The SaaS company should own the purpose, approved wording, sender-identity policy, localization, expiry and resend rules, and approval history for its login one-time passcodes (OTPs). SMS and email providers can deliver messages and handle channel-specific setup, but operating the delivery platform does not make a provider the product owner. In the EU, controller and processor roles depend on who actually determines the purposes and means of processing—not just the labels in a contract.
Who should own an OTP template?
Treat the OTP message as part of the login product and security policy, while treating delivery as an operational service. Assign decisions clearly so a provider dashboard or an urgent copy edit does not silently become the source of truth.
| Responsibility | Accountable owner | What it covers |
|---|---|---|
| OTP purpose and user-facing policy | SaaS product and security owners | Why an OTP is sent; approved wording; sender identity policy; supported languages and accessibility variants; code lifetime; resend limits; abuse controls; fallback behavior; and review of changes to links, support language, and brand identifiers. |
| Provider and delivery configuration | SaaS engineering or delivery operations | Provider account access, sender assets, DNS records, credentials, routing and fallback logic, delivery telemetry, and incident escalation. |
| Message transport and channel setup | SMS or email provider, under contract | Delivery infrastructure, channel configuration, and applicable technical setup or registration support. These tasks do not replace the SaaS’s decisions about product content and policy. |
| EU privacy-role assessment | SaaS data-protection or legal owner | Document the actual controller/processor roles, data flows, and any required processor terms and instructions. |
Keep the approved template and its associated rules versioned. Define who may approve a change, and ensure the provider configuration matches that approved version.
How do SMS and email differ operationally?
The key distinction is not which channel has better OTP delivery performance: the cited sources do not establish a comparative speed, completion, fraud, or cost result. The operational work differs by channel, and the SaaS should use its own telemetry to assess delivery, fallback, and user recovery.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Ownership area | SMS OTP | Email OTP |
|---|---|---|
| Sender identity | The SaaS should set the sender-identity policy and maintain the sender assets required by its provider and destination markets. | The SaaS should control the visible sender identity and the domain used for transactional OTP messages. |
| Registration or configuration burden | Depends on provider, sending method, destination country, and applicable carrier or local processes. AWS documents a US 10DLC workflow of brand registration followed by campaign registration; its documentation describes brand vetting as optional. AWS registration instructions. | Requires email-domain authentication configuration, coordinated with the mail provider and DNS owner. The relevant mechanisms are SPF, DKIM, and DMARC. |
| DNS and domain ownership | The cited SMS guidance does not establish a comparable DNS requirement; check the chosen provider’s setup instructions. | Engineering or delivery operations must coordinate authentication records with whoever controls the domain’s DNS. |
| Delivery, fallback, and recovery | Set routing, fallback, telemetry, and abuse controls as SaaS policy; measure results in your own service. | Set routing, fallback, telemetry, and abuse controls as SaaS policy; measure results in your own service. |
What should US SMS owners check?
For US 10DLC, AWS describes registration as two stages: complete brand registration, then register the campaign. The same documentation presents brand vetting as an optional step intended to increase messaging capacity. Assign an internal owner for the business identity and campaign details, and confirm current requirements in the selected provider’s US documentation before launch; requirements can depend on sending method, provider, and current carrier processes.
What should EU SMS owners check?
There is no single EU sender-registration rule established here for every provider and destination. Requirements can vary by country and provider. For example, Brevo says its platform requires sender registration for each destination country for transactional as well as marketing SMS. That is Brevo’s policy, not proof of a universal EU legal obligation. Check the chosen provider’s current country guidance and applicable local rules.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What must email OTP owners configure?
Use a sender identity and domain the SaaS controls, and coordinate the domain’s authentication records with the email provider and DNS owner. The three mechanisms have complementary functions:
- SPF identifies the hosts authorized to send email for a domain.
- DKIM uses a digital signature to verify the sending domain’s message and detect alteration in transit.
- DMARC tells receiving systems how to handle mail that appears to come from the domain but fails SPF or DKIM checks, and can provide reporting.
The European Commission describes these email security standards in its email communication security standards. The FTC also recommends email authentication for businesses using their own domain and explains that DMARC aligns the authentication identity with the visible From address in its Cybersecurity for Small Business guidance.
Rank #3
- Protect Online Account - Offer a strong factor authentication to your online account. Never lose your accounts through password theft, phishing, hacking or keylogging scams.
- Universal Compatibility - The Thetis U2F key can be used on any websites which support U2F protocol with the latest Chrome installed on your Windows, Mac OS or Linux. (Important Note: Not compatible with any email clients including Apple Mail, Mozilla Thunderbird or Microsoft Outlook)
- FIDO-U2f-Certified - Safety is our priority. Certified by world's largest Ecosystem for Standards-based, interoperable Authentication. Only support U2F protocol (No UAF or OTP). Provide low-cost and simple solution with high security.
- Extremly Durable - Designed with a 360° rotating metal cover that shields the USB connector when not in use. Also, crafted from a durable aluminum alloy to protect the Key from drops, bumps and scratches.
- Portable Design - Compact, ultra-portable design allows you to take your FIDO key anywhere you need it.
How do GDPR roles apply to OTP delivery?
Under GDPR Article 4(7), a controller is the person or body that, alone or jointly with others, determines the purposes and means of processing personal data. A processor handles personal data on behalf of a controller. Article 28 requires an appropriate binding arrangement and documented instructions for processor activity, subject to the regulation’s stated legal exception. Determine and document the roles from the actual SaaS/vendor relationship and OTP data flows; a contract label alone does not settle the question. See Regulation (EU) 2016/679.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Does payment SCA law dictate OTP for every SaaS login?
No. Commission Delegated Regulation (EU) 2018/389 establishes technical standards for strong customer authentication in the payment-services context. It should not be treated as a universal rule requiring SMS or email OTP for ordinary SaaS sign-ins. Separate routine account login from regulated payment authentication and seek legal review for payment-related flows. See Commission Delegated Regulation (EU) 2018/389.
Quick Recap
Rank #4
- MULTI-APPLICATION SECURITY KEY FOR ENTERPRISE USE: Supports FIDO2 passkeys, U2F, Smart Card (PIV), and OTP for flexible authentication across enterprise environments.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, U2F, PIV, and OTP across enterprise, cloud, and identity infrastructure.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. Additional software may be required for PIV or OTP
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries or drivers required for FIDO2.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

