auto-suspend/auto-freeze/auto-disable enforcement itself is a platform-wide setting 6X controls per channel; while any of them is off, you still get every alert by email, just without anything being automatically blocked.