TCPA Compliance for SMS: The U.S. Marketer's Guide

Astreaux Team

5 min read

TCPA Compliance for SMS: The U.S. Marketer’s Guide

Every marketing text you send without prior express written consent is a potential liability per message with no statutory cap on aggregate damages. TCPA compliance for SMS comes down to four non-negotiable obligations: collect valid written consent before sending marketing texts, honor opt-outs by any reasonable method within the required window, register your campaigns through A2P 10DLC, and keep audit-ready records of every consent event.

Before your next campaign goes out, confirm these steps are complete:

  • Collect prior express written consent with a clear, unchecked checkbox and required disclosure language before sending any promotional text.

  • Register your brand and campaigns in The Campaign Registry (TCR) for A2P 10DLC. Carriers have been blocking unregistered traffic since early 2025.

  • Honor STOP and all reasonable opt-out requests in real time and suppress across every system.

  • Scrub your list against the National Do-Not-Call Registry before each send.

  • Log consent metadata (timestamp, source URL, IP address, disclosure text shown) and retain it for the life of the relationship plus a litigation buffer.

  • Restrict send times to 8 AM–9 PM in the recipient’s local time zone.

  • Consult qualified legal counsel before launching new programs or entering new states.

The Federal Communications Commission (FCC), the CTIA (the wireless industry’s trade association), and the National Do-Not-Call Registry are the three authorities whose rules shape every compliant SMS program in the United States.

Key Takeaways

TCPA compliance for SMS requires prior express written consent for every marketing text, real-time opt-out processing across all systems, A2P 10DLC registration, and audit-ready consent records retained for at least four years plus the life of the relationship.

Point

Details

Written consent is mandatory

Every marketing SMS requires prior express written consent with six required disclosure elements before sending.

Damages are per message

Statutory damages run $500–$1,500 per non-consensual text, with no aggregate cap under 47 U.S.C. § 227.

A2P registration is a delivery gate

Carriers have blocked unregistered A2P 10DLC traffic since February 2025; register in TCR before any campaign sends.

Opt-outs must be multi-channel

Honor STOP keywords and all reasonable revocation methods; cross-system suppression must propagate in real time.

Astreaux automates key controls

Astreaux enforces real-time suppression, timestamped consent logging, and A2P-ready workflows across 7,000+ integrations.

This article provides general compliance information, not legal advice. Consult qualified legal counsel before launching new SMS programs or entering new states.

What does TCPA compliance for SMS actually require?

The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, treats text messages as “calls” for regulatory purposes. That single classification is what makes the statute so consequential for SMS marketers. The FCC enforces the TCPA and issues orders that expand or clarify its reach.

The FCC’s Second Report and Order, published in the Federal Register in January 2024, made two changes that every SMS marketer must understand. First, it requires terminating mobile wireless providers to block texts from numbers identified by the Enforcement Bureau. Second, it codifies National Do-Not-Call Registry protections for text messages, closing a gap that some senders had tried to exploit. The Federal Register publication also tightened the definition of prior express written consent, limiting it to one identified seller under certain conditions.

Beyond the TCPA itself, a growing patchwork of state mini-TCPA laws adds stricter requirements in states like Florida, Texas, Oklahoma, Washington, and Maryland. State rules can impose lower damage thresholds, shorter quiet-hour windows, or per-message statutory damages that exceed the federal floor.

The CTIA operates at the industry level, setting messaging guidelines that carriers enforce through their own content policies and A2P 10DLC vetting. CTIA rules are not law, but violations get your campaigns blocked.

Layer

Authority

Enforcement mechanism

Damage exposure

Federal statute

TCPA (47 U.S.C. § 227)

Private class actions, FCC, state AGs

$500–$1,500 per message

FCC orders

Second Report and Order (2024)

Carrier blocking, FCC enforcement

Campaign suspension

State mini-TCPA

Florida FTSA, Texas SB 140, others

State AG, private right of action

Varies by state

Industry/carrier

CTIA, A2P 10DLC, TCR

Carrier filtering and blocking

Deliverability loss

Statutory damages under the TCPA run from several hundred to over a thousand dollars per non-consensual message, with no aggregate cap. A campaign sending 10,000 unconsented texts faces up to $15 million in exposure before a single class is certified.

How do you know which messages need written consent?

The consent level required depends on the message type. Promotional or telemarketing messages, meaning any text that encourages a purchase, promotes a product, or drives a commercial transaction, require prior express written consent. Purely informational or transactional messages (appointment reminders, order confirmations, two-factor authentication codes) require only prior express consent, a lower bar that can be met verbally or through a clear opt-in action.

Short examples that illustrate the line:

  • “Your appointment is confirmed for Tuesday at 2 PM.” — Transactional. Prior express consent is sufficient.

  • “Hi, it’s [Brand]. Your order shipped!” — Transactional. Prior express consent is sufficient.

  • “Flash sale: 20% off today only. Shop now: [link]” — Promotional. Prior express written consent required.

  • “We noticed you viewed [product]. Still interested?” — Promotional. Prior express written consent required.

The ATDS question adds another layer. If your platform has the capacity to dial or text from a database using automated software, it may qualify as an Automatic Telephone Dialing System (ATDS) under the TCPA, regardless of whether you actually use that capacity on a given send. The case law on ATDS definition remains contested after the Supreme Court’s 2021 ruling in Facebook, Inc. v. Duguid, but the practical advice from most compliance counsel is to treat any automated bulk-text system as an ATDS and obtain written consent accordingly.

Lead generators and comparison sites face an additional constraint from the 2024 FCC order: consent obtained through a lead-gen form must be tied to a specific, identified seller. A single consent checkbox that purports to cover dozens of unnamed partners does not satisfy the prior express written consent standard.

Decision flow for classifying a message:

  1. Does the text promote a product, service, or commercial transaction? → Yes: written consent required.

  2. Is it purely informational with no commercial call to action? → Prior express consent may suffice.

  3. Is it sent via automated software from a database? → Treat as ATDS; use written consent regardless of message type.

  4. Did consent come from a third-party lead generator? → Verify the consent names your brand specifically.

How to collect consent that will hold up in an audit

Valid prior express written consent for marketing SMS has six required elements. Miss any one of them and the consent is defective.

  • Clear and conspicuous disclosure of what the consumer is agreeing to, presented before they opt in.

  • Unchecked checkbox or equivalent affirmative action. Pre-checked boxes do not satisfy the written consent standard.

  • Sender identification: the specific brand or company name sending the texts.

  • Message frequency disclosure: “You will receive up to [X] messages per month” or “Message frequency varies.”

  • Not a condition of purchase: the opt-in cannot be required to complete a transaction.

  • HELP and STOP instructions and a link to your privacy policy and terms.

Acceptable collection methods include web form checkboxes, text-to-join keywords (where the consumer texts a keyword to a short code), point-of-sale sign-up sheets, and e-signatures. For e-signature collection, building an ESIGN-compliant disclosure into your consent flow ensures the electronic record meets the same legal standard as a handwritten signature.

Sample web form consent language:

Log the following alongside every consent event: source URL, timestamp in UTC, IP address, user agent string, exact disclosure text shown at the time of opt-in, method of opt-in, consent version number, and the campaign or brand identifier. This metadata is what you produce during discovery. Hunton Andrews Kurth’s guidance on consent documentation is the practical standard most compliance teams follow.

Pro Tip: Never rely on a single broad opt-in that covers multiple brands or product lines. If your consent form says “you may be contacted by our partners,” that language will not protect you when a partner sends a marketing text. Each brand needs its own named consent.

What counts as a valid opt-out, and how fast must you act?

The FCC’s position is that consumers may revoke consent by any reasonable method, not just by texting STOP. The per-se revocation keywords carriers and platforms recognize are: STOP, UNSUBSCRIBE, QUIT, CANCEL, END, and REVOKE. Your system must process these automatically and in real time.


Hands managing opt-out requests in workspace

Beyond keyword replies, you must also honor opt-outs submitted by email, through a web form, by phone call, or in writing. The practical standard for keyword opt-outs is immediate suppression. For non-keyword channels, the FCC allows up to 10 business days to process the revocation, but most compliance counsel recommend treating every opt-out as real-time regardless of channel.

Forcing consumers into a single revocation method is a documented compliance failure. Offering multiple opt-out paths (keyword reply, web form, email, customer service line) reduces both legal exposure and the friction that leads to complaints.

After processing an opt-out, send one confirmation message: “You have been unsubscribed from [Brand Name] texts. You will receive no further messages.” Do not send any additional marketing content after that confirmation. Cross-system suppression is critical: the opt-out must propagate to your CRM, your email platform, your SMS vendor, and any third-party tools that could trigger an outbound text.

For dispute resolution, your opt-out log (timestamp, channel, keyword or method used, confirmation sent) is your primary defense. Keep it exportable and tied to the original consent record.

What must every compliant SMS message contain?

Every marketing text must identify the sender by name. Recipients should never have to guess who is texting them. The message should include, or your program should have communicated in the welcome message, instructions for texting STOP to opt out and HELP for assistance.

CTIA’s SHAFT framework identifies the content categories carriers screen most aggressively: Sex, Hate, Alcohol, Firearms, and Tobacco. Campaigns touching any of these categories face additional carrier vetting and are more likely to be filtered or blocked. Beyond SHAFT, carriers also screen for content that resembles phishing, loan-sharking, or illegal drug promotion.

Required elements in every marketing SMS:

  • Sender name or brand identifier (e.g., “From: [Brand Name]”)

  • Clear commercial message

  • STOP instruction (at minimum in the welcome message; periodically in ongoing campaigns)

  • HELP instruction with a contact method

Content to avoid:

  • Deceptive subject lines or misleading claims

  • Shortened URLs that obscure the destination domain

  • Urgent language that mimics fraud alerts (“Your account has been compromised”)

  • Any SHAFT-category content without carrier pre-approval and age-gating

Industry best practices from Twilio recommend sending an opt-in confirmation message immediately after a consumer subscribes, which both confirms the subscription and delivers the required disclosures in a durable format.

Autodialers, reassigned numbers, and carrier blocking: the technical risks

An ATDS under the TCPA is a system with the capacity to store or produce telephone numbers using a random or sequential number generator and to dial those numbers automatically. After Facebook v. Duguid (2021), the Supreme Court narrowed the definition, but the practical exposure for bulk SMS senders remains real. If your platform pulls numbers from a database and sends texts without human intervention on each send, most compliance attorneys treat it as ATDS-adjacent and recommend written consent regardless.

Reassigned numbers are a separate risk. A number that belonged to a consenting subscriber may have been reassigned to a new person who never opted in. Texting that new person is a TCPA violation even if your records show valid consent. The FCC’s Second Report and Order created a waiver pathway tied to the Reassigned Numbers Database (RND), which carriers and senders can query to check whether a number has been reassigned since consent was obtained.

On the carrier side, A2P 10DLC registration is now the operational gate to deliverability for businesses sending automated texts from 10-digit long codes. Since February 2025, carriers have been blocking unregistered A2P 10DLC traffic outright. Registration happens through The Campaign Registry (TCR) and requires:

  • Brand registration (your company’s legal name, EIN, and contact details)

  • Campaign registration (use case, message samples, opt-in method description)

  • Carrier vetting and approval before traffic flows

Technical controls to reduce filtering and blocking:

  • Register every brand and campaign in TCR before sending.

  • Query the RND before each send cycle to catch reassigned numbers.

  • Maintain a clean suppression list and scrub against the National Do-Not-Call Registry.

  • Avoid URL shorteners that obscure domains; use branded short links or full URLs.

  • Monitor carrier filtering reports and act on any DNO (Do Not Originate) notices immediately.

For CRM-integrated SMS workflows, syncing suppression lists in real time across platforms is covered in the HubSpot SMS integration guide on the Astreaux blog.

What records do you need to keep, and for how long?

Your consent records are your litigation defense. If you cannot produce a timestamped, complete consent record for a plaintiff’s phone number, you are effectively starting from zero in a TCPA class action. Hunton Andrews Kurth recommends documenting consent with full metadata and maintaining audit-ready exports.

Required fields for each consent record:

  • Source URL where consent was collected

  • Timestamp in UTC

  • IP address of the consenting device

  • User agent string (browser/device identifier)

  • Exact disclosure text shown at the time of opt-in

  • Method of opt-in (checkbox, text-to-join, point-of-sale, e-signature)

  • Consent version number (so you can match the record to the exact disclosure language)

  • Campaign and brand identifiers

  • Opt-out timestamp and method, if applicable

Retain consent records for the life of the customer relationship plus at least four years, which aligns with the statute of limitations for TCPA claims. Keep opt-out records indefinitely; a consumer who opted out five years ago and receives a text today has a fresh claim.

When evaluating SMS vendors, ask these questions directly:

  • Can you export all consent metadata in a structured format (CSV, JSON) within 30 days of a legal hold request?

  • Do you store the exact disclosure text shown at opt-in, versioned by date?

  • How do you handle opt-out propagation across integrated platforms?

  • What is your data retention policy, and can it be extended contractually?

A vendor who cannot answer these questions clearly is a compliance liability.

What happens after a complaint, and how do you respond?

TCPA statutory damages are $500 per violation for standard violations and $1,500 per violation for willful or knowing violations. Each individual text message is a separate violation. Private plaintiffs can bring class actions, state attorneys general can pursue enforcement, and the FCC can initiate its own proceedings. There is no statutory aggregate cap.

When you receive a demand letter, a class action notice, or a carrier blocking notice, the immediate response sequence matters:

  1. Suspend the affected campaign within hours of receiving notice. Do not send another message in the implicated program until counsel clears it.

  2. Preserve all logs. Issue a litigation hold covering consent records, opt-out logs, campaign send logs, and vendor contracts. Deleting records after notice is spoliation.

  3. Notify legal counsel before responding to any demand or subpoena.

  4. Audit the opt-out records for the implicated number or numbers. Confirm whether a valid opt-out was received and when.

  5. Check A2P registration status. Confirm your brand and campaign are registered and approved in TCR.

  6. Review vendor contracts for indemnification clauses and notification obligations.

  7. Remediate the root cause before relaunching: fix the consent flow, update suppression lists, or retrain the team.

Practical mitigation before any complaint arrives: run quarterly audits of your consent records, test your STOP and HELP flows monthly, and verify suppression list synchronization across every platform that can trigger an outbound text.

Pre-send compliance checklist for every SMS campaign

Complete every item on this list before a new campaign goes live. Assign a named owner to each item so accountability is clear.

Registration and infrastructure:

  • [ ] Brand registered in The Campaign Registry (TCR)

  • [ ] Campaign registered and carrier-approved in TCR

  • [ ] Short code or 10DLC number provisioned and verified

Consent verification:

  • [ ] Consent records exist for every number on the send list

  • [ ] Consent records include all required metadata fields

  • [ ] Consent was obtained for this specific brand and use case (not a generic partner opt-in)

  • [ ] Consent records are exportable and backed up

List hygiene:

  • [ ] List scrubbed against the National Do-Not-Call Registry

  • [ ] Suppression list applied (all opt-outs removed)

  • [ ] RND check completed for numbers not recently verified

  • [ ] State-specific suppression rules applied (Florida, Texas, and other mini-TCPA states)

Message content:

  • [ ] Sender name included in message or welcome message

  • [ ] STOP instruction included (at minimum in welcome message)

  • [ ] HELP instruction included with a contact method

  • [ ] No SHAFT-category content without carrier pre-approval

  • [ ] No deceptive URLs or misleading claims

Timing and delivery:

  • [ ] Send times restricted to 8 AM–9 PM in recipient’s local time zone

  • [ ] Time-zone suppression logic verified in platform settings

Opt-out processing:

  • [ ] STOP keyword auto-response tested and confirmed

  • [ ] HELP keyword auto-response tested and confirmed

  • [ ] Non-keyword opt-out channels (email, web form) tested and synced

Pro Tip: Build this checklist into your campaign launch workflow as a required sign-off step, not an optional review. Platforms like Astreaux can automate several of these checks, including suppression sync and time-zone enforcement, so the checklist becomes a verification step rather than a manual process.

Run a full compliance audit quarterly. Assign the consent record audit to your legal or compliance team, the technical checks (STOP/HELP flows, suppression sync) to your engineering or operations team, and the content review to your marketing lead.


Pre-send compliance checklist for every SMS campaign — overview diagram

Copy-ready consent and opt-out templates

These templates include all required disclosure elements. Adapt the bracketed fields to your brand before deploying.

Web form checkbox opt-in

☐ By checking this box, I agree to receive recurring automated marketing text messages from [Brand Name] at the phone number provided above. Consent is not a condition of purchase. Message and data rates may apply. Message frequency: up to [X] messages per month. Reply STOP to unsubscribe or HELP for help. [Privacy Policy] | [Terms of Service]

Text-to-join opt-in (displayed at point of collection)

Text JOIN to [Short Code / 10DLC Number] to receive [offer/program description] from [Brand Name]. Message and data rates may apply. Up to [X] msgs/month. Reply STOP to cancel, HELP for info.

Welcome / confirmation message

STOP confirmation message

HELP reply

Implementation notes: Store each template version with a version number and effective date. When you update disclosure language (for example, changing message frequency), create a new version and log which version was shown to each subscriber at the time of opt-in. This versioning is what lets you match a consent record to the exact disclosure a plaintiff saw. For e-signature collection in the field, a mobile signature app can capture a timestamped, ESIGN-compliant record at point of sale.

How automation platforms reduce your TCPA risk

Manual compliance processes fail at scale. A single missed opt-out propagation across a CRM and an SMS platform is a potential $1,500 violation. Automation platforms that are built with compliance in mind address this by enforcing rules at the system level, not the human level.

The use cases where automation makes the biggest difference:

Real-time STOP processing. A compliant platform processes STOP keywords instantly and suppresses the number across every connected system before the next send cycle runs. No manual step, no delay.

Cross-system suppression sync. When your CRM, your SMS vendor, and your ad platform all share a suppression list in real time, an opt-out in one system propagates everywhere within seconds. Platforms with API hooks for suppression sync eliminate the gap that creates duplicate violations.

Timestamped consent logging. Automated consent capture on web forms, text-to-join flows, and point-of-sale integrations generates a complete metadata record without requiring a human to manually log anything. The record is created at the moment of opt-in.

A2P 10DLC integration. Platforms that integrate with The Campaign Registry can surface registration status and flag unregistered campaigns before they send.

Audit log exports. When a legal hold arrives, a compliant platform should produce a structured export of all consent and opt-out records within 30 days.

When evaluating any SMS vendor, ask specifically: Can you export consent metadata in CSV or JSON? Do you store the exact disclosure text shown at opt-in? How does opt-out propagation work across integrations? A vendor who cannot answer these questions with specifics is a compliance risk, not a compliance tool.

Why compliance-first SMS is a growth strategy, not a cost center

The conventional framing treats TCPA compliance as a legal tax on SMS marketing. That framing is wrong, and it leads teams to treat compliance as a checkbox rather than a system design principle.

Compliant SMS programs have higher deliverability because registered, well-maintained campaigns are less likely to be filtered by carriers. They have lower churn because subscribers who opted in clearly and can opt out easily are less likely to file complaints or block your number. And they have better conversion rates because the audience is genuinely interested, not coerced.

The teams that get into TCPA trouble are almost always the ones who inherited a list from a third party, used a single broad consent checkbox, or never tested their STOP flows. These are not sophisticated compliance failures. They are process failures that a well-designed system prevents automatically.

Training your marketing team on TCPA basics is not a legal department responsibility. It belongs in onboarding, in campaign launch checklists, and in quarterly reviews. Baking consent capture into your product flows, so that opt-in is a natural step in the user journey rather than an afterthought, is what separates programs that scale from programs that generate class actions.

Run a compliance drill once a quarter: send a test STOP keyword, verify suppression propagated across every system, pull a sample consent record and confirm all metadata fields are present, and check your A2P registration status. Fifteen minutes of testing prevents months of litigation.

Astreaux gives you compliance-first SMS automation from day one

Staying compliant while growing your SMS pipeline is exactly the problem Astreaux is built to solve. Rather than managing consent logs in spreadsheets, testing STOP flows manually, and hoping your CRM syncs with your SMS vendor, Astreaux automates the controls that matter most: real-time opt-out suppression across integrations, timestamped consent logging on every opt-in event, time-zone enforcement to keep sends within quiet-hour windows, and A2P-ready workflows that align with TCR registration requirements.


Astreaux

For service professionals, including contractors, mortgage brokers, and real estate agents, Astreaux’s conversational AI handles instant lead replies and appointment booking while keeping every interaction inside a compliant, logged workflow. The platform integrates with over 7,000 apps, so suppression lists stay synchronized without manual intervention. Whether you want to audit your current SMS program with Astreaux’s compliance checklist, run a pilot on a single campaign, or see the full platform in action, the next step is straightforward: start with Astreaux and build your SMS program on a foundation that holds up under scrutiny.

Sources

The following official and industry sources are the primary references for U.S. SMS compliance:

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

What is the difference between prior express consent and prior express written consent?

Prior express consent is an oral or written agreement to receive informational texts. Prior express written consent, required for marketing SMS, must be a signed, written agreement with specific disclosures including sender identity, frequency, and a statement that consent is not a condition of purchase.

Does the TCPA apply to transactional texts like appointment reminders?

Yes, the TCPA applies, but transactional texts only require prior express consent rather than the stricter written consent standard. If the message contains any promotional content, the written consent requirement applies.

How quickly must you honor a STOP request?

Keyword opt-outs (STOP, UNSUBSCRIBE, etc.) must be processed in real time. For non-keyword revocation channels like email or web forms, the FCC allows up to 10 business days, but processing immediately is the safer practice.

What happens if you text a number on the National Do-Not-Call Registry?

Texting a number registered on the DNC Registry without an established business relationship or prior express written consent is a TCPA violation. The FCC’s 2024 Second Report and Order explicitly codified DNC protections for text messages.

Does Astreaux support TCPA-compliant SMS workflows?

Astreaux automates real-time opt-out suppression, timestamped consent logging, time-zone enforcement, and A2P-ready campaign workflows, covering the core operational controls that TCPA compliance for SMS requires.