SMS opt-in requirements: what you must do before texting anyone

TCPA requires prior express written consent before most marketing texts. Learn every SMS opt-in requirement, what disclosures are mandatory, and what a violation costs.

LeadCompliant Team
25 min read
In This Article

Last updated 2026-07-10

Person holding a smartphone at a sunlit desk, representing SMS opt-in compliance
Person holding a smartphone at a sunlit desk, representing SMS opt-in compliance

TL;DR

Before sending a marketing text, you need prior express written consent under the TCPA (47 U.S.C. § 227). That means a written agreement, a clear disclosure that autodialed texts will follow, your company name, message frequency, a data-rate notice, and opt-out instructions. Miss any one element and each message exposes you to $500 to $1,500 in statutory damages.

What is an SMS opt-in and why does it matter legally?

An SMS opt-in is a person's affirmative agreement to receive text messages from a specific sender. Sounds simple. The legal weight behind it is not.

The Telephone Consumer Protection Act, 47 U.S.C. § 227, prohibits using an automatic telephone dialing system or an artificial or prerecorded voice to send any text message to a cell phone without prior express consent [1]. For marketing messages, that consent has to be in writing. The FCC reads "writing" to include electronic records, web forms, and keyword replies to a short code. The burden of proof always sits with the sender, never the recipient [2].

Here is why that matters in practice. TCPA is a strict-liability statute for many violations. A plaintiff doesn't have to prove you meant any harm. They just show the text arrived on their cell phone without proper consent. That single fact is why TCPA class actions stay near the top of consumer litigation year after year. The FCC's 2023 one-to-one consent order, which took effect January 27, 2025, tightened things further by requiring consent to go to one named seller at a time instead of a whole list of companies through one checkbox [2].

Run any outbound texting program, a real estate drip sequence or a restaurant loyalty list, and opt-in is the foundation everything else sits on. Get it wrong and each message is a potential $500 to $1,500 liability. Blast 10,000 people without proper consent and the math gets ugly fast.

What are the specific disclosure requirements for SMS opt-in?

This is where most small teams get tripped up. Consent is more than a checkbox. The FCC and TCPA case law together demand a specific set of disclosures at the point of opt-in, and if one element is missing, the consent may not survive in court.

Here is what every valid SMS marketing opt-in has to include at the moment consent is collected [1][2][3]:

Required elementWhat it must say (example)
Sender identity"You are agreeing to receive texts from Acme Corp"
Nature of messages"Marketing messages about our products and promotions"
Message frequency"Up to 4 messages per month" or "Message frequency varies"
Data and message rates notice"Message and data rates may apply"
Opt-out instructions"Reply STOP to unsubscribe at any time"
Help instructions"Reply HELP for help"
Link to Terms of Service and Privacy PolicyFull URL or clickable link

Those seven elements are the floor, not the ceiling. The CTIA (Cellular Telecommunications Industry Association) Messaging Principles and Best Practices add that the disclosure has to sit next to the consent mechanism, meaning above or right below the submit button, not buried in a footer link [3].

One detail teams miss: the disclosure has to be plainly visible before the person clicks submit. Pre-checked boxes are not valid consent under the FCC's 2012 TCPA order [2]. The person takes an affirmative action, typing a keyword, checking an empty box, or clicking a dedicated button, after they see the full disclosure.

For sms opt-in forms, the disclosure text belongs on the form itself, not on a separate linked page. Some carriers and aggregators, Bandwidth among them, layer their own requirements on top of FCC rules. More on that below.

The phrase "prior express written consent" comes straight from 47 C.F.R. § 64.1200(f)(9), the FCC's implementing rule for the TCPA [1]. It calls for a written agreement, in any form that can be kept and reproduced, that clearly and conspicuously authorizes the seller to deliver telemarketing messages using an automatic telephone dialing system to the person's cell number.

The rule reads: "The term 'prior express written consent' means an agreement, in writing, bearing the signature of the person called, that clearly authorizes the seller to deliver or cause to be delivered to the person called advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice" [1].

Four things that do NOT meet this standard:

1. A verbal agreement on a prior call. That covers transactional texts only, never marketing. 2. A general terms-of-service agreement with a buried texting clause the person never actually saw. 3. A lead-gen form where consent is one of twenty items in a multi-seller disclaimer. 4. A purchased list where someone else collected consent under their own name.

The FCC's January 2025 one-to-one consent rule shut the multi-seller loophole for good [2]. Before that, a single lead-generation form could bundle consent for dozens of companies in one click. Now each seller must be named individually and the consumer must have specifically agreed to hear from that seller. Lead generation companies that sold "TCPA-compliant leads" under the old model had to rebuild their consent flows from scratch.

TCPA SMS violation: key numbers at a glance Statutory thresholds and timelines every SMS sender should know 500 Statutory damages per text (standard) 1,500 Statutory damages per text (willful) 4 Years to retain opt-in records (statute of limitat… 2,025 One-to-one consent rule eff… year Source: 47 U.S.C. § 227 [1]; 28 U.S.C. § 1658 [12]; FCC one-to-one consent order [2]

How does the opt-in process work for keyword-based SMS programs?

Keyword opt-in is the most common setup for consumer-facing SMS programs. A person texts a word like JOIN or YES to a short code or ten-digit long code, and that action enrolls them. It works well, but the sequence has to be right to count as valid consent.

Here is the correct flow [3][4]:

1. The advertised call to action (on a website, in a store, on social media) carries the full disclosures listed above: message frequency, STOP/HELP instructions, and the message-and-data-rates notice. 2. The person sends the keyword. 3. An auto-reply confirms the subscription and restates the key terms: program name, frequency, STOP to cancel, HELP for help, and a reminder that message and data rates may apply.

That confirmation text is a welcome message. It does not count as a marketing message because it responds to the person's own action. You can send it without it becoming your first consent-required message. What you can't do is drop a promotional offer into that first reply before you've confirmed the subscription terms.

For sms double opt-in programs, an added step asks the person to confirm again, usually by replying YES to the welcome message. Double opt-in is not required by federal law. It does build a stronger audit trail and cut down on false enrollments. Some carriers encourage it, and some enterprise brand policies require it.

What are the Bandwidth SMS opt-in requirements specifically?

Bandwidth is a major voice and messaging API provider that carriers and software platforms use to route SMS traffic. Its requirements layer on top of FCC rules and reflect the carrier-level policies running beneath every text message.

Bandwidth's published messaging policies require that any application on its network follow CTIA guidelines. That means opt-in has to happen before the first message goes out, the opt-in has to be documented and retrievable, and the sender has to honor STOP requests within one message of receipt [4]. Bandwidth also bans sending to numbers that never opted in and requires opt-in records to be kept for a set period, typically at least four years to match the TCPA statute of limitations.

Beyond the standard CTIA elements, Bandwidth follows the A2P (Application-to-Person) 10DLC (10-digit long code) campaign registration process managed by The Campaign Registry. To send on a registered 10DLC campaign, your registration has to describe the opt-in method accurately. Tell TCR your opt-in is web-form-based when you're actually running keyword opt-in, and your campaign can be rejected or suspended [11].

In practice, your Bandwidth-routed opt-in flow has to:

  • Match the opt-in method you registered in TCR.
  • Include all CTIA-mandated disclosure language.
  • Keep documented records ready if Bandwidth or a downstream carrier asks for an audit.

Most text message marketing software platforms running Bandwidth under the hood enforce these at the campaign-creation stage. The legal responsibility for valid consent still stays with the business sending the messages, not the software vendor.

Do different types of messages have different opt-in rules?

Yes, and this distinction matters more than most teams realize.

The TCPA draws a line between promotional messages and informational or transactional messages. The consent standard is different for each [1][2].

Message typeExampleConsent required
Marketing / promotional"Get 20% off this weekend"Prior express WRITTEN consent
Mixed purpose (info + promo)Appointment reminder that includes an upsellPrior express WRITTEN consent
Purely transactionalOrder confirmation, fraud alertPrior express consent (not required to be written)
EmergencyPublic safety alertsMay not require consent at all

The tricky one is "mixed purpose." Courts have held that any promotional element, even a small mention of a sale inside an otherwise transactional notice, turns the whole message into marketing and triggers the higher written-consent standard [5]. Keep transactional and promotional sends in separate message streams with separate consent records. It's the safest setup.

B2B texting to business landlines may fall outside the TCPA's autodialer restriction. The moment you text a person's cell phone, even for B2B purposes, you're in TCPA territory. The TCPA has no broad B2B exemption for cell phones. That trips people up constantly. Our tcpa sms compliance guide covers the broader landscape.

How should you handle opt-outs, and what happens if you ignore them?

The opt-out side of consent carries just as much legal weight as the opt-in side. Get careless here and you manufacture fresh violations.

Federal rules require you to honor an opt-out within a reasonable time. The CTIA standard sets that at one business day, though most platforms process it instantly [3]. After a STOP message or any reasonable opt-out request, you may send exactly one confirmatory message. That message confirms the unsubscribe, markets nothing, and charges the person nothing.

The word list that triggers opt-out processing includes STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT [3]. You honor all of them, more than STOP. You also can't force a person through hoops to unsubscribe, like sending them to a website or making them call a phone number.

Texting someone after they've opted out is not a technical hiccup. It's a fresh TCPA violation. Each post-opt-out message carries its own $500 to $1,500 exposure, and courts have shown little patience for defendants who blame a slow STOP process [5]. In Van Patten v. Vertical Fitness Group, the Ninth Circuit confirmed that an unwanted text is a concrete injury enough for standing, even with no other harm shown [5].

On record keeping: hold onto what consent was collected, when, what disclosures were shown, and which phone number it tied to. Face a TCPA claim and the burden is on you to prove consent existed. "We're pretty sure they opted in" wins nothing.

Are there state-specific SMS opt-in rules that go beyond the TCPA?

Yes. The TCPA is the federal floor. Several states built higher walls on top of it.

California's Invasion of Privacy Act (CIPA) extends similar autodialer rules, and California courts have read it broadly enough to cover SMS [6]. Florida's Telephone Solicitation Act (FTSA), amended in 2021, created a private right of action specifically for unsolicited texts to Florida residents and does not require class-action status, which drove a surge of individual suits [7]. Oklahoma, Texas, and Washington each carry their own state telemarketing statutes that can overlap with TCPA claims.

What this means for a small team: if you text consumers, you need to know where they live. A contact in Florida gets FTSA protections stacked on top of TCPA. Florida's law reaches any "unsolicited telephonic sales call," extends to texts, and carries a $500 per-text private right of action [7].

State law diverges most sharply on the definition of an "autodialer." After the Supreme Court's narrow reading in Facebook v. Duguid (2021), a federal ATDS has to generate random or sequential numbers [8]. Some state laws use broader definitions that may sweep in predictive dialers and other systems the post-Duguid federal standard leaves alone. Florida's FTSA uses a definition wider than what Facebook v. Duguid set.

This is one reason watching tcpa news today matters if you run an active text program. The patchwork keeps shifting.

What records do you need to keep for SMS opt-in compliance?

Consent records are your entire defense if you get sued. For every number on your list you need to show what the person agreed to, when they agreed, the exact disclosure language shown, how you verified the number was theirs, and which campaign the consent covers.

Minimum records to retain [1][3]:

  • Timestamp of the opt-in event (date and time, ideally with IP address for web forms).
  • The exact form copy or keyword advertisement shown, with version tracking if you update disclosures over time.
  • The phone number that submitted consent.
  • The campaign or sender the consent tied to.
  • Any later opt-out events and the date they were processed.

The TCPA statute of limitations is four years under 28 U.S.C. § 1658, so keep records at least that long [12]. Some attorneys push for five years as a buffer.

For platforms handling thousands of opt-ins, you want this data exportable. If your SMS platform can't export a consent log per phone number, that's a gap worth fixing before a demand letter lands. LeadCompliant's free TCPA compliance kit includes a consent-record template you can adapt for your stack, and the tools can help you audit existing lists for documentation gaps.

For marketing text message service providers, check whether the platform stores opt-in metadata natively or whether you have to pipe it into your own CRM.

What do SMS opt-in requirements look like for lead generation and third-party consent?

Lead generation is where most TCPA SMS violations actually start. A consumer fills out a form on a comparison site, clicks a vague checkbox, and suddenly texts arrive from five companies they've never heard of. Before January 2025 this was common. After January 2025 it's legally much riskier.

The FCC's 2023 one-to-one consent order (effective January 27, 2025) requires that consent from a lead-generation form be specific to one named seller [2]. The form can't bundle multiple sellers into one click. If your company wants to text leads from a third-party lead gen partner, you have two options:

1. Get named explicitly on the third party's form, with the consumer affirmatively selecting you as a company they want to hear from. 2. Collect your own consent through your own form before sending any texts.

The FCC also used "logically and topically associated" language in that order, meaning the consumer's visit context has to reasonably line up with the messages you plan to send. A consumer on a home insurance quote form giving consent to a mortgage company is not logically and topically associated.

For real estate teams, this hits hard. Many real estate lead-gen platforms built their models on shared consent. The real estate text message marketing guide covers how that industry is adjusting. The short version: if you didn't collect the consent yourself, verify exactly what language the third party used and whether your company was named.

How much can a TCPA violation cost, and what are the real lawsuit risks?

The TCPA sets statutory damages at $500 per violation, with treble damages up to $1,500 per violation when a court finds willful or knowing conduct [1]. No cap per plaintiff. No cap per case. One message to one person is a $500 minimum. A marketing blast to 50,000 people without proper consent is a $25 million minimum.

That math explains why TCPA class actions cluster the way they do. A single class can pull millions of individual texts into one lawsuit. Large TCPA class-action settlements have run into the millions of dollars, though individual cases vary enormously, and settlement trackers like WebRecon publish figures showing wide swings from case to case [9]. Small businesses rarely face nine-figure exposure. They regularly see five-figure and six-figure demand letters.

The FCC can pursue its own enforcement independent of private suits. In 2020 the agency issued a $225 million fine against a health insurance robocall operation, its largest at the time, though collection on big FCC forfeitures is often incomplete [10].

For small outbound teams, the realistic risk is the individual demand letter, not the massive class action. A plaintiff's attorney who spots missing disclosures in your opt-in flow will often send a pre-suit demand for $5,000 to $20,000. Plenty of companies settle without ever seeing a courtroom. That's exactly why getting opt-in right from day one costs far less than cleaning it up later.

The chart below breaks down the statutory numbers every sender should have memorized.

What does a compliant SMS opt-in flow for a small business look like end to end?

Here is a working example of a compliant web-form opt-in flow for a small business running a promotional SMS program. Treat it as a functional template, not legal advice. Have an attorney review your specific implementation.

On the web form: An unchecked checkbox with an adjacent label: "By checking this box, I agree to receive text messages from [Business Name] about promotions, offers, and updates at the number provided. Message frequency: up to 4 per month. Message and data rates may apply. Reply STOP to unsubscribe, HELP for help. [Terms of Service] | [Privacy Policy]"

Immediately after form submission: Auto-reply text: "[Business Name]: You're subscribed to our SMS alerts (up to 4/mo). Msg & data rates may apply. Reply STOP to cancel, HELP for help."

Ongoing: Every marketing message carries an opt-out reminder at least once per 30-day period. That's a CTIA best practice and common in carrier guidelines, not a hard statutory requirement [3].

Records stored:

  • Timestamp and IP of form submission.
  • Phone number submitted.
  • Exact checkbox disclosure text with version number.
  • Date of welcome message delivery.

For sms opt in programs using keyword enrollment instead of web forms, the call to action has to carry all the same disclosures wherever it shows up: your website, a store sign, a social post, a print ad.

LeadCompliant offers a free compliance checklist that walks through each step of this flow. Use it to audit an existing program or build a new one. Building your form from scratch? The sms opt-in form guide covers design and legal copy in more detail.

Frequently asked questions

Can I text someone who gave me their phone number verbally?

Not for marketing messages. Verbal consent can cover purely informational or transactional texts, but the TCPA requires prior express written consent for any promotional content. "Written" includes web forms and electronic records, but a phone number on a business card or spoken on a call does not satisfy the written-consent standard. You need a documented, affirmative opt-in with the required disclosures.

The TCPA sets no hard expiration date, but courts and the FCC have found consent can go stale: a long gap between consent and outreach, a relationship that clearly ended, or a consumer who reasonably wouldn't expect to hear from you. A common practical standard is re-confirming consent after 18 to 24 months of inactivity, though nobody has drawn a bright legal line here.

What is the difference between single opt-in and double opt-in for SMS?

Single opt-in means one action triggers enrollment: a form submission or a keyword text. Double opt-in adds a confirmation step, usually a reply of YES to the welcome message. Federal law doesn't require double opt-in, but it builds a stronger audit trail. If a subscriber later claims they never opted in, a double opt-in record is much harder to dispute. Carriers and platforms increasingly recommend it.

Generally yes, if the message types are materially different. Consent to receive promotional offers doesn't automatically cover appointment reminders or survey requests, and vice versa. Best practice is describing the message types specifically in the disclosure language, or collecting separate consents for separate programs. Bundling broad consent language to cover every possible message type is less defensible in litigation.

Are there opt-in requirements for texting existing customers?

Existing customers get a narrow exemption for certain transactional texts, but marketing texts still require prior express written consent even for people you already have a relationship with. The FCC's established business relationship exemption that exists for some voice calls does not apply to marketing text messages. If you want to text existing customers with promotions, you still need documented written consent.

Effective January 27, 2025, the FCC's rule requires consent from lead-generation forms to be specific to one named seller at a time. A consumer can't consent to receive texts from a list of companies through a single click on a comparison site. Each business that wants to text that consumer must be individually named on the form, and the consumer must affirmatively select them. This effectively ended shared-consent lead-gen models.

How long do I need to keep SMS opt-in records?

The TCPA statute of limitations is four years under 28 U.S.C. § 1658. Keep opt-in records at least four years from the date of consent, and many compliance attorneys recommend five years to account for late-discovered claims. Records should include the timestamp, the phone number, the exact disclosure language shown, and the opt-in method used.

Does the TCPA apply to B2B text messages?

Yes, if you're texting a person's cell phone. The TCPA's cell phone protections apply to the phone number, not the purpose of the message. There's no broad B2B exemption for marketing texts to mobile numbers. Some defenses exist around non-autodialed business outreach, but relying on those is risky. If your sales team texts prospects' personal cell phones for any marketing purpose, written consent is the safe standard.

What opt-in rules apply to SMS marketing in Florida specifically?

Florida's Telephone Solicitation Act (FTSA), amended in 2021, creates a state-level private right of action for unsolicited texts to Florida residents, separate from the TCPA. It carries $500 per-text damages and doesn't require a class action to pursue. Florida uses a broader autodialer definition than the post-Facebook v. Duguid federal standard. If you text consumers in Florida, FTSA compliance is a separate obligation on top of the TCPA.

Can I buy a list and start texting it if the list provider says it's TCPA compliant?

No. Consent is seller-specific under the post-January 2025 FCC rules. Even if the list provider collected opt-in consent, that consent went to the list provider or someone else, not to you. To lawfully send marketing texts, the consumer must have specifically consented to receive messages from your company by name. Buying a "TCPA-compliant" list does not transfer consent to you.

What happens if someone opts out and I accidentally text them again?

Each post-opt-out text is an independent TCPA violation with its own $500 to $1,500 statutory damages exposure. Courts haven't been lenient about system-lag excuses. You're required to honor opt-out requests within one business day per CTIA guidelines, and most compliant platforms process them faster. If a system error causes post-STOP messages, document it right away and fix it. A pattern of such errors looks like willfulness to a judge.

Do SMS opt-in requirements apply to nonprofit organizations?

The TCPA applies to most organizations, but there's a limited exemption for certain non-commercial calls and messages. Nonprofits running purely informational outreach unrelated to revenue may have narrower exposure, but the exemption is not blanket. If a nonprofit sends texts that could be read as soliciting donations or promoting events commercially, standard TCPA consent rules likely apply. Nonprofits should get counsel on their specific programs.

What is 10DLC and how does it affect SMS opt-in requirements?

10DLC (10-digit long code) is the carrier-managed system for registering business SMS campaigns sent over standard phone numbers. Registering a 10DLC campaign through The Campaign Registry requires describing your opt-in method accurately. If your described method doesn't match your actual process, carriers can suspend your campaign. 10DLC registration does not make your opt-in legally valid; it's a carrier compliance layer on top of TCPA requirements.

No. The FCC's 2012 TCPA order and later case law are clear that pre-checked boxes don't satisfy the prior express written consent standard. Consent has to be an affirmative act by the consumer. A box checked by default that the user must actively uncheck to decline is not valid consent for marketing texts. Courts have consistently rejected this mechanism as a defense.

Sources

  1. Cornell Legal Information Institute, 47 U.S.C. § 227 (Telephone Consumer Protection Act) and 47 C.F.R. § 64.1200: TCPA statutory damages are $500 per violation, up to $1,500 for willful violations; prior express written consent is required for marketing texts to cell phones
  2. Bandwidth, Messaging Policy and acceptable use documentation: Bandwidth requires opt-in before the first message, documented and retrievable consent records, and STOP honoring within one message, consistent with CTIA guidelines
  3. Van Patten v. Vertical Fitness Group, LLC, 847 F.3d 1037 (9th Cir. 2017): Ninth Circuit held that receiving an unsolicited text message constitutes a concrete injury sufficient for Article III standing under the TCPA
  4. California Legislature, California Invasion of Privacy Act (CIPA), Penal Code § 638.51: CIPA has been interpreted by California courts to extend autodialer and privacy restrictions to SMS messages sent to California residents
  5. Florida Legislature, Florida Telephone Solicitation Act (FTSA), Fla. Stat. § 501.059 (2021 amendment): Florida FTSA as amended in 2021 provides a private right of action for unsolicited texts, $500 per text, with a broader autodialer definition than the post-Duguid federal standard
  6. U.S. Supreme Court, Facebook, Inc. v. Duguid, 592 U.S. 395 (2021): Supreme Court held that an ATDS under the TCPA must have the capacity to generate random or sequential phone numbers, narrowing the federal autodialer definition
  7. WebRecon LLC, TCPA Lawsuit and Settlement Tracker: Tracking of TCPA class-action settlements shows values ranging into the millions of dollars, with wide variation between individual cases
  8. The Campaign Registry, 10DLC Campaign Registration Guidelines: TCR requires that the opt-in method described during 10DLC campaign registration accurately match the actual opt-in process used by the sender
  9. Cornell Legal Information Institute, 28 U.S.C. § 1658 (Statute of Limitations): The general federal statute of limitations is four years, which applies to TCPA civil claims

Disclaimer: LeadCompliant is a compliance review tool, not a law firm. We do not provide legal advice. Consult with a TCPA attorney for legal guidance on specific compliance questions. Compliance scores, audits, and risk assessments are informational only.

LeadCompliant Team

LeadCompliant provides expert guidance and tools to help you succeed. Our content is reviewed for accuracy and kept up to date.

Related Articles

LeadCompliant
Build My Kit