{"id":604,"date":"2026-08-23T08:36:00","date_gmt":"2026-08-23T03:06:00","guid":{"rendered":"https:\/\/smppcenter.com\/journal\/?p=604"},"modified":"2026-08-22T03:21:38","modified_gmt":"2026-08-21T21:51:38","slug":"reserved-usernames-now-blocked-across-signup-and-reseller-user-creation","status":"publish","type":"post","link":"https:\/\/smppcenter.com\/journal\/reserved-usernames-now-blocked-across-signup-and-reseller-user-creation\/","title":{"rendered":"Reserved Usernames Now Blocked Across Signup and Reseller User Creation"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">SMPP Center now blocks reserved and privileged-looking usernames on self-serve signup, reseller panel user create, and SMS API reseller user create, with live feedback, smart suggestions, and admin controls for extra brand-specific blocks.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"584\" src=\"http:\/\/smppcenter.com\/journal\/wp-content\/uploads\/2026\/08\/reserved-usernames-now-blocked-1024x584.webp\" alt=\"Illustration about Reserved Usernames Now Blocked\" class=\"wp-image-605\" srcset=\"https:\/\/smppcenter.com\/journal\/wp-content\/uploads\/2026\/08\/reserved-usernames-now-blocked-1024x584.webp 1024w, https:\/\/smppcenter.com\/journal\/wp-content\/uploads\/2026\/08\/reserved-usernames-now-blocked-300x171.webp 300w, https:\/\/smppcenter.com\/journal\/wp-content\/uploads\/2026\/08\/reserved-usernames-now-blocked-768x438.webp 768w, https:\/\/smppcenter.com\/journal\/wp-content\/uploads\/2026\/08\/reserved-usernames-now-blocked.webp 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As messaging platform operators, you already know that usernames are more than login labels. On white-label domains they sit next to your brand, appear in support tickets, and can be used by attackers who try to look like&nbsp;<code>admin<\/code>,&nbsp;<code>support<\/code>, or&nbsp;<code>root<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have rolled out reserved username protection so those names, and obvious lookalikes, cannot be registered through the normal account-creation paths.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What changed<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">SMPP Center now rejects reserved usernames such as&nbsp;<code>admin<\/code>,&nbsp;<code>root<\/code>,&nbsp;<code>support<\/code>, and other system, role, mail, and infrastructure names during account creation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The check is not limited to exact matches. It also blocks obvious numbered or separator variants, for example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>admin1<\/code><\/li>\n\n\n\n<li><code>root_99<\/code><\/li>\n\n\n\n<li><code>support-2<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Letter-extended names that look like real brands or personal handles are still allowed, for example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>myadmin<\/code><\/li>\n\n\n\n<li><code>adminx<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So the rule targets impersonation and privileged-looking identities, not every username that happens to contain those letters.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Where it applies<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The same protection is enforced on all primary ways accounts are created:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Self-serve public signup\u00a0on the front\/login theme pages<\/li>\n\n\n\n<li>Reseller panel user create\u00a0under User Management<\/li>\n\n\n\n<li>SMS API reseller user create\u00a0when accounts are provisioned through the API<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">That means a name blocked on signup is also blocked if someone tries to create it from the reseller panel or via API. Operators and resellers get consistent behavior instead of three different validation rules.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Better feedback while typing<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">On signup, username checks now give clearer live feedback:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If the name is reserved, the user is told it is not allowed<\/li>\n\n\n\n<li>If the name is already taken, the system can suggest alternative available usernames<\/li>\n\n\n\n<li>Suggestions avoid reserved names as well, so users are not pointed toward another blocked option<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is fewer failed submits and fewer \u201cwhy can\u2019t I register this username?\u201d support tickets.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Admin control in Sign up Settings<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Under&nbsp;Sign up Settings, admins can:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Open a modal to view the full\u00a0built-in reserved usernames\u00a0list<\/li>\n\n\n\n<li>Add\u00a0extra reserved usernames\u00a0for brand-specific or market-specific blocks<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Extras merge with the built-in list. They do not replace it. Names already covered by the system list are cleaned up on save, so you do not maintain duplicates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use extras for things unique to your brand or operations, such as partner aliases, internal project names, or names you never want customers to claim on your portal.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Why this matters for white-label operators<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">On a pointed reseller domain, a public account named&nbsp;<code>support<\/code>&nbsp;or&nbsp;<code>admin<\/code>&nbsp;creates confusion and risk:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Customers may trust the wrong account<\/li>\n\n\n\n<li>Support and abuse cases become harder to triage<\/li>\n\n\n\n<li>Privileged-looking names weaken the professionalism of your portal<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Blocking these early is a small UX change with a meaningful security and brand benefit, especially for multi-tenant and white-label deployments.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What resellers and end users will notice<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Creating a user with a reserved name fails with a clear validation message<\/li>\n\n\n\n<li>Public signup shows live guidance and, when useful, alternative username suggestions<\/li>\n\n\n\n<li>Valid letter-extended names such as\u00a0<code>myadmin<\/code>\u00a0can still be used<\/li>\n\n\n\n<li>Username length and uniqueness rules remain in place as before<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">What you should do<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Review\u00a0Sign up Settings\u00a0and open the built-in reserved list<\/li>\n\n\n\n<li>Add any brand-specific extras you want blocked<\/li>\n\n\n\n<li>Brief reseller teams that reserved and lookalike names are rejected in panel and API user create<\/li>\n\n\n\n<li>Point support to the updated guidance if users ask why a name was rejected<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This is a platform hardening update: clearer signup UX, safer usernames across self-serve and reseller provisioning, and admin visibility into what is blocked by default.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SMPP Center now blocks reserved and privileged-looking usernames on self-serve signup, reseller panel user create, and SMS API reseller user create, with live feedback, smart suggestions, and admin controls for extra brand-specific blocks.<\/p>\n","protected":false},"author":1,"featured_media":605,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[626],"tags":[628,629,627,630],"class_list":["post-604","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-privileged-usernames","tag-reseller-panel","tag-reserved-usernames-blocked","tag-sms-api-reseller-user-create"],"_links":{"self":[{"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/posts\/604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/comments?post=604"}],"version-history":[{"count":0,"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/posts\/604\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/media\/605"}],"wp:attachment":[{"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/media?parent=604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/categories?post=604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smppcenter.com\/journal\/wp-json\/wp\/v2\/tags?post=604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}