SMS double opt-in: what it is, when you need it, and how to set it up

Is SMS double opt-in required by law? TCPA says no, but it cuts lawsuit risk dramatically. Here's exactly how it works and when to skip it.

LeadCompliant Team
26 min read
In This Article

Last updated 2026-07-10

Person at kitchen table holding smartphone with SMS opt-in confirmation message visible
Person at kitchen table holding smartphone with SMS opt-in confirmation message visible

TL;DR

SMS double opt-in means a subscriber texts a keyword and then confirms with a second reply before you add them to your list. Federal law (TCPA) does not require it, but it creates a timestamped, two-step consent record that is far harder to attack in court. Most compliance attorneys recommend it for marketing texts. Klaviyo and most SMS platforms support it natively.

What is SMS double opt-in and how does it actually work?

Single opt-in is one step: a person gives you their number, you start texting. Double opt-in adds a second step. After someone submits their number, you send them a confirmation text, they reply with a keyword like YES or CONFIRM, and only then does your platform add them to the active list.

Here is the flow in practice. A customer sees a sign-up widget on your website or a call-to-action at checkout. They enter their number and submit. Your platform immediately sends a message along the lines of: "Reply YES to confirm you want texts from [Brand]. Msg & data rates may apply. Reply STOP to cancel." The customer replies YES. Your system logs the timestamp, the number, and the confirmation reply. That person is now an opted-in subscriber with a two-point consent trail.

People who do not reply never enter your active list. That is the whole point. The second step filters out typos, people who did not realize they were signing up, and bad actors who enter someone else's number as a prank or harassment. The drop-off rate between step one and step two is real, typically somewhere between 10 and 25 percent depending on the channel and offer [1], but the subscribers who finish both steps are almost always genuinely interested, which pushes reply rates and purchase conversion up.

The confirmation message itself counts as a transactional or administrative text, not a marketing text, so you can send it before consent is complete. Carriers and the CTIA treat it as a necessary part of the opt-in flow.

Is double opt-in required for SMS under federal law?

No. The Telephone Consumer Protection Act (47 U.S.C. § 227) does not mandate double opt-in for SMS marketing [2]. The FCC's rules require "prior express written consent" for autodialed or prerecorded marketing messages, but the statute and the agency do not dictate the exact mechanism for capturing and confirming that consent.

The CTIA (the wireless industry trade group) publishes its own Messaging Principles and Best Practices, and those guidelines recommend double opt-in, particularly for marketing programs [3]. CTIA guidelines are not law. But carriers like AT&T, Verizon, and T-Mobile enforce them through their short code and toll-free number policies. A program that consistently skips confirmation steps can get flagged or blocked at the carrier level.

Some states are worth watching separately. California's CPRA strengthens consent documentation requirements and gives regulators and private plaintiffs more tools to challenge ambiguous opt-ins [4]. Florida's mini-TCPA (the Florida Telephone Solicitation Act) tightened consent rules for texts and calls starting in 2021 [5]. Neither law explicitly says "you must do double opt-in," but both raise the stakes when your consent record is thin.

The practical answer: double opt-in is not legally required, but it is the cleanest way to prove the consent that is legally required. Those are different things, and conflating them is a mistake a lot of small teams make.

Section 227(b) of the TCPA prohibits using an automatic telephone dialing system or a prerecorded message to call or text a mobile number without the called party's "prior express consent" [2]. For marketing messages specifically, the FCC's 2012 rules upgraded that to "prior express written consent," which must include a clear disclosure that the person is agreeing to receive autodialed texts, the name of the company, and the fact that consent is not a condition of purchase [6].

"Prior express written consent" under the FCC's definition means "an agreement, in writing, bearing the signature of the person called" or its electronic equivalent, as long as it clearly authorizes marketing messages from the identified sender [6]. A web form checkbox with a compliant disclosure and a timestamp qualifies. A text-back keyword flow qualifies. A verbal agreement alone does not.

What double opt-in adds on top of that baseline is a second timestamped record: the outbound confirmation message and the inbound reply. In litigation, plaintiffs often argue that the person never submitted the form, that the form's disclosure was buried, or that someone else entered their number. A two-step log makes all three arguments much harder to sustain. Defendants who can produce a database record showing the originating IP address, the timestamp, the outbound confirmation message, and the confirmed reply have won motions to dismiss that single-opt-in defendants have lost.

For a deeper look at the full statute and FCC rules, see our TCPA overview and the SMS opt-in requirements guide.

Key numbers for SMS double opt-in compliance The figures that actually drive decisions on consent, liability, and list management 500 Statutory damages per text (negligent violation) 1,500 Max statutory damages per text (willful violation) 4 Minimum years to retain consent records (TCPA SOL) 18 Typical subscriber drop-off… confirmation step (%) Source: 47 U.S.C. § 227 (TCPA); CTIA Messaging Principles 2023; 28 U.S.C. § 1658

How does double opt-in reduce TCPA lawsuit risk?

TCPA litigation is expensive regardless of outcome. Per-violation statutory damages run $500 per text for negligent violations and up to $1,500 per text for willful violations [2]. A small marketing campaign sending 50,000 texts to a list with even a handful of people who claim they never consented can generate demand letters fast.

The most common plaintiff strategy in TCPA text cases is to deny consent entirely: "I never signed up for this." Without a strong consent record, the defendant is stuck trying to prove a negative. With double opt-in, you have the original opt-in timestamp, the confirmation text your system sent, and the reply the plaintiff's number sent back. That is three data points the plaintiff has to overcome, not one.

Nobody has clean data on exactly how much double opt-in cuts suit rates, because most cases settle quietly. What is documented is that courts have consistently treated two-step confirmation records as strong evidence of consent. When a plaintiff admitted replying to a confirmation text but claimed they did not understand what they agreed to, courts have leaned on the disclosure language in that confirmation message to decide the point. The text of the disclosure matters. Vague language still loses [7].

The other risk double opt-in addresses is list quality over time. Numbers get recycled by carriers. Someone who opted in three years ago may have their number assigned to a new person now. Double opt-in does not fully solve recycled-number risk (you need a separate tool for that), but it at least confirms the person opting in was in possession of the number at the moment of opt-in.

See TCPA SMS compliance for a complete breakdown of where teams actually get sued.

How do you set up SMS double opt-in in Klaviyo?

Klaviyo has native SMS double opt-in support, and it is turned off by default for most accounts, which surprises a lot of people. You have to enable it deliberately per SMS list or flow.

Here is the basic setup path as of mid-2025. In your Klaviyo account, go to Account Settings, then SMS. You will find a toggle for "Double opt-in" under the compliance settings. When you enable it, Klaviyo automatically sends a confirmation SMS to any new subscriber collected through Klaviyo forms or API calls. The default confirmation message is editable, and you should edit it: make sure it states your brand name, says what kinds of messages they will receive, includes "Msg & data rates may apply," and includes the STOP opt-out instruction [8].

Klaviyo's double opt-in flow does not suppress the subscriber from your list immediately upon opt-in. It creates a "pending" state. If the subscriber confirms, they move to active. If they do not confirm within a set window (Klaviyo's default is 48 hours), they stay in pending and never receive your marketing flows. You can see pending subscribers in your list view filtered by SMS consent status.

One thing that catches teams off guard: if you collect numbers through a third-party tool (a pop-up platform, a POS system, a landing page builder) and push them to Klaviyo via API, double opt-in only fires if the API call is structured correctly and the subscriber's SMS consent status is set to "pending" rather than "subscribed." If your integration pushes them straight to "subscribed," Klaviyo's double opt-in step gets bypassed. Check your integration settings, more than the Klaviyo account settings.

For a broader look at how to structure a compliant program in Klaviyo and similar tools, the SMS opt-in form guide walks through form copy, disclosure language, and the consent checkbox setup.

What should the confirmation text say?

The confirmation message is the legal and practical core of the whole process. Get it wrong and you undermine the protection you are trying to build.

A compliant confirmation text needs the name of the company sending messages, a brief description of the types of messages the subscriber will receive, message frequency (even approximate), a disclosure that message and data rates may apply, how to get help (reply HELP), how to opt out (reply STOP), and the actual confirmation instruction (reply YES to confirm) [3][8].

Here is an example that covers all of that: "[Brand Name]: Reply YES to get weekly deals and order updates by text. Msg frequency varies. Msg & data rates may apply. Reply STOP to cancel, HELP for info."

That is under 160 characters, which matters because multi-part SMS costs more and can look fragmented depending on the device. Keep it under 160 if you can.

What you should not do: make the confirmation message feel like an ad. If your first contact reads promotional, some recipients will report it as spam before they even confirm, which hurts your sender reputation with carriers. Keep the tone informational and direct.

One more thing. The CTIA guidelines say the confirmation message should carry a disclosure even if the opt-in already came with a written disclosure (like a web form) [3]. The second disclosure is redundant but expected under best practices.

Single opt-in vs. double opt-in: which one should you actually use?

Double opt-in is the right default for any program sending promotional, marketing, or sales texts. Single opt-in makes sense only for strictly transactional messages. Here is how the two approaches compare across the factors that matter most to a small outbound team.

FactorSingle opt-inDouble opt-in
Legal requirementNoNo
CTIA recommendationAcceptable for some programsRecommended for marketing
Consent evidence strengthModerateStrong
List growth speedFaster10-25% slower [1]
List quality (engagement)LowerHigher
Carrier spam riskHigherLower
TCPA litigation defenseWeakerStronger
Setup complexityMinimalLow to moderate

My honest opinion: for marketing texts, double opt-in wins. The slower list growth is a real cost, but the better list quality tends to make it back in revenue-per-subscriber within a few months, and the litigation protection is not something you can retrofit after a lawsuit lands.

The one place I would consider single opt-in is a strictly transactional program (order confirmations, appointment reminders, shipping updates) where the person's action, placing an order or booking an appointment, already creates a clear implied consent context and none of the messages carry promotional content. Even then, watch what "strictly transactional" means under TCPA, because plenty of order confirmation flows eventually sneak in upsell content.

For teams doing real estate text message marketing or any outbound lead follow-up, double opt-in earns the friction because the consent source in those programs is often ambiguous to begin with.

How do you handle double opt-in for contacts collected offline?

This one is genuinely tricky. If someone gives you their number on a paper form at a trade show, a retail counter, or during a phone call, you cannot trigger a web-form-based double opt-in flow the same easy way.

For offline collection, send the confirmation text right after the number lands in your system, ideally within minutes. The confirmation text is your first contact, and it should reference how the person gave you their number: "You recently gave us your number at [Event/Location]. Reply YES to receive texts from [Brand]." That context cuts the "I don't know who this is" confusion that drives complaint spikes.

Paper forms themselves can serve as the written consent record if you set them up correctly. The form needs the required disclosures printed on it, the person needs to physically sign or check a box, and you need to keep a copy of the completed form. That is a high operational bar for high-volume events. Some teams photograph the signed forms and attach them to the contact record in their CRM.

Phone-collected numbers are harder. A verbal opt-in from a phone conversation can meet the "prior express consent" standard if the call is recorded and the disclosure is read clearly, but it does not satisfy "express written consent" for marketing texts on its own under the FCC's rules [6]. The safest move: follow up with a text-based double opt-in right after the call.

For teams building out a full intake process, the SMS opt-in guide breaks down consent capture methods by channel.

TCPA does not name a retention period for consent records, which sounds reassuring until you remember that TCPA claims carry a four-year statute of limitations under the catch-all federal statute (28 U.S.C. § 1658) [9], and some state consumer protection claims run longer. Keep your consent records at least five years. Seven is safer.

What you need for each subscriber: the timestamp and IP address of the original opt-in (if web-based), the exact text of the disclosure they saw or heard, the outbound confirmation message content and timestamp, the inbound confirmation reply and timestamp, the phone number, and any later opt-out or opt-in changes with timestamps.

Most SMS platforms store this data automatically, but you need to verify what your platform actually retains and for how long. Some purge data after 12 or 24 months by default. Export and archive your consent data separately if your platform has short retention windows.

Switching platforms is where teams get burned. Migrating a list from one SMS platform to another does not automatically move the consent audit trail. Before you migrate, export all consent records from your current platform and store them somewhere durable (your CRM, a compliance-specific data store, even a secured cloud folder with version control). Discovering mid-litigation that your consent records live in a platform you no longer have access to is a bad day.

LeadCompliant's free compliance kit includes a consent record template and a retention policy checklist covering SMS, email, and call-based opt-ins. Worth having even if you never need it.

What are common mistakes teams make with SMS double opt-in setup?

The most common error is treating double opt-in as a checkbox and never auditing the actual message flow. Teams turn on the feature in Klaviyo or their SMS platform, leave the default confirmation message untouched, and assume they are covered. Default confirmation messages from most platforms are generic and often missing required elements like frequency disclosure or a clearly presented company name.

A second common mistake is bypassing double opt-in for imported lists. If you upload a CSV of contacts who "signed up at some point" through a third-party source, most platforms let you mark them as subscribed without triggering the confirmation flow. That is legally risky. Imported lists are exactly where consent disputes start. At minimum, run a re-opt-in campaign before adding an imported list to your active marketing flows.

Third: using different confirmation flows for different sign-up sources without documenting which consent record belongs to which flow. If someone opted in through your website popup with one version of your disclosure and someone else opted in through a partner co-registration form with a different version, and you later update your disclosure language, your records need to reflect which version each subscriber saw. Courts have asked for exactly this level of specificity.

Fourth: forgetting about opt-out mechanics. Double opt-in creates the entry record, but you also need a compliant opt-out process. Every marketing text must include STOP instructions. Opt-outs must be honored within 10 business days under the FCC's rules [6], though processing them same-day is the operational standard.

For a current look at how the FCC and carriers are enforcing these requirements, check TCPA news today.

Does double opt-in affect deliverability and carrier filtering?

Yes, meaningfully. Carriers filter messages based on complaint rates, and complaint rates drop sharply for confirmed-consent lists. AT&T, Verizon, and T-Mobile all run automated systems that track spam reports per sending number or short code. A high complaint rate can get your short code suspended or your toll-free number flagged, sometimes with very little warning.

The CTIA's 2023 Messaging Principles and Best Practices state that confirmed opt-in (their term for double opt-in) reduces the likelihood of spam complaints, and they recommend it for high-volume messaging programs [3]. High-volume in practice means any program sending more than a few hundred messages per day.

Deliverability also matters for A2P (application-to-person) 10DLC registration, which is now required for most business SMS in the US. When you register your brand and campaign with The Campaign Registry, the campaign description you file includes information about your consent practices [11]. Programs with confirmed opt-in generally get approved faster and with fewer carrier restrictions than programs relying on single opt-in from ambiguous sources.

If you are using a marketing text message service or evaluating text message marketing software, ask specifically how the platform handles 10DLC registration and whether its double opt-in flow is reflected in the campaign registration it files on your behalf. Most reputable platforms handle this. Not all do.

How does SMS double opt-in work differently for B2B versus B2C?

The TCPA's protections apply to individual mobile phone numbers, not to business lines generally. But most B2B contacts you text are reached on personal cell phones, so the TCPA applies to them just as it does to a consumer.

The practical difference in B2B is that consent is often more implicit. Someone hands you a business card with a mobile number. Someone fills out a contact form on your site. A rep collects a number during a sales call. None of those alone counts as "prior express written consent" for marketing texts under the FCC's definition [6].

For B2B SMS marketing, double opt-in matters as much as it does for B2C. The confirmation text does the same legal work: it creates a documented, two-step consent record tied to that specific number. The number belonging to a business contact does not reduce your exposure under TCPA.

B2B programs sometimes get a bit more room in the definition of the relationship and the reasonable expectations around follow-up. A contact who downloads a whitepaper and fills out a form that says "an account executive may text you to schedule a demo" has clearer implicit consent than a consumer who buys a product online. But "clearer" is not the same as "legally sufficient for marketing texts." Get the written confirmation.

For teams working in lead generation specifically, lead generation compliance news and the B2B lead generation GDPR compliance article are useful alongside this one, since GDPR runs parallel to TCPA for any contacts in the EU.

Frequently asked questions

Is SMS double opt-in required by law in the United States?

No federal law mandates double opt-in for SMS marketing. The TCPA (47 U.S.C. § 227) requires prior express written consent for marketing texts but does not specify a two-step confirmation process. The CTIA's Messaging Principles recommend double opt-in as a best practice. Some state laws, including California's CPRA and Florida's FTSA, raise consent documentation standards but do not explicitly require a two-step flow.

How do I turn on double opt-in for SMS in Klaviyo?

In Klaviyo, go to Account Settings, then SMS, and enable the Double Opt-In toggle. This triggers Klaviyo to send a confirmation text to new subscribers before adding them to your active list. Edit the default confirmation message to include your brand name, message types, frequency, message and data rate disclosure, and STOP opt-out instructions. Check that any third-party integrations pushing contacts to Klaviyo set the SMS consent status to "pending," not "subscribed."

What is the difference between single opt-in and double opt-in for SMS?

Single opt-in: a person provides their number and is immediately added to your list. Double opt-in: after providing their number, they receive a confirmation text and must reply before being added. Double opt-in creates a two-point consent record, reduces spam complaints, filters out bad numbers and typos, and strengthens your litigation defense under TCPA. List growth is about 10-25% slower, but list quality and engagement tend to be higher.

What should my SMS confirmation text include?

A compliant confirmation text should include your brand name, a description of the messages the subscriber will receive, approximate message frequency, a statement that message and data rates may apply, how to opt out (reply STOP), how to get help (reply HELP), and the confirmation instruction itself (reply YES). Keep it under 160 characters if possible. Avoid promotional language in the confirmation message; it should be informational and clear.

TCPA claims have a four-year statute of limitations under federal law (28 U.S.C. § 1658), and some state consumer protection claims run longer. Keep SMS consent records, including opt-in timestamps, IP addresses, disclosure language shown, confirmation messages sent, and confirmation replies received, for at least five years. Seven years is a more conservative and defensible standard. Verify your SMS platform's data retention settings and export records before switching platforms.

Can I skip double opt-in for transactional SMS messages like order confirmations?

Transactional texts (order confirmations, shipping updates, appointment reminders) have more flexibility under TCPA because the underlying transaction creates implied consent for related communications. Single opt-in or even the transaction itself may suffice. But if those messages ever include promotional content, upsells, or offers, they become marketing texts requiring prior express written consent. Many teams blur this line without realizing it. When in doubt, use double opt-in.

What happens if someone does not reply to the confirmation text?

They stay in a pending or unconfirmed state and should not receive any marketing messages. Klaviyo and most SMS platforms handle this automatically when double opt-in is properly configured. After a set window (Klaviyo defaults to 48 hours), the pending subscriber effectively times out. You can send one reminder confirmation message within a reasonable window, but you cannot send marketing messages to unconfirmed subscribers. Doing so defeats the purpose of double opt-in and creates TCPA exposure.

Does double opt-in help with carrier filtering and deliverability?

Yes. Carriers like AT&T, Verizon, and T-Mobile filter messages based on spam complaint rates. Confirmed opt-in lists generate fewer complaints because subscribers actively chose to be there. The CTIA's 2023 Messaging Principles cite reduced spam complaints as a primary benefit of confirmed opt-in for high-volume programs. Better complaint rates also reduce the risk of your short code or toll-free number being suspended or rate-limited by carriers.

Does TCPA apply to B2B SMS text messages?

Yes. TCPA protections apply to individual mobile numbers, and most B2B contacts receive business texts on personal cell phones. The statute does not distinguish between consumer and business recipients based on context; it applies to the number type. A business card exchange or a contact form submission alone does not create prior express written consent for marketing texts. B2B teams need the same consent documentation as B2C teams, and double opt-in provides the same protection.

How do I handle double opt-in for contacts collected at events or offline?

Send a confirmation text immediately after entering the number into your system, referencing where you met: "You gave us your number at [Event]. Reply YES to get texts from [Brand]." Paper sign-up forms can constitute written consent if they include proper disclosures and a signature, and you retain a copy. Phone-collected numbers require a separate written confirmation step since verbal consent alone does not meet the FCC's prior express written consent standard for marketing texts.

What are the TCPA penalties for texting someone without proper consent?

TCPA statutory damages are $500 per violation (per text) for negligent violations and up to $1,500 per text for willful or knowing violations. There is no cap per lawsuit, meaning a small campaign to a few thousand people with even partial consent problems can generate six-figure demands. TCPA litigation is a cottage industry; plaintiff firms actively seek consumers who received texts without documented consent. A strong double opt-in record is one of the most practical defenses available.

Can I use double opt-in confirmation for an imported contact list?

Yes, and you should. Imported lists are where consent disputes most often originate, because the original opt-in happened outside your current platform and may have had inadequate disclosure language. Before sending any marketing content to an imported list, run a re-confirmation campaign: text each contact explaining who you are and asking them to reply YES to join your list. This creates a fresh, documented consent record and filters out anyone who no longer wants your messages.

How does 10DLC registration relate to SMS double opt-in?

10DLC (ten-digit long code) is the registration system required for most business SMS in the US. When you register your campaign with The Campaign Registry, you describe your consent practices. Programs using double opt-in are viewed more favorably by carriers during the vetting process and face fewer restrictions. Using double opt-in is not technically required for 10DLC approval, but it reduces the risk of your campaign being rejected or limited for spam concerns.

Do state laws like California's CPRA or Florida's FTSA change SMS double opt-in requirements?

Neither California's CPRA nor Florida's FTSA explicitly requires double opt-in, but both raise the stakes for inadequate consent. California's CPRA gives consumers stronger rights over their data and enables stricter enforcement of consent-based data practices. Florida's FTSA, effective July 2021, covers texts sent with autodialing to Florida numbers and carries its own per-violation damages. Both laws make strong, documented consent more important, which is exactly what double opt-in provides.

Sources

  1. CTIA, Messaging Principles and Best Practices 2023: Opt-in list growth drop-off between single and double confirmation flows is typically cited in CTIA guidance as a trade-off against higher list quality and lower complaint rates for confirmed opt-in programs.
  2. Cornell LII, 47 U.S.C. § 227 (TCPA full statute text): TCPA prohibits autodialed or prerecorded messages to mobile numbers without prior express consent; statutory damages are $500 per violation and up to $1,500 for willful violations.
  3. CTIA, Messaging Principles and Best Practices 2023: CTIA recommends confirmed opt-in (double opt-in) for marketing SMS programs and specifies that the confirmation message must include brand name, message types, frequency, rate disclosure, STOP, and HELP instructions.
  4. California Attorney General, California Consumer Privacy Act (CCPA/CPRA) overview: California's CPRA strengthens consent documentation requirements and gives regulators and private plaintiffs stronger tools to challenge ambiguous or undocumented consent.
  5. Florida Legislature, Florida Telephone Solicitation Act, Fla. Stat. § 501.059: Florida's FTSA, effective July 2021, tightened consent rules for autodialed texts to Florida numbers and carries per-violation damages for non-compliant programs.
  6. Klaviyo Help Center, SMS Double Opt-In: Klaviyo's SMS double opt-in toggle is in Account Settings under SMS; the default confirmation message is editable and should include brand name, message types, frequency, rate disclosure, and STOP instructions.
  7. Cornell LII, 28 U.S.C. § 1658 (federal catch-all statute of limitations): Federal claims arising under statutes enacted after December 1990, including TCPA, carry a four-year statute of limitations under 28 U.S.C. § 1658.
  8. FTC, CAN-SPAM Act Compliance Guide for Business: FTC guidance on consumer consent documentation supports retention of records showing the original consent context, disclosure language, and method of collection.
  9. The Campaign Registry, A2P 10DLC overview: A2P 10DLC registration requires campaign descriptions including consent practices; programs with confirmed opt-in face fewer carrier restrictions during vetting.

Disclaimer: LeadCompliant is a compliance review tool, not a law firm. We do not provide legal advice. Consult with a TCPA attorney for legal guidance on specific compliance questions. Compliance scores, audits, and risk assessments are informational only.

LeadCompliant Team

LeadCompliant provides expert guidance and tools to help you succeed. Our content is reviewed for accuracy and kept up to date.

Related Articles

Related Forms & Templates

Related Glossary Terms

LeadCompliant
Build My Kit