Last updated 2026-07-10

TL;DR
SMS opt-in is the process of getting a person's express written consent before sending them marketing texts. Under the TCPA (47 U.S.C. § 227), you need prior express written consent for autodialed or prerecorded marketing messages. Missing that consent can cost $500 to $1,500 per text. This article explains what counts, what doesn't, and what good opt-in language actually looks like.
What is SMS opt-in and why does it matter legally?
SMS opt-in is a consumer agreeing, before any marketing text arrives, to receive messages from a specific sender. It's not paperwork you file and forget. It's the line between a lawful campaign and per-message statutory damages that stack up fast.
The governing statute is the Telephone Consumer Protection Act, 47 U.S.C. § 227 [1]. For marketing texts sent using an autodialer or prerecorded voice, the TCPA requires "prior express written consent." The FCC codified that standard at 47 C.F.R. § 64.1200(a)(2) [2]. The written part matters. A verbal "yeah, sure" over the phone does not satisfy it.
The FCC's 2012 order (FCC 12-21) tightened the rules and made clear that electronic signatures count as written consent, so a checked checkbox on a web form, a reply keyword sent via text, or a signature on a paper form all work. What does not work is burying consent in generic terms of service, pre-checking the box for the consumer, or lumping SMS consent inside unrelated disclosures.
Why does this hit the bank account? Each text sent without proper consent is a separate TCPA violation. Statutory damages run $500 per violation and up to $1,500 per willful violation [1]. A campaign that sends 10,000 texts without valid consent generates $5 million in potential exposure at the floor rate. Class actions are common. Settlements regularly run into the millions.
What does "prior express written consent" actually require?
The FCC spelled out the elements at 47 C.F.R. § 64.1200(f)(9) [2]. A valid prior express written consent must include:
1. A written agreement (paper or electronic) bearing the signature of the person called. 2. A clear and conspicuous disclosure that by signing, the person authorizes the seller to deliver telemarketing messages via autodialer or prerecorded message to the telephone number they provided. 3. Agreement that is not a condition of purchasing any good or service.
That third element trips people up constantly. If your checkout flow says "enter your phone number to complete purchase" and buries SMS consent in the same click, you have just made consent a condition of purchase. That is expressly prohibited.
The disclosure also needs to name the seller or identify the company clearly enough that the consumer knows who will be texting them. A generic "you agree to receive messages from our partners" does not cut it, especially after the FCC's January 2025 one-to-one consent rule (adopted in FCC 23-107) took effect [3]. Under that rule, a consumer's consent to one company cannot be shared with or assigned to a separate company. Each brand needs its own direct consent.
For non-marketing texts, such as purely informational messages about a transaction the consumer initiated, the standard is lower: "prior express consent" without the "written" requirement. But the moment a message promotes a product or service, you are back to the written standard. Most compliance teams treat everything as marketing to avoid the line-drawing problem.
What are the main SMS opt-in methods?
There are four common ways people opt in to SMS. Each has different documentation requirements.
Keyword opt-in (text-to-join): The consumer sends a keyword (like JOIN or YES) to a short code or long code. The system logs the inbound message, which itself becomes the written consent record. This is one of the cleaner methods from a documentation standpoint because the carrier record of the inbound message is time-stamped. You still need to follow up with a compliant opt-in confirmation message (more on that below).
Web form opt-in: The consumer enters their phone number in a form and affirmatively checks a box that contains the required disclosure. The checkbox must not be pre-checked. This is the most common method for lead generation and e-commerce. See sms opt-in form for a full breakdown of what the form must contain.
Paper form opt-in: Still common in retail, healthcare, and events. The consumer writes their number and signs (or initials) next to the disclosure language. You need to retain a scanned copy or photograph of the form.
Point-of-sale or verbal capture with written follow-up: Someone provides their number verbally, but consent is formalized when they later reply YES to a confirmation text. The initial verbal step alone is not sufficient for marketing texts.
| Method | Written record created? | Condition-of-purchase risk | Best for |
|---|---|---|---|
| Keyword / text-to-join | Yes, inbound message | Low | Promotions, events |
| Web form with checkbox | Yes, form submission log | Medium if near checkout | E-commerce, lead gen |
| Paper form | Yes, if retained | Low | Retail, in-person |
| Verbal + confirmation reply | Yes, reply message | Low | Call centers |
Double opt-in, where the system sends a confirmation message and requires the consumer to reply to confirm, adds a second layer of documentation. It is not legally required under federal law today, but it produces a stronger consent record and catches fake numbers and mistyped digits. Read more at sms double opt-in.
What should an SMS opt-in message say? Real examples
The opt-in confirmation message, sent immediately after someone opts in, is often required by the CTIA (the wireless industry trade group whose guidelines carriers enforce) [4] and is good practice regardless. A compliant confirmation message typically includes:
- The business name
- A brief description of what messages they will receive
- Message frequency disclosure
- "Message and data rates may apply"
- Instructions to reply STOP to opt out
- Instructions to reply HELP for help
Here are real SMS opt-in message examples you can model:
Retail / e-commerce: "[Brand Name]: You're in! Expect exclusive deals and early sale access (up to 4x/month). Msg & data rates may apply. Reply STOP to cancel, HELP for info."
Lead generation / real estate: "[Agent/Company Name]: Thanks for signing up. You'll get property alerts and market updates for [City]. Up to 8 msgs/month. Msg & data rates may apply. Reply STOP to unsubscribe, HELP for support." For industry-specific use cases, see real estate text message marketing.
Restaurant loyalty program: "[Restaurant Name] Rewards: Welcome! You'll hear about weekly specials and members-only offers (4-6 msgs/month). Msg & data rates may apply. Reply STOP to quit, HELP for questions." More restaurant-specific templates appear at sample text message marketing for restaurants.
B2B / SaaS: "[Company Name]: You're subscribed to product updates and tips. Up to 6 msgs/month. Msg & data rates may apply. Reply STOP anytime to unsubscribe."
None of these need to be long. Under 160 characters is ideal so they send as a single SMS segment. The required elements are non-negotiable. The marketing copy around them is where you can be brief.
What should an SMS opt-in form look like? Form examples
The web form is where most compliance failures happen. A compliant SMS opt-in form has a few non-optional elements.
Phone number field: Obviously. But the label matters. "Mobile phone" or "Cell phone" is better than just "Phone" because you're representing to the consumer that you'll text them specifically.
Unchecked checkbox: Placed directly next to the disclosure text. Not above it, not below a submit button, not in a separate modal.
Disclosure text: This is the legal load-bearing element. It must be clearly readable (at least 12pt font or equivalent in digital terms, per CTIA guidance [4]) and must say something close to: "By checking this box, you agree to receive recurring automated marketing text messages from [Company Name] at the phone number provided. Consent is not a condition of purchase. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe, HELP for help. View our [Privacy Policy] and [Terms of Service]."
Submit button that does NOT say "I agree to texts": The checkbox handles consent. The submit button should say what the form does ("Get my free quote," "Subscribe," "Sign up").
Here is a minimal SMS opt-in form example in structure form:
``` Name: ___________ Email: ___________ Mobile phone: ___________
[ ] By checking this box, I agree to receive recurring automated marketing texts from Acme Corp at the number above. Consent is not a condition of purchase. Msg & data rates may apply. Up to 4 msgs/month. Reply STOP to cancel. [Privacy Policy] [Terms]
[Get My Free Quote] ```
For a full guide with technical implementation notes, visit sms opt-in form.
One practical note: store a server-side log of each form submission that captures the timestamp, IP address, phone number, and the exact disclosure text shown. If the disclosure language changes, version-stamp it. You want to prove, years later, exactly what the consumer saw when they opted in.
How does the FCC's 2025 one-to-one consent rule change opt-ins?
This is the biggest change to SMS consent rules in over a decade. The FCC adopted its "one-to-one consent" rule in FCC Order 23-107, with the relevant provisions taking effect in January 2025 [3].
Before this rule, a consumer could sign a web form agreeing to be contacted by "our partners" and that single consent could be sold or shared with dozens of companies. Lead aggregators built entire business models on this. That model is now gone for telephone and SMS marketing.
Under the new rule, prior express written consent must be given directly to the specific company that will do the contacting. One consumer, one consent, one company. You cannot buy a list of "opted-in" numbers and rely on the aggregator's consent records to cover your texting. If you text someone who opted in to a different company's form, you are unprotected.
For companies that rely on purchased leads or shared lead forms, this is a fundamental operational change. The form must name your company specifically, or the consent does not protect you. The FCC stated the goal as ensuring consumers are not "subjected to a barrage of calls from multiple sellers as a result of consenting to contact from one seller." [3]
Practical steps: audit every lead source you have. If consent was captured on a third-party form that lists multiple companies, that consent does not protect you after January 2025. You need to either get fresh consent directly, or stop texting those numbers. tcpa-sms-compliance has more on how to audit your lead sources.
What happens when someone opts out, and what are your obligations?
Opt-out is the mirror of opt-in, and the TCPA treats failures to honor opt-outs as independent violations. The CTIA guidelines and standard carrier requirements [4] say you must honor STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT as opt-out keywords. You must process the opt-out immediately (the standard expectation is within 10 business days under FCC guidance, but most platforms process it in seconds).
After someone sends STOP, you are permitted to send one final confirmation message acknowledging the opt-out. Something like: "[Brand]: You've been unsubscribed. No more messages. Reply JOIN to re-subscribe or call [number] for help." That single confirmatory message is not a violation even though the person opted out.
What you cannot do: continue sending any marketing messages after an opt-out, require the consumer to jump through hoops to opt out (like visiting a website or calling a number), or treat an opt-out from one campaign as inapplicable to another campaign from the same company.
For HELP responses, the guidelines require you to send back company name, a description of the program, and contact information.
Honoring opt-outs also applies to numbers that are reassigned. The FCC's reassigned numbers database [5] exists precisely because mobile numbers change hands. If a number was opted in by one person and then reassigned to a different consumer, the new holder never consented. The Reassigned Numbers Database (RND) gives senders a lookup mechanism to check whether a number has been reassigned since the consent was captured. Using it is not legally required today, but it is a strong defense if a plaintiff claims they never opted in.
What are the TCPA penalties for texting without proper opt-in?
The numbers are stark. Under 47 U.S.C. § 227(b)(3) [1], a person who receives an unwanted text can sue for:
- $500 per violation (per text message)
- Up to $1,500 per willful or knowing violation
- Actual damages if higher
There is no cap per plaintiff in the statute. Class actions aggregate thousands of plaintiffs, each with their own per-message claim. A 2021 settlement against Papa John's reached $16.5 million over unapproved text messages [6]. A 2019 settlement against Domino's Pizza reached $9.45 million [6]. These are real numbers from public court records.
The plaintiff's bar has made TCPA class actions a cottage industry. Filing is cheap, discovery of text message logs is straightforward, and statutory damages mean plaintiffs do not need to prove they suffered actual harm. Even small outbound teams that send a few thousand texts without clean consent records can face six-figure settlements.
One thing people underestimate: the burden of proof is on you. You need to produce the consent record. If you cannot prove consent, the presumption runs against you. That is why documentation, timestamps, and version-controlled disclosure language are not optional overhead. They are your defense.
For a broader look at how TCPA enforcement works and what courts have found, see tcpa.
Do B2B texts need SMS opt-in consent too?
This is one of the most misunderstood areas in SMS compliance. The short answer is: it depends on whether you are texting a personal cell phone, what the content is, and what technology you are using.
The TCPA applies to "any telephone number assigned to a paging service, cellular telephone service, specialized mobile radio service, or other radio common carrier service." [1] Business cell phones fall under that definition. The fact that someone is being texted in their capacity as an employee does not strip their cell number of TCPA protection.
That said, courts have generally applied a more lenient standard to non-marketing B2B communications, and the FCC's established exemptions for certain informational messages (appointment reminders, fraud alerts, transactional confirmations) give some breathing room. But if you are sending promotional content, cold outreach designed to generate a sale, or automated campaign sequences to cell numbers pulled from a business database, you are in TCPA territory.
The practical answer for B2B teams: if your texts are going to personal cell numbers (which almost all business cell numbers are), treat them as requiring consent. If you are using a manual, non-autodialed approach with individually composed messages to a small list, the autodialer requirement may not apply, but you still want documented consent for any marketing content.
For B2B teams using list-purchased contacts, see b2b lead generation platforms gdpr compliance for an overview of how international data rules intersect with domestic consent requirements.
How should you store and document SMS opt-in records?
There is no single federal regulation that prescribes an exact retention period for TCPA consent records, but the standard civil statute of limitations for TCPA claims is four years under 28 U.S.C. § 1658 [7]. Some courts have applied a shorter limitation in specific contexts, but plaintiffs often argue for the longer period, so the safe practice is to retain consent records for at least four years from the date of the last contact with that number.
What should a consent record contain?
- The consumer's phone number
- The method of opt-in (web form, keyword, paper)
- The timestamp (date and time with timezone)
- The exact disclosure language the consumer agreed to (or a version reference if you track language changes)
- For web forms: the IP address and form URL
- For keyword opt-ins: the inbound message log from your SMS platform
Store these records in a system that is separate from your sending platform. If your SMS vendor has an outage, goes out of business, or revokes your account, you still need access to consent documentation. Export records regularly.
If a plaintiff or their attorney sends you a litigation hold letter or a discovery request, the first thing they will ask for is the consent record for their client's number. Teams that cannot produce it end up settling. Teams that can produce a clean, timestamped record with the exact disclosure text often get cases dismissed or settled at nuisance value.
LeadCompliant's free TCPA compliance kit includes a consent record template and a documentation checklist you can adapt to your own process without starting from scratch.
Which state laws add extra SMS opt-in requirements beyond the TCPA?
Federal TCPA is the floor, not the ceiling. Several states have layered additional requirements on top.
Florida (FTSA, Florida Statute § 501.059): Florida's Mini-TCPA, amended in 2021, created a private right of action for violations of the state's telephone solicitation rules, including texts. It has a lower threshold for what constitutes an "autodialer" than the current federal standard, which matters for platform-based campaigns. Florida plaintiffs have filed aggressively under this statute [8].
Oklahoma (Oklahoma Telephone Solicitation Act, 15 O.S. § 775A): Similar structure to Florida's, with a private right of action and per-call/text statutory damages.
Washington State: Has its own Commercial Electronic Mail Act and telephone solicitation laws that can apply to SMS in certain contexts.
California (CCPA/CPRA): While the California Consumer Privacy Act is primarily a data privacy law, it intersects with SMS in that consumers can request deletion of their data (including phone numbers) and opt out of data sales that might result in future contact. It does not replace TCPA consent requirements but adds a parallel compliance track [9].
The practical takeaway: if you have significant volume into Florida or Texas (which has its own Business and Commerce Code Chapter 305 provisions), review state-specific rules or have counsel do so. Running national campaigns means you plan around the strictest applicable state law, above federal minimums.
For ongoing updates as state laws shift, follow lead generation compliance news and tcpa news today.
What are the opt-in requirements from carriers and CTIA, beyond the FCC?
This is a layer that purely legal-focused teams often miss. Carriers (AT&T, Verizon, T-Mobile) and the CTIA have their own messaging policies that SMS platforms must follow to get and keep access to short codes and 10-digit long codes (10DLC). These policies are contractual, not statutory, but violating them gets your sending capabilities shut off, which is often a faster consequence than a lawsuit.
CTIA's Messaging Principles and Best Practices [4] (updated regularly, most recently with guidance on A2P 10DLC) require:
- A clear program description at point of opt-in
- Opt-in confirmation message sent immediately upon subscription
- STOP/HELP keyword support
- Message frequency disclosure at opt-in
- "Message and data rates may apply" disclosure at opt-in
- No deceptive opt-in practices
For 10DLC campaigns (most business texting in the U.S. now routes this way), The Campaign Registry (TCR) requires campaign registration and includes a description of your opt-in method. Carriers review this. If your stated opt-in method is a web form but you are actually cold-texting scraped numbers, the discrepancy will eventually surface.
Short code programs go through a more formal approval process that includes review of opt-in language and confirmation messages before the code is activated. That review does not happen for 10DLC, which is why 10DLC has become a compliance risk area. Carriers are filtering more aggressively for signs of spam, including patterns that suggest non-consented outreach.
For help choosing platforms that handle 10DLC registration and consent documentation automatically, see text message marketing software and marketing text message service.
How do you check if your current SMS opt-in process is compliant?
Walk through this checklist against your actual forms, flows, and confirmation messages.
Consent capture:
- Is the checkbox unchecked by default?
- Does the disclosure specifically name your company?
- Does it describe the type of messages (marketing, promotions, transactional)?
- Does it say consent is not required to make a purchase?
- Does it say "Message and data rates may apply"?
- Does it include message frequency (exact number or "recurring")?
- Does it include STOP and HELP instructions?
Confirmation message (sent immediately after opt-in):
- Does it name the company?
- Does it describe the program?
- Does it repeat the STOP/HELP instructions?
- Does it repeat the data rates disclosure?
Records:
- Is each opt-in logged with timestamp, phone number, and disclosure version?
- Are records stored in a system you control and can access independently of your SMS platform?
- Do you have a retention policy of at least four years?
Opt-out handling:
- Does your platform process STOP immediately?
- Are opted-out numbers suppressed from future campaigns automatically?
- Do you send one confirmatory opt-out message?
Lead sources:
- Do you have documentation of consent for every number you text?
- For purchased or shared leads: did the consumer consent directly to your company (required under FCC 23-107 since January 2025)?
If you find gaps, fix the form and the confirmation message first. Those are the two pieces plaintiffs scrutinize most in early litigation. LeadCompliant's free compliance kit includes a pre-built consent record template and a short-code/10DLC audit checklist you can use immediately.
For a deeper look at the full set of technical and legal requirements, sms opt-in requirements covers the topic in full.
Frequently asked questions
Is a pre-checked checkbox on a web form a valid SMS opt-in?
No. A pre-checked checkbox does not constitute the consumer's affirmative agreement. The FCC and CTIA both require that consent be an active, not passive, act. If the box is pre-checked, the consumer has not "signed" the agreement in any meaningful sense. Courts and regulators treat pre-checked consent as no consent at all. Always require the consumer to check the box themselves.
Can I text someone who gave me their number on a business card?
Not for marketing texts without first getting explicit consent. Handing someone a business card is not consent to receive automated marketing texts. You can call them, but sending an automated or bulk marketing SMS requires prior express written consent under the TCPA. A one-on-one text from a personal phone about a specific business matter is a different factual situation, but even there, the safest practice is to confirm consent before texting.
How long is an SMS opt-in consent valid?
There is no explicit expiration date in the TCPA statute. However, FCC guidance suggests consent should be reasonably related to the context in which it was given. If someone opted in five years ago and you have had no contact since, a court may view that consent skeptically. Best practice is to re-engage dormant subscribers with a reconfirmation message rather than just resuming sends after a long gap. Most compliance teams treat 18-24 months of inactivity as a trigger to seek reconfirmation.
Do I need a double opt-in for SMS marketing?
Federal law does not require double opt-in. A single, properly documented opt-in satisfies the TCPA's prior express written consent standard. That said, double opt-in, where the system sends a confirmation text and the consumer replies to confirm, creates a stronger evidentiary record and catches mistyped or fake numbers before they become liability. For high-volume campaigns or high-risk industries, the extra friction is usually worth it.
What is the difference between opt-in for transactional texts vs. marketing texts?
Transactional texts (order confirmations, shipping updates, appointment reminders initiated by the consumer's own action) require only "prior express consent," which does not have to be in writing. Marketing texts require "prior express written consent." The practical distinction: if the message promotes a product or service, it is marketing. If it is purely informational about a transaction the consumer started, it may qualify as transactional. When in doubt, treat it as marketing.
Can I share or sell SMS opt-in consent to another company?
No, not after January 2025. The FCC's one-to-one consent rule (FCC Order 23-107) requires that prior express written consent be given directly to the company that will do the texting. Consent cannot be transferred, sold, or shared with other companies. If a consumer signed a form that listed your company and four others, that consent does not protect any of those other companies from January 2025 forward.
What keywords must my SMS program support for opt-out?
CTIA guidelines require that your messaging platform recognize and process STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT as opt-out commands. You must also support HELP, which triggers a response with your company name, program description, and contact information. These are non-negotiable for any A2P (application-to-person) SMS program operating through U.S. carriers, regardless of whether you use a short code or 10DLC number.
What should I include in the disclosure text on my SMS opt-in form?
Your disclosure must name your company, describe the types of messages the consumer will receive, state that consent is not required for purchase, disclose approximate message frequency, say "Message and data rates may apply," and include STOP and HELP instructions with links to your Privacy Policy and Terms of Service. All of this must appear next to an unchecked checkbox, in readable font, before the submit button.
Does the TCPA apply to texts sent from a regular cell phone, not a platform?
TCPA liability for marketing texts without consent is tied to the use of an automatic telephone dialing system (autodialer) or prerecorded message. Texts manually composed and sent one at a time from a personal phone are generally not subject to the autodialer requirement. After the Supreme Court's April 2021 decision in Facebook v. Duguid, the definition of autodialer was narrowed, but most commercial SMS platforms still qualify. Individual texts from a personal phone occupy a grayer area.
How do I handle opt-in consent for numbers that may have been reassigned?
The FCC operates the Reassigned Numbers Database (RND), which lets senders check whether a number has been reported as reassigned since a given date. If you obtained consent from Person A in 2022 and the number was reassigned to Person B in 2023, your consent does not cover Person B. Checking the RND before sending to older consented numbers is not legally mandatory but provides a safe harbor defense if a reassigned-number plaintiff sues you.
What records do I need to keep to defend a TCPA lawsuit about SMS opt-in?
You need the consumer's phone number, the opt-in method, a timestamp, the exact disclosure language they agreed to (or a version-controlled reference), and for web forms, the IP address and form URL. Store these records for at least four years, in a system independent of your SMS sending platform. Courts place the burden on the sender to prove consent. Teams that cannot produce records typically settle.
Are there SMS opt-in requirements that vary by industry?
The TCPA's consent requirements apply across industries, but some sectors have additional layers. Healthcare organizations must also consider HIPAA when texting about patient matters. Financial services firms face additional CFPB guidance. Debt collectors texting consumers are subject to the FDCPA and the CFPB's Reg F. Real estate teams should note that contacting numbers on the National Do Not Call Registry without a prior business relationship is a separate TCPA violation on top of the consent issue.
What is a compliant opt-in message to send after someone joins a text list?
It should include your business name, a short description of what they subscribed to, the message frequency, "Message and data rates may apply," and STOP/HELP instructions. Example: "[Brand]: You're subscribed to sale alerts (4 msgs/month). Msg & data rates may apply. Reply STOP to cancel, HELP for info." Keep it under 160 characters if possible. Send it immediately, not hours later.
Can I use an SMS opt-in I captured two years ago to start a new campaign?
Possibly, but check a few things first. Does the original disclosure describe the type of messages your new campaign will send? If someone opted in for order updates and you now want to send promotional offers, the original consent may not cover the new use. Also check whether the number has been reassigned using the FCC's Reassigned Numbers Database. If the original disclosure language is a reasonable match and the number is not reassigned, the consent may still be valid.
Sources
- U.S. House of Representatives Office of the Law Revision Counsel, 47 U.S.C. § 227 (TCPA statute text): TCPA requires prior express written consent for autodialed marketing texts; damages of $500 per violation and up to $1,500 per willful violation
- Electronic Code of Federal Regulations, 47 C.F.R. § 64.1200: FCC regulations require prior express written consent for autodialed telemarketing calls and texts, defined at 47 C.F.R. § 64.1200(a)(2) and (f)(9)
- U.S. District Court, Middle District of Florida, TCPA class action settlements (Papa John's, Domino's): Papa John's settled a TCPA text messaging class action for $16.5 million; Domino's settled a related case for $9.45 million
- U.S. House of Representatives Office of the Law Revision Counsel, 28 U.S.C. § 1658 (four-year civil statute of limitations): Four-year civil statute of limitations under 28 U.S.C. § 1658 supports retaining TCPA consent records for at least four years
- Florida Legislature, Florida Statutes § 501.059 (Florida Telephone Solicitation Act): Florida's FTSA amended in 2021 created a private right of action for violations of state telephone solicitation rules including SMS, with a broader definition of autodialer than current federal standard
- California Attorney General, California Consumer Privacy Act (CCPA): California CCPA/CPRA gives consumers rights to data deletion and opt-out of data sales that can intersect with SMS consent obligations
- U.S. Supreme Court, Facebook, Inc. v. Duguid, 592 U.S. 395 (2021): Supreme Court narrowed the definition of ATDS (autodialer) in April 2021, requiring random or sequential number generation to qualify
- Federal Trade Commission, Telemarketing Sales Rule and CAN-SPAM resources: FTC enforces the National Do Not Call Registry and telemarketing rules that apply alongside TCPA for commercial outreach