Hand reviewing SMS consent opt-in

Stop TCPA Risk: 7 Step SMS Consent Checklist for U.S. Marketers

Marketing SMS to U.S. wireless numbers requires prior express written consent that names your company specifically, not a lead-generator’s list of “partners.” Your opt-in copy needs to sit right next to the checkbox or submit button, and you need to keep proof of when, how, and where each consent happened. If you’re running campaigns built on shared or aggregated consents, pause them now and audit every collection point before your next send.


TL;DR:

  • Collect and prove separate, specific prior written consent for each seller, with clear disclosures displayed next to the opt-in checkbox or button.
  • Scrub your contact lists against the Do-Not-Call Registry and ensure your 10DLC registration matches your opt-in disclosures to prevent blocking or filtering.
  • Ensure opt-in disclosures include your business name, program details, message frequency, rates, and clear STOP/HELP instructions, placed immediately adjacent to collection controls.
  • Log all consent evidence, including timestamps, IP addresses, channel details, and the exact disclosure text, and retain records for at least four years for potential audits.
  • Use compliant platforms with integrated STOP/HELP handling and automatic logging to simplify legal adherence and reduce operational risk.

Table of Contents

The Telephone Consumer Protection Act sets the floor: marketing text messages sent to wireless numbers using an autodialer require prior express written consent from the recipient. That consent has to be specific. It names the seller, describes what the recipient is signing up for, and it has to exist before the first promotional message goes out, not after.

The FCC’s Second Report and Order rewrote how that consent works starting January 27, 2025. The rule now requires one-to-one consent. A recipient’s “yes” has to name a single seller, not a marketplace of potential advertisers hiding behind one checkbox. This closed a loophole that lead-generation sites had exploited for years: collect one signature, resell that “consent” to dozens of downstream marketers, and let each of them claim it satisfied TCPA. It doesn’t anymore. Consent also has to be logically and topically related to the context in which it was collected, meaning a fitness sign-up form can’t justify insurance texts six months later.

The Federal Register’s summary of these rules also codifies Do-Not-Call protections specifically for text messages, not just voice calls. If a number is on the National Do-Not-Call Registry, that status now carries direct weight for texting programs the same way it long has for telemarketing calls. Scrubbing your list against the DNC Registry before sending isn’t optional anymore.

Layered on top of the statute and the FCC’s rules is CTIA, the wireless industry’s trade association. CTIA doesn’t write law, but its Messaging Principles and Best Practices are what carriers actually use to police your program day to day. That distinction matters because a text can be technically TCPA compliant and still get blocked or filtered because it violates a CTIA-derived carrier policy.

Here’s what stacks on top of each other before you can legally send a marketing text:

  • TCPA: statutory requirement for prior express written consent naming the seller
  • FCC rules: enforcement mechanism, including the January 2025 one-to-one consent mandate
  • CTIA guidance: carrier-level standards for disclosures, opt-outs, and message cadence
  • 10DLC registration: the technical gate that verifies your brand and campaign before carriers will deliver at scale
  • DNC Registry: a separate suppression layer that now extends into texting

Miss any one of these and your messages either get blocked, filtered, or become evidence in a lawsuit.

“Clear and conspicuous” isn’t a vague legal phrase you can interpret loosely. Carrier reviewers and the FCC expect a specific set of elements displayed where the recipient can’t miss them, not buried in a footer or a linked terms page three clicks away.

Your opt-in point needs to show:

  • Sender identity: your actual business name, not a generic brand or app name
  • Program description: what kind of texts they’re signing up for (appointment reminders, promotions, alerts)
  • Message frequency: an honest estimate, such as “up to 4 messages per month”
  • Rate disclosure: the standard “Msg & data rates may apply” line
  • Privacy and terms links: visible, clickable, not requiring a scroll hunt
  • STOP/HELP instructions: stated in the opt-in text itself, not assumed

Placement matters as much as content. The AWS registration checklist is explicit that this text needs to sit adjacent to the actual collection control, meaning right next to the checkbox or submit button a person clicks. A link to a separate disclosures page satisfies nobody: not the FCC, not carriers reviewing your 10DLC application, and not a plaintiff’s attorney looking for a gap. Pre-checked boxes are a rejection waiting to happen, and so is disclosure text sized at 8 points in gray on white.

Here’s copy-ready language you can adapt:

“By checking this box, you agree to receive marketing text messages from [Business Name] at the number provided. Message frequency varies. Msg & data rates may apply. Reply STOP to unsubscribe, HELP for help. View our [Privacy Policy] and [Terms].”

What not to do: don’t hide this text below the fold, don’t pre-check the box, and don’t describe the program vaguely as “updates” when you actually mean weekly sales pitches.

Pro Tip: Take a screenshot of your live opt-in form the day you launch it, and re-screenshot it every time you edit the page. That dated image is often the single most persuasive piece of evidence in a consent dispute.

Dated consent screenshots forming evidence trail

Different channels need different mechanics, but the underlying discipline is the same everywhere: disclosure at the point of action, and a record you can retrieve later.

For web forms and mobile CTAs:

  1. Place the disclosure paragraph directly beneath or beside the checkbox, never above the fold on a separate section.
  2. Leave the checkbox unchecked by default; a pre-ticked box is not consent.
  3. Log the timestamp, IP address, form URL, and the exact disclosure text shown at that moment.
  4. Send a confirmation text within seconds that restates the program name and STOP/HELP options.

For keyword and shortcode opt-ins (texting “JOIN” to a five- or six-digit number), the sequence carriers expect looks like this:

  1. Recipient texts the keyword.
  2. Your system replies immediately with a confirmation message naming the brand, describing the program, stating frequency, and repeating “Msg & data rates may apply” plus STOP/HELP.
  3. You log the inbound keyword, the originating number, and the timestamp as your consent record.

For contact-center verbal enrollment, agents need a script that names the company, states what the customer is agreeing to receive, and confirms frequency out loud before capturing the number. Document the date, agent ID, and a recording or call note as evidence.

For QR codes and in-person sign-ups, keep the physical text short (a business card or table sign works), and link through to the full disclosure and opt-in form rather than trying to cram every element onto a poster. The linked page still needs the checkbox-adjacent disclosure described above.

How Should You Handle STOP, HELP, and Message Timing Rules?

Opt-out handling isn’t a policy you write down and hope agents remember. It has to run automatically, every time, with zero exceptions for “just this one VIP campaign.”

The moment a recipient replies STOP, your system needs to suppress that number immediately and send exactly one confirmation message. That confirmation should be strictly informational, something like “You’ve been unsubscribed from [Brand] alerts. No more messages will be sent,” per carrier messaging policy. Slipping a discount offer into that final message is a common and entirely avoidable violation.

HELP replies need substance, not a shrug. A compliant HELP response includes:

  • Your program or brand name
  • A customer support phone number or email
  • A brief description of the messaging program
  • STOP instructions repeated

Quiet hours matter operationally. Carriers and industry guidance expect sends only between 8 a.m. and 9 p.m. in the recipient’s local time zone, not yours. That means your system needs to resolve area codes or stored addresses to a time zone before queuing a send, not just check the clock at your office.

Message content itself needs to stay identifiable and on-topic: your brand name should appear in the body, and the subject matter should track back to whatever the recipient actually opted into.

Pro Tip: If your platform can’t automatically detect a recipient’s time zone from their number, don’t buy it for marketing SMS. That single gap causes more accidental quiet-hours violations than any other configuration mistake.

Why Do Carriers Reject 10DLC Registrations, and How Do You Avoid It?

10DLC, short for “10-digit long code,” is the registration system carriers use to vet who’s texting from a given number before granting it real throughput. Skip it or botch it, and your messages get throttled, filtered, or blocked outright, regardless of how clean your legal consent is.

Reviewers want to see a specific packet of evidence, not just a business name and a form:

  • Screenshots of the live opt-in flow showing the disclosure text in place
  • Sample messages representing exactly what subscribers will receive
  • A working privacy policy and terms-of-service URL
  • A clear description of the opt-in method (web form, keyword, verbal, QR)

The AWS opt-in checklist points to three recurring rejection causes: brand name mismatch between what’s registered and what actually appears on the opt-in page, disclosures that are technically present but visually buried, and missing sample confirmation messages. Fix the brand mismatch first. If your legal entity is “Acme Holdings LLC” but your website says “Acme Coffee,” register under the name customers actually see.

Build a submission folder before you apply: dated screenshots, your exact disclosure copy, a sample welcome and confirmation message, and the URL where the opt-in lives. Reviewers move faster on complete packets, and resubmissions after a rejection can cost you weeks of delivery delay.

If a subscriber disputes ever opting in, or a carrier audits your program, your defense is only as good as your records. Verbal assurance that “we definitely got consent” carries zero weight in a TCPA dispute.

Keep, at minimum:

  • The exact opt-in copy and disclosure text shown at the time
  • Timestamp of consent
  • The phone number itself
  • IP address, session ID, or campaign ID tied to the collection point
  • The channel used (web form, keyword, verbal, QR)

Retain these records for at least four years, a window that covers the TCPA’s statute of limitations with margin for litigation timelines, per carrier and platform guidance. Export formats matter less than accessibility. A searchable database beats a folder of screenshots, but either works if you can retrieve a specific record fast when asked.

Build a simple internal audit checklist: pull ten random subscribers quarterly, confirm you have full consent evidence for each, and flag any gaps for immediate remediation. Even transactional or one-time-passcode programs deserve this discipline, since auditors and carriers may request proof for any messaging stream, not just marketing.

TCPA violations carry statutory damages, and those numbers add up fast in ways that make “we’ll fix it later” a genuinely bad bet.

Under the TCPA, violations expose senders to $500 per negligent message and $1,500 per willful violation. Send one noncompliant campaign to a list of 10,000 numbers, and even the negligent-tier math puts theoretical exposure at $5 million before a court ever weighs intent or class-action multipliers.

Shared and lead-generator consents are now the riskiest category of all, since the FCC’s one-to-one rule specifically targeted that model as improper. A consent purchased from a third-party list broker almost certainly doesn’t satisfy the current standard, no matter what the broker’s paperwork claims.

Controls that materially reduce exposure:

  • Scrub every list against the Do-Not-Call Registry before each campaign
  • Throttle sends and stagger large campaigns to avoid one catastrophic blast
  • Run a recurring compliance review of opt-in flows, not a one-time setup check
  • Loop in legal counsel before launching any new consent-collection method

What’s a Practical Seven-Step Checklist to Fix Your SMS Program This Week?

  1. Rewrite opt-in copy so your business name appears first and disclosures sit next to the checkbox.
  2. Update confirmation-message content to include program name, frequency, and STOP/HELP.
  3. Scrub your list against the National Do-Not-Call Registry.
  4. Register or re-verify your 10DLC campaign with matching brand details.
  5. Centralize consent records into one searchable system rather than scattered spreadsheets.
  6. Test STOP and HELP yourself, from a real phone, to confirm the automated replies actually fire correctly.
  7. Schedule a recurring quarterly audit on the calendar, not as a someday task.

Before launching anything new, ask two gating questions: can you produce documented proof of consent for this exact list right now, and does your opt-in page name your company by name before the checkbox? If either answer is no, don’t send.

Pro Tip: Run the STOP test from your own phone before every major campaign launch, not just once at setup. Platform updates and carrier-side changes can quietly break automated opt-out handling.

How Does a Cloud Communications Platform Handle These Controls?

Building compliant SMS infrastructure from scratch means someone on your team owns time-zone logic, STOP/HELP automation, and consent logging indefinitely. That’s a real engineering commitment for a small marketing or nonprofit team.

Some business communications platforms support business SMS through branded local, toll-free, or vanity numbers, with STOP and HELP handling built into the messaging flow rather than something you code yourself. Message logs capture the record trail auditors and carrier reviewers actually ask for: what was sent, when, and to which number, exportable when you need to produce evidence.

None of this replaces legal judgment. Whether your specific opt-in flow or consent language satisfies TCPA in your exact use case is a question for counsel, not a platform’s feature list. What a platform like Talkroute does is remove the operational guesswork around STOP/HELP automation and logging, so your legal review can focus on consent language instead of on whether your suppression logic actually works.

Express written consent and implied consent aren’t two flavors of the same thing. They’re different legal standards that apply to different types of messages, and confusing them is how well-meaning businesses end up in violation.

Express and implied consent comparison

Express written consent requires an affirmative, documented action: a checked box, a signed form, or a keyword text, paired with disclosure of what the recipient is agreeing to. This is the standard that applies to marketing and promotional texts sent via autodialer, per TCPA and FCC rules. Nothing about it can be inferred. If you can’t produce a record of the affirmative action, you don’t have it.

Implied consent is a lower bar that can sometimes apply to non-marketing communications, particularly when a prior business relationship or the customer’s own action (like giving you their number during a purchase) creates reasonable grounds to text them about that specific transaction. A customer who gives their number to receive a delivery update has implicitly agreed to receive that delivery update, not a coupon for next month’s sale.

The practical trap is businesses assuming implied consent from a phone number collected for one purpose covers a completely different purpose. Getting someone’s number for appointment scheduling does not imply consent for marketing blasts. Every context shift, from transactional to promotional, effectively requires fresh, explicit consent under the current framework. Treat implied consent as narrow and fragile, and default to express written consent whenever a message carries any promotional intent.

Yes, and the gap between the two categories is exactly where most businesses get tripped up. Informational and transactional messages, things like appointment reminders, shipping updates, or one-time passcodes, generally operate under a lighter consent standard than marketing messages do.

A customer who books an appointment and provides their number has a reasonable expectation of a reminder text about that appointment. That’s typically covered by implied or general consent tied to the transaction itself. The moment that same message includes a promotional element, a discount code, an upsell, a “while you’re here” pitch, it can shift into marketing territory and trigger the prior express written consent requirement.

This distinction isn’t always crisp in practice, which is exactly why it causes trouble. A “your order has shipped” text is safely informational.

The safest operational rule: if a message exists purely to serve a transaction the customer initiated, treat it as informational and keep it that way, with no promotional content mixed in. If a message exists to generate new sales, treat it as marketing and hold it to the full prior express written consent standard regardless of how it’s dressed up. Keeping these two message streams entirely separate, even using separate opt-in flows, makes the distinction far easier to defend later.

How Do International Rules Affect Cross-Border SMS Compliance?

TCPA governs texts to U.S. wireless numbers, but plenty of U.S. businesses text customers who travel internationally, or serve customers based outside the country entirely. That’s where things get genuinely complicated, because consent rules aren’t remotely uniform across borders.

The European Union’s ePrivacy Directive and GDPR framework generally require opt-in consent that’s even more restrictive than the U.S. baseline, with stricter rules around data storage and the right to be forgotten. Canada’s Anti-Spam Legislation (CASL) imposes its own consent and identification requirements that don’t map cleanly onto TCPA compliance. A U.S. business texting a customer with a Canadian or EU number isn’t automatically protected by having satisfied American rules.

Carrier behavior compounds this. International SMS routing often passes through different carrier agreements and pricing structures, and delivery to international numbers can fail silently or get filtered without the clear feedback a domestic 10DLC-registered number provides.

The practical guidance for most U.S. small businesses and nonprofits: if your subscriber base is domestic, TCPA and CTIA rules are your primary framework, and that’s genuinely sufficient. If you’re knowingly collecting international numbers, whether from an EU customer base or Canadian donors, treat that segment separately, get consent that satisfies the stricter jurisdiction’s standard, and don’t assume your domestic opt-in language covers you once a recipient’s number falls outside U.S. carrier territory.

The FCC’s one-to-one consent rule that took effect January 27, 2025 wasn’t a one-time fix; it was a signal that regulators intend to keep tightening the lead-generation loophole rather than let a new workaround emerge. Expect continued scrutiny of any consent-collection model that resembles the shared-list structure the FCC just closed, even if it’s dressed up differently.

Lead-generation businesses face the most structural pressure. The FCC’s order effectively requires these companies to redesign how they collect and sell consent, since a single generic signup can no longer be resold to multiple downstream sellers. Some will pivot to per-seller consent capture; others may exit the model entirely.

Carrier-side enforcement through CTIA and 10DLC registration will likely keep tightening as well, with reviewers getting more sophisticated about detecting brand mismatches and buried disclosures rather than less. Businesses that build clean, well-documented opt-in flows now are positioned well regardless of what specific technical requirement changes next; the ones relying on gray-area shortcuts are the ones most likely to face a scramble when the next rule closes their particular gap.

The single most common problem I see isn’t a business ignoring the law. It’s a business that genuinely believes their opt-in flow is fine because nobody’s complained yet, when the actual issue is that their disclosure text technically exists somewhere on the page, just not next to the checkbox where it needs to be. Fix that placement first. It resolves more rejections and more legal exposure than any other single change.

Second priority: assemble your 10DLC registration packet, screenshots, sample messages, disclosure text, before you apply, not after a rejection forces you to scramble. And don’t treat an audit as a one-time launch task. Run it quarterly. Consent standards tightened once already in 2025; they’ll tighten again.

— Paul

How Talkroute Helps You Run a Compliant Texting Program

Building STOP/HELP automation, time-zone-aware send logic, and audit-ready logging from scratch takes real engineering time, time most marketing teams and nonprofit staff don’t have to spare.

Talkroute

Some business communications platforms offer branded local, toll-free, or vanity business numbers built for two-way SMS, with STOP and HELP handling integrated into the messaging flow rather than something your team has to build and maintain. Every message logs automatically, so when a carrier reviewer or an auditor asks for proof of a specific conversation, you can pull it in minutes instead of reconstructing it from memory. If you’re currently managing texting through a personal phone or a patchwork of tools, that’s usually the moment to evaluate a dedicated platform instead of continuing to build compliance controls piece by piece.

Compare how business texting platforms stack up on compliance features for small teams managing exactly this kind of SMS program, and see what a properly centralized setup looks like before your next campaign goes out.

Sources

Stephanie

Stephanie is the Marketing Director at Talkroute and has been featured in Forbes, Inc, and Entrepreneur as a leading authority on business and telecommunications.

Stephanie is also the chief editor and contributing author for the Talkroute blog helping more than 200k entrepreneurs to start, run, and grow their businesses.

StephanieStop TCPA Risk: 7 Step SMS Consent Checklist for U.S. Marketers