- SMS marketing is legal in the US, but the Telephone Consumer Protection Act (TCPA) requires documented prior express written consent before you send a single promotional message.
- 10DLC (10-digit long code) is a carrier registration system, not a law. You must register your brand and campaigns through it or your messages get filtered at the carrier level before they ever reach a phone.
- The compliance checklist is finite: get consent, honor opt-outs within 10 business days, identify yourself in every message, and register your sending number.
- Most established SMS platforms handle the mechanical parts of compliance, but they cannot create the consent records that protect you from TCPA litigation.
- A single TCPA violation carries statutory damages of $500 to $1,500 per text message, which makes consent documentation the highest-ROI line item in your SMS program.
SMS marketing is legal in the United States when senders obtain prior express written consent, register their sending numbers through the 10DLC system, identify their brand in every message, and honor opt-out requests. TCPA SMS compliance governs consent requirements and penalty exposure. The 10DLC system governs deliverability. Getting both right is a documented process, not a legal minefield.
The fear is understandable. TCPA class actions have generated eight- and nine-figure settlements, and the plaintiff’s bar actively monitors commercial texting. But the brands that get sued are not the ones with good compliance programs. They are the ones that bought lists, imported contacts without consent documentation, or skipped registration and hoped carriers would not notice. If you have a real opt-in flow and a registered sending number, the legal exposure shrinks to manageable.
This article walks through what the TCPA actually requires, how 10DLC works mechanically, and what your SMS tool should be doing on your behalf. It is written for marketing operators making stack decisions, not for lawyers. It is not legal advice, and you should consult qualified legal counsel before making compliance decisions for your specific program.
What Is the TCPA and What Does It Actually Require for SMS?
The Telephone Consumer Protection Act was passed in 1991 and has been interpreted and expanded by the FCC multiple times since. For SMS marketing, the operative requirement is prior express written consent: a consumer must affirmatively agree to receive promotional text messages from your brand before you send them. A checkbox buried in terms of service does not satisfy this. A pre-checked box definitely does not.
The FCC’s 2012 rules tightened the consent standard substantially. Written consent can be digital, but the consumer must take a clear affirmative action specifically agreeing to receive autodialed or pre-recorded texts for marketing purposes. The agreement must name your company. It must describe the nature of the messages. It cannot be a condition of purchasing a product.
Transactional messages, which include order confirmations, shipping alerts, appointment reminders, and one-time passcodes, have a lower consent bar. They fall under “prior express consent” rather than “prior express written consent.” In practice, a purchase or account creation generally establishes that consent. Promotional messages require the stricter standard.
What counts as prior express written consent?
A compliant opt-in has three components. First, the consumer submits their phone number. Second, they check an unchecked box (or take some other affirmative action) that is specifically about SMS marketing, not buried in a general terms acceptance. Third, the language near that checkbox names your company and describes what messages they will receive.
Example compliant disclosure language: “By checking this box, you agree to receive promotional text messages from [Brand Name] at the number provided. Message and data rates may apply. Reply STOP to opt out. Reply HELP for help.” That is the template the FCC’s guidance and TCPA case law have validated repeatedly.
What are the TCPA’s damages for SMS violations?
The TCPA allows statutory damages of $500 per violation, which means $500 per nonconsensual text message. Willful violations go to $1,500 per message. These amounts can be trebled by a court finding willfulness. The per-message structure is why class actions are so damaging: a single campaign sent to 100,000 non-consenting recipients creates $50 million in potential statutory exposure before any multiplier.
How Did the FCC’s 2024 One-to-One Consent Rule Change Things?
In December 2023, the FCC adopted a rule requiring one-to-one consent, effective January 2025. Before this rule, a consumer could theoretically consent to receive messages from multiple marketing partners through a single opt-in on a lead-generation landing page. That practice is now prohibited.
Under the one-to-one consent rule, each brand that wants to send marketing texts to a consumer must obtain its own independent consent. Purchasing a lead list from a third-party aggregator and texting those leads is no longer a defensible practice, even if the aggregator claims those consumers opted in to receive “marketing messages from our partners.” The consent must be specific to your brand.
This rule primarily closed a loophole used heavily in insurance, mortgage, and home services lead generation. For brands running their own opt-in flows, it changes very little. The takeaway for marketing operators: consent records must be first-party, documented, and brand-specific.
What Is 10DLC and Why Do Carriers Require It?
10DLC, or 10-digit long code, is the carrier-level framework that US mobile carriers including AT&T, T-Mobile, and Verizon implemented to regulate commercial SMS traffic on standard 10-digit phone numbers. It replaced a system where businesses could send high volumes of messages through local-looking numbers with no vetting whatsoever.
Before 10DLC, this lack of vetting created a spam and fraud problem. Carriers responded by building a registration and trust-scoring system through an industry body called CTIA and a central registry operated by The Campaign Registry (TCR). Brands now register their company identity with TCR, and they register each distinct messaging use case as a “campaign” with associated sample messages and opt-in flow descriptions.
Once registered and approved, your messages carry a trust signal that tells carrier filtering systems to let them through. Without registration, carriers apply aggressive filtering that can block or throttle a significant percentage of messages. This is a deliverability problem, not just a compliance one.
How does the 10DLC registration process work?
Registration happens in two steps. First, you register your brand with TCR, which involves providing your company’s legal name, EIN (for US entities), physical address, and the type of entity you are. TCR performs an identity verification check. Second, you register each campaign, which is a use case category such as “marketing,” “customer care,” or “two-factor authentication,” along with sample message content and a description of your opt-in flow.
Your SMS platform or aggregator typically submits these registrations on your behalf through their TCR connectivity. The fees are modest, running approximately $4 to register a brand and $10 to $15 per campaign per month depending on the carrier surcharges your provider passes through. Approval timelines have shortened significantly from the early days of 10DLC and now typically take days rather than weeks for standard campaigns.
Shortcodes versus long codes versus toll-free numbers
10DLC applies specifically to standard 10-digit local phone numbers. Dedicated shortcodes, the 5- or 6-digit numbers that major brands often use, have their own vetting process directly with carriers and have always had higher throughput. Toll-free numbers (1-8XX) have a separate verification process through carriers and TCR. If you are starting a new SMS program, most SMS platforms will push you toward a 10DLC local number or a verified toll-free number because shortcode provisioning is slower and more expensive.
If you are considering RCS business messaging as an alternative channel alongside SMS, the best RCS business messaging platforms for US senders operate under a different verification framework entirely, though consent requirements under the TCPA still apply.
What Is the AboutMartech SMS Compliance Checklist?
Most compliance guides list rules in the abstract. What operators need is a concrete sequence to run before and after launching a program. The following framework, the AboutMartech SMS Compliance Checklist, covers the five layers that protect a program from both carrier filtering and TCPA liability.
Layer 1: Consent capture
Every contact in your SMS list must have a documented, brand-specific opt-in. The opt-in record should store the date and time, the IP address or session identifier where consent was given, the exact disclosure language the consumer saw, and the phone number they submitted. Store these records permanently. TCPA litigation can emerge years after a campaign.
Layer 2: Number registration
Register your brand and each campaign use case in TCR before sending. If your SMS platform handles this registration, confirm in writing that they have submitted and received approval. Do not assume registration happened. Ask for the TCR campaign ID.
Layer 3: Message-level compliance
Every promotional message must identify your brand by name. Your first message to any new subscriber must include opt-out instructions (“Reply STOP to unsubscribe”). Every message must include opt-out instructions or a reminder to reply STOP, depending on your platform’s configuration and your message cadence. Messages must also include a response to HELP requests, typically a customer support contact.
Layer 4: Opt-out processing
When someone replies STOP, CANCEL, UNSUBSCRIBE, END, or QUIT, you are legally required to stop sending within 10 business days. All reputable SMS platforms process these automatically. The risk is in programs that build custom integrations or route messages through less structured tools, where suppression lists may not sync properly.
Layer 5: Sending time and frequency
The TCPA does not set specific quiet hours, but the FTC and many state laws restrict contact to reasonable hours. CTIA guidelines recommend sending only between 8 a.m. and 9 p.m. in the recipient’s local time zone. Your messaging use case registration with TCR also specifies expected message frequency, and staying within those parameters matters for maintaining your trust score.
Which State Laws Add Requirements Beyond Federal TCPA?
Florida, Oklahoma, and Washington have passed state-level texting statutes that, in some cases, create additional requirements or broader definitions of autodialing than the federal TCPA. California’s CCPA intersects with SMS compliance around data handling and consumer deletion rights for phone numbers stored in your systems.
Florida’s FTSA (Florida Telephone Solicitation Act), amended in 2021, has been the most aggressive: it created a private right of action for violations with per-text damages and a broader definition of automated texting that can capture marketing platforms the federal TCPA might not reach. If a meaningful portion of your list is Florida residents, this statute deserves specific attention from your legal team.
If your SMS program feeds data from a CDP or warehouse, how you store and process consent records also intersects with data privacy law. The best CDPs for B2B teams now include consent management features specifically for this reason.
What Should Your SMS Platform Be Handling Automatically?
The compliance pieces that a good SMS platform automates include: automatic opt-out processing on STOP keywords, sending-time guardrails based on subscriber time zone, 10DLC registration submission and management, automatic HELP response messages, and suppression list management across campaigns. These are table stakes at this point, not differentiators.
What no platform can do for you: create consent records retroactively, clean up a purchased list, or protect you from liability for contacts you added without proper documentation. The tool is only as safe as the data you put into it.
Platforms built specifically for SMS marketing, like Attentive, Postscript, Klaviyo, and Yotpo SMS, have built compliance infrastructure that general-purpose email tools may lack. If you are running SMS programs through a CRM or marketing automation platform as an add-on, verify that its 10DLC registration and keyword suppression features are actually configured, not just technically available. For a ranked comparison of SMS tools by use case, the best SMS marketing apps for Shopify stores covers the leading options for ecommerce programs, and for smaller programs, the best SMS marketing tools for small business budgets breaks down cost-effective configurations.
A Worked Scenario: Where Compliance Actually Breaks Down
Consider a DTC brand with 40,000 email subscribers. They decide to add SMS. Someone on the team exports the email list, uploads it to an SMS platform, and fires a welcome campaign. This is a TCPA violation at scale, regardless of the opt-in language those subscribers agreed to when they provided their email address. Email consent does not transfer to SMS. Those 40,000 people never consented to receive texts from this brand.
The right path: build an SMS opt-in flow, typically a popup on the site, a checkout field, or a keyword-based opt-in campaign (“Text DEALS to 12345”). Grow the SMS list independently. Some brands run an email campaign to their existing list inviting subscribers to opt into SMS, which is compliant because you are not texting anyone who has not yet consented.
That scenario is the obvious failure mode. The subtler ones are harder to catch in advance. A common enforcement pattern involves brands that do run a compliant opt-in flow but then import a legacy segment from a CRM migration or data warehouse sync without re-validating consent records. The contacts look legitimate inside the SMS platform because they have phone numbers and email addresses attached. What is missing is the documented TCPA-compliant opt-in record from the SMS-specific flow. If a plaintiff’s attorney subpoenas consent records, a CRM entry with no timestamp, IP address, or disclosure language captured against it will not hold up. Programs that centralize subscriber data through a CDP or warehouse should confirm that their data pipelines are carrying consent metadata, not just contact fields, the best warehouse-native CDPs increasingly support consent fields as a standard data model, precisely because of this gap.
A second common breakdown: brands that correctly configure STOP processing in their primary SMS platform but also send transactional messages through a separate provider (often their ESP or order management system). A subscriber opts out of marketing texts. The suppression updates in the SMS marketing tool. The transactional provider never receives the signal. Three days later, a shipping notification goes out. Depending on the message content and state of residence of the recipient, that can be a TCPA violation even if the message is transactional in intent, because the consumer has expressed a desire to stop receiving texts. Suppression list synchronization across all sending tools in the stack is not optional, it is where multi-vendor SMS programs fail compliance audits.
The brands in TCPA litigation are almost always in the “we had their email,” “we migrated from a legacy CRM,” or “suppression didn’t sync” category. The consent gap and the suppression gap are where the real exposure lives, not in obvious bulk-list blunders.
Frequently Asked Questions About SMS Marketing Compliance
Is SMS marketing legal in the US?
Yes, SMS marketing is legal in the United States. The TCPA requires that you obtain prior express written consent from each recipient before sending promotional text messages, register your sending number through the 10DLC system, include your brand name and opt-out instructions in every message, and honor opt-out requests within 10 business days. Compliance is a defined process. The legal risk comes from skipping consent documentation or buying contact lists, not from running a properly structured SMS program.
What is TCPA compliance for SMS?
TCPA compliance for SMS means collecting documented prior express written consent before texting any consumer for marketing purposes, maintaining those consent records indefinitely, processing opt-outs within 10 business days, identifying your brand in every message, and only sending messages within reasonable hours. Violations carry statutory damages of $500 to $1,500 per text message, which means a single campaign sent to an unconsented list can create seven- or eight-figure liability exposure in a class action.
What is 10DLC and do I need it?
10DLC (10-digit long code) is a carrier registration system that allows businesses to send SMS at commercial volumes through standard 10-digit phone numbers. You register your brand and your messaging use cases with The Campaign Registry, and carriers use that registration to score your messages as legitimate. Without 10DLC registration, carriers will filter or block a portion of your messages. Any US business sending commercial SMS at scale through a local 10-digit number needs it. Your SMS platform typically manages the submission process, but you should confirm registration is complete before sending.
Does buying a lead list violate the TCPA?
In practice, texting a purchased lead list almost always violates the TCPA under current FCC rules. The FCC’s one-to-one consent rule, effective January 2025, requires that consent be specific to your brand. A third-party lead aggregator cannot grant you permission to text their opt-in list. Each consumer must have independently consented to receive text messages specifically from your company. If you cannot produce a first-party consent record for a number, you should not text it.
What happens if someone opts out and I keep texting them?
Continuing to send messages after a consumer replies STOP is a TCPA violation. Each subsequent message creates independent statutory damages of $500 to $1,500. Courts have found these violations to be willful, which triggers the trebling provision and can result in $1,500 per message in damages. Reputable SMS platforms process STOP replies automatically and suppress the number across all campaigns. The risk is higher in custom-built integrations where suppression lists may not update in real time across all sending tools in your stack.
What is the difference between express consent and express written consent for SMS?
Express consent allows you to send informational or transactional messages, such as order confirmations, appointment reminders, and shipping updates. Express written consent is the higher standard required for promotional or marketing messages. Written consent does not have to be on paper. Digital opt-in flows with an affirmative, unchecked checkbox satisfy the requirement. The key elements are: an affirmative action by the consumer, disclosure language naming your brand, a description of message type, and notice that consent is not required to make a purchase.
How does 10DLC registration affect deliverability?
Unregistered 10-digit numbers sending commercial SMS volumes are subject to carrier filtering that can block a substantial portion of messages before they reach the recipient. Registration with TCR gives your messages a trust score that signals to carrier systems that your traffic is legitimate. Higher trust scores correlate with lower filtering rates. Your message content, opt-out rate, and message frequency all feed into ongoing trust scoring after registration, which means a compliant sending practice is also a deliverability practice.
Are there state laws stricter than the TCPA for SMS marketing?
Yes. Florida’s FTSA uses a broader definition of automated texting than federal law and creates a private right of action with per-text damages. Oklahoma and Washington have also passed state texting statutes with their own requirements. California’s CCPA affects how you store and process consumer phone numbers and consent records. If your list includes recipients in these states, those state laws apply to those recipients even if your federal TCPA compliance is clean. Legal counsel familiar with the relevant state statutes should review programs with significant exposure in these states.
The Compliance Baseline Is Higher Than Most Marketers Think
The common assumption is that SMS compliance is a legal problem to hand off to counsel once and forget. It is not. Consent documentation is a data infrastructure problem, 10DLC registration is an ops problem, and suppression list management is a platform configuration problem. Each layer has a different owner in most marketing organizations, and the gaps between those owners are where violations happen.
The good news is that the checklist is genuinely finite. If you have first-party opt-ins with documented consent language, a registered sending number, automatic STOP processing, and messages that identify your brand, your exposure is minimal. The tools have gotten good enough that the mechanical compliance tasks are largely automated. What the tools cannot automate is the decision to add unverified contacts to a list, and that decision still creates all the exposure.
For operators ready to evaluate which SMS platforms handle compliance infrastructure most reliably, and which add CRM integration, flows, and segmentation on top of it, the Attentive vs Postscript comparison covers the two dominant Shopify-focused options in detail. SMS compliance is the floor. The question after that is which tool builds the best program on top of it.
This article is for informational purposes only and does not constitute legal advice. SMS compliance requirements involve federal and state law that changes over time. Consult qualified legal counsel for guidance specific to your program and jurisdiction.





