TCPA Compliance for SMS: A Practical U.S. Playbook

August 15, 2026 · Rooted Up

TCPA Compliance for SMS: A Practical U.S. Playbook

To run lawful SMS marketing in the United States, you need prior express written consent for promotional messages, a working opt-out system that honors revocations within the FCC's 10-business-day window, carrier registration through 10DLC for long-code traffic, and timestamped records proving all of the above. That is the short version. The longer version is what this guide covers.

Before you send a single campaign, check these four items:

The TCPA (Telephone Consumer Protection Act) is the federal statute. The FCC enforces it and issues orders that refine how it applies to modern messaging. The CTIA sets carrier-level standards that operate alongside the law. You need to satisfy all three layers.


Key Takeaways

TCPA-compliant SMS marketing requires prior express written consent, real-time opt-out processing, 10DLC carrier registration, and timestamped consent records that can survive litigation discovery.

Point Details
Consent standard for marketing Promotional texts require prior express written consent (PEWC); transactional messages require a lower prior express consent threshold.
Opt-out processing window Honor revocations by any reasonable method within 10 business days; process in-band STOP replies immediately.
Carrier registration Register brand and campaign with The Campaign Registry (10DLC) before sending A2P traffic on long codes; unregistered traffic is blocked.
Recordkeeping fields Store timestamp, disclosure text, channel, IP, campaign ID, and revocation records; retain for the relationship duration plus 4 years.
Rooted Up implementation Rooted Up designs consent flows, handles 10DLC registration, and configures suppression and monitoring as part of monthly marketing plans.

Table of Contents

What does the TCPA actually cover for SMS texts?

The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, treats text messages as "calls" for regulatory purposes when they are sent using an automatic telephone dialing system (ATDS) or contain a prerecorded/artificial voice component. That classification is what pulls SMS marketing squarely into TCPA territory.

The FCC's 2024 Report and Order went further than prior guidance. It codified how revocation must work, established the mechanics of the one-time confirmation message, and reinforced that the National Do-Not-Call Registry protections extend to text messages. A separate 2024 order required terminating mobile wireless providers to block illegal texts upon Commission notification, which means carriers now have a regulatory obligation to filter traffic, not just a business incentive.

Three distinct layers govern your SMS program:

The practical upshot: TCPA is the legal floor, and CTIA/carrier rules are the operational ceiling. You need to clear both.


Who is actually responsible for TCPA compliance?

Primary liability under the TCPA attaches to the party that initiates the message. If your brand's name is in the text, you are the initiating party regardless of which platform or vendor sent it on your behalf. That said, vendors, platforms, and lead buyers can share exposure when they participate in the consent chain or control the sending infrastructure.

Key liability assignments to understand:

Before activating any vendor or platform, require the following in writing:

Pro Tip: Write a short vendor compliance questionnaire and require it before onboarding any SMS platform or lead source. Ask specifically: How do you handle STOP replies? How quickly are opt-outs propagated to suppression lists? Do you support 10DLC registration? The answers tell you more than any contract clause.


Transactional vs. promotional texts: why the distinction matters

The consent standard you need depends entirely on the primary purpose of the message. Get this classification wrong and you may be sending promotional content under a transactional consent standard, which is one of the most common TCPA exposure points.

The primary purpose test works like this:

  1. Promotional (marketing) messages: Any message whose primary purpose is to advertise or promote a product, service, or commercial opportunity. These require prior express written consent (PEWC), the highest consent standard under the TCPA.
  2. Transactional or informational messages: Messages that relay information the recipient requested or that relate to an existing transaction (appointment reminders, order confirmations, account alerts). These require prior express consent, a lower threshold that does not need to be in writing.
  3. Emergency messages: No consent required, but the emergency exception is narrow and should not be stretched.

Short examples mapped to consent standard:

The operational warning here is real: do not add promotional language to a transactional thread. A single upsell sentence in an order confirmation can reclassify the entire message as promotional, retroactively exposing every prior message in that thread to PEWC scrutiny. Keep the threads separate.


Core TCPA requirements every SMS marketer must meet

These are the non-negotiable requirements. Think of this as the minimum viable compliance set for any U.S. SMS program.

Prior express written consent for marketing messages. The consent must be in writing (electronic signatures qualify), voluntary, and obtained before the first promotional message. The disclosure must name the sender and describe the message type.

Checklist of core TCPA SMS marketing requirements

Sender identification. Every message must identify who is sending it. 47 CFR § 64.1200 requires that the sender's identity be clear. Do not rely on the short code or number alone.

Opt-out language in every message. Include a clear opt-out instruction in every marketing message. "Reply STOP to unsubscribe" is the standard. Variations like "Text STOP to cancel" are acceptable, but the instruction must be present.

Quiet hours. The FCC prohibits telemarketing calls and texts outside established quiet hours in the recipient's local time zone. This is not a soft guideline. Enforce it at the platform level using time-zone detection, not just the sender's time zone.

Opt-out processing timeline. The FCC requires revocations to be honored within a reasonable time not to exceed 10 business days. For in-band STOP replies, process them immediately.

The one-time confirmation message is a specific allowance, not a loophole. It must be non-promotional. Using it to pitch a product or offer a discount after someone opts out is a violation.

Pro Tip: Build quiet-hours enforcement at the platform level, not in your campaign scheduling. If a message is queued for 8:45 PM and delivery is delayed, a platform-level time-zone check prevents it from landing at 9:05 PM in a recipient's local time. Scheduling alone is not enough.


How to capture valid prior express written consent

PEWC has four required elements. Miss any one of them and the consent may not hold up in litigation or regulatory review.

Sample PEWC language for a web form:

By checking this box, I agree to receive recurring promotional text messages from [Brand Name] at the phone number provided. Message and data rates may apply. Message frequency varies. Reply STOP to unsubscribe. Reply HELP for help. View our [Privacy Policy] and [Terms of Service].

Sample double-opt-in confirmation message:

[Brand Name]: You requested to join our SMS list. Reply YES to confirm. Reply STOP to cancel. Msg & data rates may apply.

Steps for a compliant consent capture flow:

  1. Display the PEWC disclosure adjacent to the phone number field, not below the submit button.
  2. Use an unchecked checkbox for SMS consent. Never pre-check it.
  3. Log the timestamp, IP address, page URL, form version, and the exact disclosure text shown at the time of consent.
  4. Send a double-opt-in confirmation and log the reply before adding the number to your active list.
  5. Tie the consent record to a campaign ID so you can demonstrate which program the subscriber joined.

Pro Tip: Version-control your consent language. If you update the disclosure text, existing subscribers consented to the prior version. Depending on the change, you may need to re-consent them. Keep a dated archive of every version of your consent form.


How to implement opt-out and revocation correctly

Accept opt-outs by any reasonable method. That phrase comes directly from the FCC's 2024 rulemaking and it is broader than most marketers realize. A subscriber who emails your support team asking to stop receiving texts has submitted a valid revocation request. So has someone who tells a customer service rep on a phone call.

The operational flow:

  1. Receive the revocation request via any channel (STOP reply, email, chat, phone, web form).
  2. Log the request with a timestamp, the channel it arrived through, and the agent or system that received it.
  3. Update the suppression list in your SMS platform immediately for in-band STOP replies. For off-channel requests, complete suppression within 10 business days.
  4. Send one non-promotional confirmation text if the subscriber opted out via STOP reply. Example: "You have been unsubscribed from [Brand Name] alerts. No further messages will be sent. Reply START to re-subscribe."
  5. Persist the audit record indefinitely. A suppressed number that gets reactivated because a record was deleted is a litigation risk.

Pro Tip: Build a real-time integration between your customer support platform (Zendesk, Intercom, or similar) and your SMS suppression list. When a support agent logs an opt-out request, it should trigger an automatic suppression update, not a manual ticket. The 10-business-day window sounds generous until you factor in weekends, agent errors, and ticket backlogs.

Edge cases to handle explicitly:


What to store and how to build an auditable consent record

Retain consent records for as long as you send to that subscriber, plus a reasonable litigation hold period afterward. The FCC does not specify a minimum retention period in the TCPA rules, but plaintiffs' attorneys and courts expect records to survive at least four years given the TCPA's statute of limitations.

Office desk with consent record folder and closed laptop

Pro Tip: Tools like ActiveProspect's TrustedForm create cryptographically signed consent certificates that capture a session replay of the consent form, the IP, the timestamp, and the exact disclosure text. These certificates are designed to survive discovery. If you are running high-volume campaigns or buying leads, this type of third-party consent certification is worth the cost.


Third-party leads, lead generators, and one-to-one consent

Treat every third-party lead as high risk until proven otherwise. When you buy or receive a lead, you are inheriting the consent chain that lead generator built, and you have no direct visibility into how that consent was obtained.

The one-to-one consent rule has had a complicated history. The FCC proposed a rule requiring that consent be specific to a single named company rather than a broad category of "marketing partners." An appeals court vacated that rule, but the underlying regulatory intent has not disappeared. Marketers who relied on broad partner-consent language to cover dozens of brands in a single checkbox are still operating in a legally uncertain environment.

Practical steps for managing third-party lead consent:

  1. Require the lead provider to supply the consent record for every lead: timestamp, disclosure text, IP address, and the URL where consent was captured.
  2. Audit a sample of records before activating a new lead source. Verify that the disclosure named your brand specifically, not just a category of partners.
  3. Capture fresh consent where possible. If the lead's consent record is weak or the disclosure did not name you, send a consent-request message before sending any promotional content.
  4. Document the chain of transfer. Keep records showing when you received the lead, from whom, and what consent documentation accompanied it.
  5. Suppress against the DNC registry before any outreach. The FCC's 2024 order confirmed that DNC protections extend to text messages.

Contract checklist for lead providers:


Technical controls and sender registration you need in place

Register your brand and campaign with The Campaign Registry (TCR) for any A2P traffic sent via 10-digit long codes. 10DLC registration became mandatory for this traffic type, and carriers have been blocking unregistered campaigns. This is not a compliance checkbox you can defer.

Sender type selection matters for your use case:

Technical controls to implement before launch:

Vendor feature checklist. Require these from any SMS platform you use:

Pro Tip: Legal practitioners at Holland & Knight note that aligning your privacy policy and consent disclosures with your campaign design before attempting TCR registration reduces the risk of rejection. Carriers commonly reject registrations where the privacy policy does not explicitly describe how mobile data is used or shared. Fix the policy first, then register.


What TCPA enforcement actually costs and how to reduce your exposure

Statutory damages under the TCPA run from $500 to $1,500 per message. There is no statutory aggregate cap. A class action covering many recipients can produce significant settlement exposure potentially in the millions before a single trial. Private class actions are the primary enforcement vehicle, not FCC fines, which means the plaintiff's bar drives most of the risk.

Common claim triggers and their fixes:

Practical mitigation steps:


Your pre-launch compliance checklist and message templates

Work through this sequentially. Do not skip steps because a campaign is time-sensitive.

Pre-launch checklist:

  1. Confirm consent type required for each message category (PEWC for promotional, prior express consent for transactional).
  2. Draft and legal-review your PEWC disclosure language. Confirm it names your brand, describes message type and frequency, includes cost disclosure, and links to your privacy policy.
  3. Verify your privacy policy explicitly describes how mobile/SMS data is collected, used, and shared.
  4. Register your brand and campaign with TCR (10DLC) or complete toll-free verification.
  5. Configure suppression list integration in your SMS platform. Test that a STOP reply removes the number from the active list within 60 seconds.
  6. Enable time-zone quiet-hours enforcement at the platform level.
  7. Build or import your consent records into a structured data store with all required fields (see Section 8).
  8. Run a suppression check against the DNC registry and your internal opt-out list before the first send.
  9. Send a test batch of 10 to 20 internal numbers. Verify delivery, opt-out processing, and confirmation message content.
  10. Document the test results and store them with the campaign record.

Sample PEWC consent text for a web form:

By providing your phone number and checking this box, you agree to receive recurring automated promotional text messages from [Brand Name] at the number provided. Consent is not a condition of purchase. Message and data rates may apply. Message frequency varies. Text STOP to unsubscribe, HELP for help. [Privacy Policy] | [Terms of Service]

Sample double-opt-in confirmation:

[Brand Name] SMS: We received your request to join our list. Reply YES to confirm. Reply STOP to cancel. Msg & data rates may apply. Up to [X] msgs/month.

Sample opt-out confirmation:

[Brand Name]: You've been unsubscribed. No further messages will be sent. Reply START to re-subscribe or visit [URL] for help.

QA test plan before go-live:

Pro Tip: Run your QA test plan against a staging environment that mirrors production. A suppression check that works in staging but fails in production because of an environment variable difference has caused real violations. Treat the test plan as a release gate, not a formality.


How Rooted Up builds compliant SMS programs for solo professionals

For solo professionals and small business owners who want to use SMS marketing without building a compliance infrastructure from scratch, Rooted Up handles the operational setup so you can focus on your clients.

The practical steps Rooted Up follows when building a compliant SMS program:

Readers who want professional implementation rather than a DIY build can review Rooted Up's service offerings and monthly plans at Rootedup.


The part most small businesses get wrong

Small operators consistently make two errors that create outsized TCPA risk. The first is treating consent as a one-time setup task. They build a form, add a checkbox, and assume they are covered indefinitely. But consent is tied to a specific disclosure at a specific point in time. When the form changes, the message type expands, or a new lead source is added, the consent chain needs to be re-evaluated. The second error is assuming the SMS platform handles compliance automatically. Platforms provide tools; they do not make compliance decisions for you. A platform that processes STOP replies correctly does not protect you if your consent form was defective from the start.

On the technical side, outsource the platform configuration and 10DLC registration to someone who has done it before. The TCR registration process has specific requirements around privacy policy language, and a rejected registration delays your entire program. Keep the consent records in-house or with a certified consent-capture provider like ActiveProspect. Those records are your legal defense, and you want direct access to them.

State-level variability is real. Florida, Oklahoma, and Washington have their own mini-TCPA statutes with different consent thresholds and damages structures. If your list includes recipients in those states, get counsel to review your program against state law, not just the federal TCPA.


Rooted Up handles the compliance setup so you can focus on your clients

Running a TCPA-compliant SMS program requires consent flows, carrier registration, suppression logic, and audit trails working together before a single message goes out. For solo professionals and small business owners, building that infrastructure while running a practice is not realistic.

Rooted Up

Rooted Up's monthly marketing plans include consent flow design, 10DLC registration support, platform configuration, and ongoing monitoring as part of a structured, done-for-you service. You get a compliant program without spending weeks on regulatory research or carrier paperwork. The concrete difference is that your consent forms, privacy policy, and campaign registration are aligned before you send, which is the step most small operators skip and later pay for.

Visit Rooted Up's services page to see the monthly plans and schedule a conversation about building your SMS program the right way from the start.


Sources

The sources below are the primary regulatory and practical references for U.S. SMS compliance. Bookmark the regulatory ones and check them when rules change.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Recommended

Marketing handled, so you can do the work you love.

See our plans