To run lawful SMS marketing in the United States, you need prior express written consent for promotional messages, a working opt-out system that honors revocations within the FCC's 10-business-day window, carrier registration through 10DLC for long-code traffic, and timestamped records proving all of the above. That is the short version. The longer version is what this guide covers.
Before you send a single campaign, check these four items:
- Consent type: Promotional texts require prior express written consent (PEWC) under 47 U.S.C. § 227. Transactional messages require a lower threshold, but the line between the two is narrower than most marketers assume.
- Revocation handling: The FCC's 2024 rulemaking requires you to honor opt-outs by any reasonable method within 10 business days. In-band STOP replies should be processed immediately.
- Carrier registration: A2P 10DLC registration became mandatory for 10-digit long-code traffic. Unregistered campaigns face carrier blocking.
- Recordkeeping: Store the consent record, the exact disclosure text shown, the channel, IP address, timestamp, and campaign ID. These are your litigation defense.
The TCPA (Telephone Consumer Protection Act) is the federal statute. The FCC enforces it and issues orders that refine how it applies to modern messaging. The CTIA sets carrier-level standards that operate alongside the law. You need to satisfy all three layers.
Key Takeaways
TCPA-compliant SMS marketing requires prior express written consent, real-time opt-out processing, 10DLC carrier registration, and timestamped consent records that can survive litigation discovery.
| Point | Details |
|---|---|
| Consent standard for marketing | Promotional texts require prior express written consent (PEWC); transactional messages require a lower prior express consent threshold. |
| Opt-out processing window | Honor revocations by any reasonable method within 10 business days; process in-band STOP replies immediately. |
| Carrier registration | Register brand and campaign with The Campaign Registry (10DLC) before sending A2P traffic on long codes; unregistered traffic is blocked. |
| Recordkeeping fields | Store timestamp, disclosure text, channel, IP, campaign ID, and revocation records; retain for the relationship duration plus 4 years. |
| Rooted Up implementation | Rooted Up designs consent flows, handles 10DLC registration, and configures suppression and monitoring as part of monthly marketing plans. |
Table of Contents
- What does the TCPA actually cover for SMS texts?
- Who is actually responsible for TCPA compliance?
- Transactional vs. promotional texts: why the distinction matters
- Core TCPA requirements every SMS marketer must meet
- How to capture valid prior express written consent
- How to implement opt-out and revocation correctly
- What to store and how to build an auditable consent record
- Third-party leads, lead generators, and one-to-one consent
- Technical controls and sender registration you need in place
- What TCPA enforcement actually costs and how to reduce your exposure
- Your pre-launch compliance checklist and message templates
- How Rooted Up builds compliant SMS programs for solo professionals
- The part most small businesses get wrong
- Rooted Up handles the compliance setup so you can focus on your clients
- Sources
What does the TCPA actually cover for SMS texts?
The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, treats text messages as "calls" for regulatory purposes when they are sent using an automatic telephone dialing system (ATDS) or contain a prerecorded/artificial voice component. That classification is what pulls SMS marketing squarely into TCPA territory.
The FCC's 2024 Report and Order went further than prior guidance. It codified how revocation must work, established the mechanics of the one-time confirmation message, and reinforced that the National Do-Not-Call Registry protections extend to text messages. A separate 2024 order required terminating mobile wireless providers to block illegal texts upon Commission notification, which means carriers now have a regulatory obligation to filter traffic, not just a business incentive.
Three distinct layers govern your SMS program:
- TCPA / FCC: Federal law and FCC orders. These set the consent standards, revocation rules, quiet hours, and identification requirements. Violations create private right of action and FCC enforcement exposure.
- CTIA guidelines: Industry standards maintained by the wireless industry association. Carriers use these as the baseline for what traffic they will deliver. CTIA compliance is not optional in practice, even though it is not a statute.
- Carrier / 10DLC rules: The Campaign Registry (TCR) and individual carriers enforce registration requirements, content policies, and throughput limits at the network level. A campaign can be legally compliant and still get blocked if it fails carrier screening.
The practical upshot: TCPA is the legal floor, and CTIA/carrier rules are the operational ceiling. You need to clear both.
Who is actually responsible for TCPA compliance?
Primary liability under the TCPA attaches to the party that initiates the message. If your brand's name is in the text, you are the initiating party regardless of which platform or vendor sent it on your behalf. That said, vendors, platforms, and lead buyers can share exposure when they participate in the consent chain or control the sending infrastructure.
Key liability assignments to understand:
- Brands/senders: Responsible for obtaining valid consent, honoring opt-outs, and registering campaigns. You cannot outsource this liability to a vendor.
- SMS platforms and aggregators: Can face secondary liability if they knowingly facilitate non-compliant campaigns. Reputable platforms will require you to certify compliance before activating a campaign.
- Lead buyers: If you purchase a list and send to those numbers, you are the initiating party. The lead generator's consent records are your problem to verify.
- Third-party agents: Marketers who use agencies or contractors to run campaigns remain the responsible party. The agent's actions bind the brand.
Before activating any vendor or platform, require the following in writing:
- A contractual representation that their platform supports TCPA-compliant consent flows and suppression list management.
- Indemnification language covering their own operational failures (e.g., failure to suppress a number after an opt-out is logged).
- Access to audit logs showing message delivery, opt-out processing, and suppression list updates.
- Data processing agreements that specify how consent records are stored and for how long.
Pro Tip: Write a short vendor compliance questionnaire and require it before onboarding any SMS platform or lead source. Ask specifically: How do you handle STOP replies? How quickly are opt-outs propagated to suppression lists? Do you support 10DLC registration? The answers tell you more than any contract clause.
Transactional vs. promotional texts: why the distinction matters
The consent standard you need depends entirely on the primary purpose of the message. Get this classification wrong and you may be sending promotional content under a transactional consent standard, which is one of the most common TCPA exposure points.
The primary purpose test works like this:
- Promotional (marketing) messages: Any message whose primary purpose is to advertise or promote a product, service, or commercial opportunity. These require prior express written consent (PEWC), the highest consent standard under the TCPA.
- Transactional or informational messages: Messages that relay information the recipient requested or that relate to an existing transaction (appointment reminders, order confirmations, account alerts). These require prior express consent, a lower threshold that does not need to be in writing.
- Emergency messages: No consent required, but the emergency exception is narrow and should not be stretched.
Short examples mapped to consent standard:
- "Your appointment is confirmed for Thursday at 2 PM." → Transactional. Prior express consent sufficient.
- "Your order has shipped. Track it here." → Transactional. Prior express consent sufficient.
- "Your appointment is Thursday. While you're here, ask about our new membership plan." → Mixed. The promotional element triggers PEWC for the entire message.
- "Flash sale: 20% off this weekend only." → Promotional. PEWC required.
The operational warning here is real: do not add promotional language to a transactional thread. A single upsell sentence in an order confirmation can reclassify the entire message as promotional, retroactively exposing every prior message in that thread to PEWC scrutiny. Keep the threads separate.
Core TCPA requirements every SMS marketer must meet
These are the non-negotiable requirements. Think of this as the minimum viable compliance set for any U.S. SMS program.
Prior express written consent for marketing messages. The consent must be in writing (electronic signatures qualify), voluntary, and obtained before the first promotional message. The disclosure must name the sender and describe the message type.

Sender identification. Every message must identify who is sending it. 47 CFR § 64.1200 requires that the sender's identity be clear. Do not rely on the short code or number alone.
Opt-out language in every message. Include a clear opt-out instruction in every marketing message. "Reply STOP to unsubscribe" is the standard. Variations like "Text STOP to cancel" are acceptable, but the instruction must be present.
Quiet hours. The FCC prohibits telemarketing calls and texts outside established quiet hours in the recipient's local time zone. This is not a soft guideline. Enforce it at the platform level using time-zone detection, not just the sender's time zone.
Opt-out processing timeline. The FCC requires revocations to be honored within a reasonable time not to exceed 10 business days. For in-band STOP replies, process them immediately.
The one-time confirmation message is a specific allowance, not a loophole. It must be non-promotional. Using it to pitch a product or offer a discount after someone opts out is a violation.
Pro Tip: Build quiet-hours enforcement at the platform level, not in your campaign scheduling. If a message is queued for 8:45 PM and delivery is delayed, a platform-level time-zone check prevents it from landing at 9:05 PM in a recipient's local time. Scheduling alone is not enough.
How to capture valid prior express written consent
PEWC has four required elements. Miss any one of them and the consent may not hold up in litigation or regulatory review.
- Clear and conspicuous disclosure: The consent language must be visible, readable, and not buried in fine print or a terms-of-service scroll. It must appear near the point of consent capture.
- Sender identification: The disclosure must name the specific company or brand sending the messages. "You consent to receive messages from our partners" does not satisfy this requirement.
- Message type and frequency disclosure: State what kind of messages the subscriber will receive and approximately how often. "Recurring marketing messages, up to 4/month" is the standard format.
- Cost disclosure: Include "Message and data rates may apply."
- Voluntary agreement: The consent cannot be a condition of purchase. Bundling consent with a required checkout step is a common violation.
- Electronic signature or affirmative action: A checked checkbox (not pre-checked), a typed name, or a keyword reply (e.g., texting "JOIN") all qualify as electronic signatures under the E-SIGN Act.
Sample PEWC language for a web form:
By checking this box, I agree to receive recurring promotional text messages from [Brand Name] at the phone number provided. Message and data rates may apply. Message frequency varies. Reply STOP to unsubscribe. Reply HELP for help. View our [Privacy Policy] and [Terms of Service].
Sample double-opt-in confirmation message:
[Brand Name]: You requested to join our SMS list. Reply YES to confirm. Reply STOP to cancel. Msg & data rates may apply.
Steps for a compliant consent capture flow:
- Display the PEWC disclosure adjacent to the phone number field, not below the submit button.
- Use an unchecked checkbox for SMS consent. Never pre-check it.
- Log the timestamp, IP address, page URL, form version, and the exact disclosure text shown at the time of consent.
- Send a double-opt-in confirmation and log the reply before adding the number to your active list.
- Tie the consent record to a campaign ID so you can demonstrate which program the subscriber joined.
Pro Tip: Version-control your consent language. If you update the disclosure text, existing subscribers consented to the prior version. Depending on the change, you may need to re-consent them. Keep a dated archive of every version of your consent form.
How to implement opt-out and revocation correctly
Accept opt-outs by any reasonable method. That phrase comes directly from the FCC's 2024 rulemaking and it is broader than most marketers realize. A subscriber who emails your support team asking to stop receiving texts has submitted a valid revocation request. So has someone who tells a customer service rep on a phone call.
The operational flow:
- Receive the revocation request via any channel (STOP reply, email, chat, phone, web form).
- Log the request with a timestamp, the channel it arrived through, and the agent or system that received it.
- Update the suppression list in your SMS platform immediately for in-band STOP replies. For off-channel requests, complete suppression within 10 business days.
- Send one non-promotional confirmation text if the subscriber opted out via STOP reply. Example: "You have been unsubscribed from [Brand Name] alerts. No further messages will be sent. Reply START to re-subscribe."
- Persist the audit record indefinitely. A suppressed number that gets reactivated because a record was deleted is a litigation risk.
Pro Tip: Build a real-time integration between your customer support platform (Zendesk, Intercom, or similar) and your SMS suppression list. When a support agent logs an opt-out request, it should trigger an automatic suppression update, not a manual ticket. The 10-business-day window sounds generous until you factor in weekends, agent errors, and ticket backlogs.
Edge cases to handle explicitly:
- Reassigned numbers: A number that belonged to a consenting subscriber may be reassigned to a new person. Check the Reassigned Numbers Database (RND) before sending to numbers that have been inactive for 30 or more days.
- Mixed consent categories: If a subscriber consented to transactional messages but not promotional ones, maintain separate suppression states for each category.
- Clarifying questions: You may ask a subscriber which message types they want to stop receiving, but only if the clarifying message itself is non-promotional and the subscriber's original opt-out is honored immediately.
What to store and how to build an auditable consent record
Retain consent records for as long as you send to that subscriber, plus a reasonable litigation hold period afterward. The FCC does not specify a minimum retention period in the TCPA rules, but plaintiffs' attorneys and courts expect records to survive at least four years given the TCPA's statute of limitations.

Pro Tip: Tools like ActiveProspect's TrustedForm create cryptographically signed consent certificates that capture a session replay of the consent form, the IP, the timestamp, and the exact disclosure text. These certificates are designed to survive discovery. If you are running high-volume campaigns or buying leads, this type of third-party consent certification is worth the cost.
Third-party leads, lead generators, and one-to-one consent
Treat every third-party lead as high risk until proven otherwise. When you buy or receive a lead, you are inheriting the consent chain that lead generator built, and you have no direct visibility into how that consent was obtained.
The one-to-one consent rule has had a complicated history. The FCC proposed a rule requiring that consent be specific to a single named company rather than a broad category of "marketing partners." An appeals court vacated that rule, but the underlying regulatory intent has not disappeared. Marketers who relied on broad partner-consent language to cover dozens of brands in a single checkbox are still operating in a legally uncertain environment.
Practical steps for managing third-party lead consent:
- Require the lead provider to supply the consent record for every lead: timestamp, disclosure text, IP address, and the URL where consent was captured.
- Audit a sample of records before activating a new lead source. Verify that the disclosure named your brand specifically, not just a category of partners.
- Capture fresh consent where possible. If the lead's consent record is weak or the disclosure did not name you, send a consent-request message before sending any promotional content.
- Document the chain of transfer. Keep records showing when you received the lead, from whom, and what consent documentation accompanied it.
- Suppress against the DNC registry before any outreach. The FCC's 2024 order confirmed that DNC protections extend to text messages.
Contract checklist for lead providers:
- Representation and warranty that all leads were obtained with TCPA-compliant consent naming your brand.
- Indemnification for TCPA claims arising from their consent practices.
- Right to audit consent records on demand.
- Obligation to notify you of any regulatory inquiry or litigation involving their consent practices.
- Data deletion obligations if a lead's consent is found to be defective.
Technical controls and sender registration you need in place
Register your brand and campaign with The Campaign Registry (TCR) for any A2P traffic sent via 10-digit long codes. 10DLC registration became mandatory for this traffic type, and carriers have been blocking unregistered campaigns. This is not a compliance checkbox you can defer.
Sender type selection matters for your use case:
- 10DLC long codes: Best for moderate-volume, personalized messaging. Requires TCR brand and campaign registration. Throughput is limited compared to short codes.
- Dedicated short codes: Higher throughput, faster delivery, more expensive. Still require carrier approval and CTIA-compliant use cases.
- Toll-free numbers: Middle ground for volume and cost. Require toll-free verification through carriers.
Technical controls to implement before launch:
- Suppression list check pre-send: Query your suppression list against every outbound batch. Never rely on a static export from last week.
- Time-zone quiet-hours enforcement: Detect the recipient's time zone from the area code or a stored preference and block delivery outside 8 AM to 9 PM local time.
- Consent lookup by campaign ID: Before sending a campaign message, verify that the recipient's consent record is tied to that specific campaign.
- RND checks: Query the Reassigned Numbers Database for numbers that have been inactive or flagged as reassigned before including them in a send.
- Rate limiting: Stay within carrier-approved throughput limits for your sender type to avoid triggering spam filters.
Vendor feature checklist. Require these from any SMS platform you use:
- Real-time suppression list updates triggered by STOP replies.
- Audit logs with message-level delivery and opt-out records.
- Campaign registration support (TCR/10DLC workflow).
- Consent API or integration point for your CRM.
- Time-zone enforcement at the platform level.
Pro Tip: Legal practitioners at Holland & Knight note that aligning your privacy policy and consent disclosures with your campaign design before attempting TCR registration reduces the risk of rejection. Carriers commonly reject registrations where the privacy policy does not explicitly describe how mobile data is used or shared. Fix the policy first, then register.
What TCPA enforcement actually costs and how to reduce your exposure
Statutory damages under the TCPA run from $500 to $1,500 per message. There is no statutory aggregate cap. A class action covering many recipients can produce significant settlement exposure potentially in the millions before a single trial. Private class actions are the primary enforcement vehicle, not FCC fines, which means the plaintiff's bar drives most of the risk.
Common claim triggers and their fixes:
- Weak or missing consent records: The plaintiff's attorney asks for the consent record. You cannot produce one. Fix: build the data model in Section 8 before sending.
- Delayed opt-out processing: A subscriber opted out via email three weeks ago and received two more campaigns. Fix: real-time integration between support channels and suppression lists.
- Mixed messaging in transactional threads: A promotional sentence in an order confirmation reclassifies the message. Fix: strict content review before any transactional template is updated.
- Reassigned number claims: You sent to a number that was reassigned after the original subscriber consented. Fix: RND checks before every send to inactive numbers.
- No quiet-hours enforcement: A message delivered at 9:15 PM in the recipient's time zone. Fix: platform-level time-zone enforcement, not campaign scheduling.
Practical mitigation steps:
- Maintain a consent audit log that can be exported and produced in litigation within 48 hours.
- Set message rate limits that match your carrier registration throughput to avoid triggering spam classification.
- Monitor complaint rates in your SMS platform dashboard. A spike in STOP replies or carrier complaints is an early warning sign.
- Review your SMS program with legal counsel at least annually, or any time you add a new lead source, change your consent flow, or expand to a new message category.
- Consider TCPA-specific insurance riders if your program volume is high.
Your pre-launch compliance checklist and message templates
Work through this sequentially. Do not skip steps because a campaign is time-sensitive.
Pre-launch checklist:
- Confirm consent type required for each message category (PEWC for promotional, prior express consent for transactional).
- Draft and legal-review your PEWC disclosure language. Confirm it names your brand, describes message type and frequency, includes cost disclosure, and links to your privacy policy.
- Verify your privacy policy explicitly describes how mobile/SMS data is collected, used, and shared.
- Register your brand and campaign with TCR (10DLC) or complete toll-free verification.
- Configure suppression list integration in your SMS platform. Test that a STOP reply removes the number from the active list within 60 seconds.
- Enable time-zone quiet-hours enforcement at the platform level.
- Build or import your consent records into a structured data store with all required fields (see Section 8).
- Run a suppression check against the DNC registry and your internal opt-out list before the first send.
- Send a test batch of 10 to 20 internal numbers. Verify delivery, opt-out processing, and confirmation message content.
- Document the test results and store them with the campaign record.
Sample PEWC consent text for a web form:
By providing your phone number and checking this box, you agree to receive recurring automated promotional text messages from [Brand Name] at the number provided. Consent is not a condition of purchase. Message and data rates may apply. Message frequency varies. Text STOP to unsubscribe, HELP for help. [Privacy Policy] | [Terms of Service]
Sample double-opt-in confirmation:
[Brand Name] SMS: We received your request to join our list. Reply YES to confirm. Reply STOP to cancel. Msg & data rates may apply. Up to [X] msgs/month.
Sample opt-out confirmation:
[Brand Name]: You've been unsubscribed. No further messages will be sent. Reply START to re-subscribe or visit [URL] for help.
QA test plan before go-live:
- Test STOP reply: send from a test number, reply STOP, verify suppression within 60 seconds, verify confirmation message is non-promotional.
- Test quiet hours: attempt a send at 8:55 PM in the recipient's time zone, verify it delivers; attempt at 9:05 PM, verify it is held or blocked.
- Test consent lookup: attempt to send to a number not in the consent database, verify the platform blocks it.
- Test RND check: use a number flagged in the RND, verify it is excluded from the send.
- Review audit log: confirm message-level records include timestamp, recipient number, campaign ID, and delivery status.
Pro Tip: Run your QA test plan against a staging environment that mirrors production. A suppression check that works in staging but fails in production because of an environment variable difference has caused real violations. Treat the test plan as a release gate, not a formality.
How Rooted Up builds compliant SMS programs for solo professionals
For solo professionals and small business owners who want to use SMS marketing without building a compliance infrastructure from scratch, Rooted Up handles the operational setup so you can focus on your clients.
The practical steps Rooted Up follows when building a compliant SMS program:
- Consent flow audit: Review existing signup forms, landing pages, and opt-in points to identify gaps in PEWC language, disclosure placement, and checkbox configuration.
- Consent language design: Draft or revise disclosure text to meet TCPA and CTIA standards, including sender identification, frequency disclosure, cost disclosure, and opt-out instructions.
- 10DLC registration support: Guide brand and campaign registration through The Campaign Registry, including privacy policy alignment to reduce carrier rejection risk.
- Platform configuration: Set up suppression list integration, quiet-hours enforcement, and audit logging in your SMS platform.
- Ongoing monitoring: Track opt-out rates, complaint signals, and campaign registration status as part of the monthly service.
Readers who want professional implementation rather than a DIY build can review Rooted Up's service offerings and monthly plans at Rootedup.
The part most small businesses get wrong
Small operators consistently make two errors that create outsized TCPA risk. The first is treating consent as a one-time setup task. They build a form, add a checkbox, and assume they are covered indefinitely. But consent is tied to a specific disclosure at a specific point in time. When the form changes, the message type expands, or a new lead source is added, the consent chain needs to be re-evaluated. The second error is assuming the SMS platform handles compliance automatically. Platforms provide tools; they do not make compliance decisions for you. A platform that processes STOP replies correctly does not protect you if your consent form was defective from the start.
On the technical side, outsource the platform configuration and 10DLC registration to someone who has done it before. The TCR registration process has specific requirements around privacy policy language, and a rejected registration delays your entire program. Keep the consent records in-house or with a certified consent-capture provider like ActiveProspect. Those records are your legal defense, and you want direct access to them.
State-level variability is real. Florida, Oklahoma, and Washington have their own mini-TCPA statutes with different consent thresholds and damages structures. If your list includes recipients in those states, get counsel to review your program against state law, not just the federal TCPA.
Rooted Up handles the compliance setup so you can focus on your clients
Running a TCPA-compliant SMS program requires consent flows, carrier registration, suppression logic, and audit trails working together before a single message goes out. For solo professionals and small business owners, building that infrastructure while running a practice is not realistic.
Rooted Up's monthly marketing plans include consent flow design, 10DLC registration support, platform configuration, and ongoing monitoring as part of a structured, done-for-you service. You get a compliant program without spending weeks on regulatory research or carrier paperwork. The concrete difference is that your consent forms, privacy policy, and campaign registration are aligned before you send, which is the step most small operators skip and later pay for.
Visit Rooted Up's services page to see the monthly plans and schedule a conversation about building your SMS program the right way from the start.
Sources
The sources below are the primary regulatory and practical references for U.S. SMS compliance. Bookmark the regulatory ones and check them when rules change.
- Federal Register, Volume 89 Issue 44 (Tuesday, March 5, 2024)
- 47 CFR § 64.1200 — Delivery restrictions
- US Business SMS: TCPA, 10DLC, and Operational Messaging Guide — Telerivet
- Beyond TCPA compliance: Why CTIA messaging principles matter — Holland & Knight
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
