Last updated 2026-07-10

TL;DR
The TCPA (47 U.S.C. § 227) requires prior express written consent before you send any marketing text. Violations cost $500 to $1,500 per message, with no statutory cap. You need clear consent language, easy opt-out, 10DLC registration, and dated written records of every opt-in. One mass blast without proper consent can produce class-action exposure in the tens of millions.
What is TCPA SMS compliance and why does it matter for texting?
TCPA SMS compliance means getting documented consent before you text, honoring opt-outs fast, and keeping records you can produce in court. The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, is the federal law that governs automated calls and texts to U.S. consumers.[1] Congress passed it in 1991. The FCC has stretched its reach to cover SMS, MMS, and RCS because the agency treats texts as calls under the statute.[7]
Why the urgency? The statute lets private citizens sue for every single message. Base damages are $500 per unsolicited text. If a court finds you ignored the rules on purpose, that triples to $1,500 per message.[1] Send one blast to 100,000 people without consent and the math turns brutal. Plaintiffs' attorneys take these cases on contingency because the damages stack so cleanly.
For outbound sales and marketing teams, TCPA compliance is not an abstract legal exercise. It shapes how you build lists, what your opt-in forms say, which platform you pick, and how fast you kill an opt-out. Get it wrong once, at scale, and a single complaint can cost more than a year of revenue.
The FCC's 2024 order, adopted in December 2023 and effective January 2025, added a hard new rule: each lead's consent has to be specific to one seller at a time. Burying a blanket consent to "marketing partners" in a lead-gen form no longer covers that broad group.[2] That change alone broke a big chunk of the shared-lead market.
What consent does the TCPA require before you can send a marketing text?
You need prior express written consent for any text that advertises or promotes something. That standard sits above the lower bar for purely transactional texts. The line between the two decides how much documentation you have to keep.
The FCC's rules at 47 C.F.R. § 64.1200(f)(9) define written consent as a signed agreement that clearly authorizes the sender to deliver autodialed or prerecorded messages and that includes the recipient's phone number.[3] The agreement has to state that consent is not a condition of purchase. That piece is not optional, and it has to appear on the consent form itself.
Informational texts (appointment reminders, order confirmations, shipping updates) need only "prior express consent," with no written requirement. But the moment a message carries any promotional content, even a throwaway line like "while you're here, check out our summer sale," the written standard kicks in.
What does "written" mean in practice? Electronic consent counts. A checkbox on a web form, a keyword opt-in over SMS, or a signature on paper all work, as long as the language around the consent is compliant.[3] That language has to:
- Name the specific company sending the texts (more than "our marketing partners")
- Describe the types of messages the person will get
- Disclose message frequency if it's predictable
- State that message and data rates may apply
- Explain how to opt out
- Confirm that consent is not required to buy anything
Platforms like Attentive and Maestra both ship built-in consent capture flows. Attentive's opt-in widgets, for instance, use a two-tap process and drop the required disclosure language in automatically. That cuts your front-end risk. It does not replace your job to read and approve the actual words before they go live. The platform automates delivery. You own the language.
Walk through exactly what your SMS opt-in documentation has to say and the specific form elements that satisfy the FCC.
What changed with the FCC's 2024 one-to-one consent rule?
The one-to-one consent rule ended shared consent. One opt-in can no longer be sold to dozens of sellers at once. It's the biggest shift in TCPA enforcement in a decade, and it hit outbound teams harder than most expected.
The FCC adopted the Report and Order in December 2023. It took effect January 27, 2025.[2] The rule targets lead-gen loopholes. Before 2025, a lead-gen site could collect one consent and share it with 40 marketing companies at once. The consumer ticked one box and suddenly had 40 sellers calling and texting.
Now consent has to be one-to-one. It must be logically and topically associated with the website where the person gives it, and specific to the individual seller. You cannot ride along on a blanket list of "partners." The FCC's order requires that such consent be "clear and conspicuous," specific enough that a reasonable consumer would understand exactly who's about to contact them.[2]
Here's what that means in practice.
If you buy leads from a third-party generator, confirm the site collected consent that names your business, more than a category. If it didn't, that lead is not safe to text under the TCPA until you re-establish consent yourself.
Shared-lead models that sold one opt-in to ten insurance companies, mortgage lenders, or solar installers are legally broken. Generators have had to rebuild their flows. Buyers have to vet the new consent records line by line before they send.
The order also set a hard clock on opt-outs: ten business days.[2] Some carriers and platforms already suppress faster. Ten business days is the outer legal limit now. Any text you send after a consumer opts out inside that window is a violation.
What is 10DLC registration and is it a legal requirement under the TCPA?
10DLC (10-digit long code) registration is a carrier requirement, not a TCPA statutory one. In practice it's inseparable from compliant SMS for U.S. business texting.[4] Skip it and your messages get filtered before they reach anyone.
Before 2021, businesses fired marketing texts from unregistered 10-digit numbers all the time. Carriers started enforcing registration through The Campaign Registry (TCR) in 2021 to fight spam and see who's sending what. Unregistered 10DLC traffic now gets filtered hard, so your texts simply won't land if you don't register.
Here's the flow. Your business registers as a brand with TCR, then registers each messaging "campaign" (a use case like marketing promotions or customer notifications). Carriers approve or reject each campaign and assign throughput limits. Fees are small, typically $4 per brand and $10 per campaign per month through most aggregators, though the numbers move around by carrier and aggregator.[4]
Registration also builds a paper trail. Carriers log the campaign each message ran under. If you face a TCPA suit and discovery, that record shows opposing counsel the stated purpose of your program. Make sure your campaign description matches what you actually send.
High-volume senders have other options. Toll-free numbers with carrier verification, and short codes (5-6 digit numbers), both exist. Short codes come with explicit carrier vetting, higher throughput, and higher cost, roughly $500 to $1,000 per month from most providers.[4] Toll-free verification is free to apply for but can take weeks. For most small outbound teams, a registered 10DLC number is the right place to start.
If you're comparing text message marketing software, ask each vendor whether they handle 10DLC registration for you or leave you to register separately through TCR.
How do you write a legally compliant SMS opt-in form?
Most TCPA SMS cases are won or lost at the opt-in stage. Clean consent documentation gives you a defense. Vague or missing language gives you a problem. Everything downstream depends on this one form.
A compliant SMS opt-in form needs specific language, and none of it can hide inside a linked privacy policy nobody reads. The FCC has been consistent that the consent disclosure must be "clear and conspicuous" at the point of collection.[3]
Required elements, on the form itself:
| Element | What it must say (example) |
|---|---|
| Sender identity | "By submitting, you agree to receive texts from [Your Company Name]" |
| Message type | "...including marketing and promotional messages" |
| Frequency | "Message frequency varies" or a specific cadence |
| Cost disclosure | "Message and data rates may apply" |
| Opt-out instructions | "Reply STOP to opt out" |
| Help instructions | "Reply HELP for help" |
| No purchase required | "Consent is not a condition of any purchase" |
| Privacy policy link | Hyperlinked, accessible |
The checkbox or phone field has to be unchecked or blank by default. Pre-ticked boxes do not produce valid consent under the TCPA.[3]
For keyword opt-ins (a user texts JOIN to your number), the confirmation reply also has to carry these disclosures. Attentive and other platforms automate that confirmation, but you still verify that your account's configuration includes every required line.
Keep consent records at least four years. The TCPA runs on a four-year statute of limitations under 28 U.S.C. § 1658, and you'll need the original record if a consumer or attorney challenges it.[11] Store the timestamp, IP address, form version, and phone number together, as one linked record.
How much does a TCPA SMS violation actually cost?
A TCPA SMS violation costs $500 per text, or $1,500 per text if the court finds you acted willfully. There's no cap. That's what makes a single blast a business-ending event.
Base statutory damages under 47 U.S.C. § 227(b)(3) are $500 per violation.[1] Willful or knowing violations let a court treble that to $1,500 per message. A class of 50,000 people who each got one non-compliant text means $25 million in base damages, and up to $75 million if the court finds willfulness.
The chart below shows how the numbers scale with volume at each tier.
Real settlements give you a feel for outcomes. A few:
- Papa John's settled a TCPA class action for $16.5 million in 2013.[5]
- Sallie Mae settled for $24.15 million in 2017.[5]
For small outbound teams, single-plaintiff claims are more common than class actions, and they still sting. One plaintiff who got five unauthorized texts can walk away with $7,500 plus attorney's fees. That happens all the time in federal district court, with little discovery and almost no cost to the plaintiff.
FCC enforcement is a separate layer. The FCC can impose forfeitures under 47 U.S.C. § 503(b) that reach tens of thousands of dollars per violation, adjusted for inflation each year.[6] The agency has hit robocallers and SMS spammers with multimillion-dollar fines.
The honest math: compliance (consent documentation, 10DLC registration, a decent platform) is a rounding error next to one settlement. Spend the $2,000 to $5,000 a year on infrastructure. Don't wing it.
What are the TCPA opt-out rules for SMS, and how fast do you have to honor them?
Once someone opts out, you must stop sending marketing texts, and the FCC's 2024 order caps the delay at ten business days.[2] Most carriers suppress in near real time. Opt-out is where operationally tight companies still get sued, because one number slips the suppression process and gets a text after replying STOP.
STOP is the industry-standard keyword. Courts and the FCC have held that variations like "unsubscribe," "cancel," "quit," and "end" also have to be honored when it's reasonably clear the consumer wants out.[10] If your system only matches exact STOP and ignores someone who replies "please stop texting me," you're exposed.
After a STOP, you're allowed one final confirmation text acknowledging the opt-out. That message cannot carry any promotional content.
Suppression lists have to stay live. Switch platforms and your opt-out list migrates with you. Buy a lead list and you scrub it against your existing opt-outs before you send. Send on behalf of a brand through an agency, and the brand owns the opt-out list, not the agency.
For the SMS opt-in requirements that pair with opt-out duties, a compliant program runs both sides in one system, so a suppression applies automatically across every campaign.
Do the TCPA SMS rules apply to B2B texting?
Yes, mostly. If you text a prospect on their personal or work cell phone, the TCPA applies regardless of whether the message is business-to-business. The statute's protections run to "any person," and courts have generally held that mobile numbers used for work are covered.[7]
The nuance sits with landlines. Business landlines get different treatment for certain calls, and the FCC has historically given some room to B2B communication where an established business relationship exists. But cell phones are cell phones. The carrier doesn't know whether a number belongs to a consumer or an employee, and the statute doesn't either.
So B2B outbound texting still needs consent. Plenty of B2B teams skip it because a lawyer once said "it's business-to-business." That's not a safe read of the statute as applied to mobile numbers. Safer path: get written consent even for B2B contacts, or limit texts to transactional confirmations of something the contact actually asked for.
For B2B lead generation in real estate, mortgage, or insurance, where the line between consumer and business contact blurs, read how B2B lead generation platforms approach GDPR compliance as a parallel framework that raises the same consent-documentation questions.
Which SMS platforms handle TCPA compliance best, and what should you look for?
No platform makes you compliant. A good one lowers the odds you make a mistake, but no vendor indemnifies you against TCPA liability. Pick tools that reduce operational risk, then own the rest yourself.
Here's what to check in any SMS platform through a TCPA lens.
Consent capture: Does it provide compliant opt-in widgets with the required disclosures built in? Attentive includes a two-step opt-in flow for e-commerce built around prior express written consent. Maestra includes consent field controls inside its customer journey builder. Both are guardrails, not substitutes for legal review.
Automatic opt-out processing: Any serious platform processes STOP replies automatically and suppresses the number across all campaigns. Ask specifically whether an opt-out from one campaign suppresses the number program-wide or only for that campaign. Program-wide is safer.
Audit logging: You need a record of every opt-in with timestamp, source, and phone number. If the platform can't export that data in a format you control, you have a discovery problem waiting to happen.
10DLC support: The platform should either register your brand and campaign with TCR for you, or give you a clear passthrough to do it yourself. Ask whether shared short codes or shared 10DLC pools are an option, and what the risk is (shared numbers carry shared exposure if another sender on the pool spams).
DNC scrubbing: Some platforms integrate national and state DNC lists. For SMS, the national DNC list applies less directly than it does to voice, but several state laws overlap with DNC rules.
To compare vendors against these criteria, the marketing text message service breakdown covers the major platforms with a compliance lens.
One more tool: LeadCompliant's free TCPA compliance kit includes a consent language template, an opt-in audit checklist, and a suppression list process template. It's a practical starting point before you spend on a full platform.
What state laws add extra SMS compliance requirements beyond the TCPA?
The TCPA is a federal floor, not a ceiling. States can go further, and Florida, California, and Washington all do.
Florida passed the Florida Telephone Solicitation Act (FTSA) in 2021, and in some ways it's stricter than the TCPA.[8] The FTSA originally required prior express written consent even for texts to numbers obtained through a prior business relationship, and it created its own private right of action. A 2023 amendment narrowed the scope after heavy industry pushback, but Florida stays one of the highest-risk states for SMS marketers.
California's privacy law (CCPA/CPRA) doesn't regulate SMS consent the way the TCPA does, but it creates data-use, opt-out, and disclosure obligations that touch marketing SMS indirectly.[9] If a California resident asks you to delete their data, that request should trigger suppression of their phone number from your SMS lists.
Washington's Automatic Dialing and Announcing Device (ADAD) statute adds its own restrictions on automated calls and texts. Texas, Oklahoma, and Arkansas each have telemarketing statutes with SMS implications too.
The practical rule: if you text consumers in Florida, California, or any state you haven't specifically researched, check the state statute before you assume federal compliance is enough. A one-time review by a TCPA attorney pays for itself here many times over.
For the latest across states, the lead generation compliance news section tracks major state and federal updates as they land.
How do you build a TCPA-compliant SMS program from scratch?
Building a compliant SMS program comes down to seven steps: define your use case, write and vet your consent language, build the opt-in form with logging, register 10DLC, configure program-wide opt-outs, audit any imported lists, and set a recurring review. Here's the sequence that actually reduces exposure.
Step 1: Decide your use case and message types. Marketing needs the highest consent standard. Transactional is lower risk. A mixed program gets treated as marketing for consent purposes.
Step 2: Write your consent language before you build the form. Use the element checklist from the opt-in section. Have a TCPA attorney review it once. This isn't ongoing legal spend, it's a one-time review that runs $500 to $1,500 from most communication-law attorneys and protects you indefinitely as long as the program doesn't change much.
Step 3: Build the form with unchecked consent boxes, every required disclosure above the fold, and logging that captures timestamp, IP, and form version on each submission.
Step 4: Register your 10DLC brand and campaign through TCR before the first message goes out. Budget two to four weeks for carrier approval on new campaigns.
Step 5: Configure the platform to process opt-outs program-wide, not campaign by campaign.
Step 6: Auditing an imported list (from a CRM, a purchased list, or a lead-gen source)? Check its consent documentation before you send. Scrub against your suppression list, and against the national DNC list for any numbers you also plan to call.
Step 7: Set a recurring audit, quarterly at minimum, to review consent records, refresh suppression lists, and check for regulatory changes. The 2024 rule change is a good reminder that this ground moves.
The SMS double opt-in approach, where the consumer confirms by reply text after submitting a form, adds a second layer of documentation that's very hard for a plaintiff to attack. It also strips fake and mistyped numbers out of your list. For marketing programs, double opt-in earns the slightly lower initial conversion rate.
LeadCompliant's compliance kit includes a checklist version of this process, mapped to the specific FCC rules, that you can hand a new hire or run as an audit.
What records do you need to keep to defend a TCPA SMS lawsuit?
The first thing opposing counsel asks for in discovery is your consent records. Can't produce them, and you lose the defense that consent existed. Keep timestamped consent records with compliant language, opt-out logs, message logs, campaign registrations, and any vendor attestations, all for at least four years.
Consent records: Every opt-in with the phone number, timestamp, IP address, form URL, and the exact consent language shown at submission. If your form language changed over time, keep versioned records so you can show which version a given user saw. Retain four years minimum, matching the TCPA's statute of limitations.[1]
Opt-out records: Every STOP reply or opt-out request with a timestamp, plus every suppression action taken in response. If a platform processed the opt-out, export and keep that log separately.
Message logs: What went out, to which numbers, and when. Most platforms retain these, but verify the retention policy. Some delete after 90 days by default.
Campaign descriptions and TCR registration: Your 10DLC records confirm your stated messaging purpose. Keep them.
Third-party consent documentation: If you imported vendor leads, keep the vendor's attestation of how consent was collected, what language was used, and when. The vendor will almost certainly blame you in litigation. Your contract and their written representations are your protection.
Nobody has clean data on how often TCPA defendants win on consent documentation. The closest picture from settlement patterns and motion practice: defendants who can produce timestamped records with compliant language win at a meaningfully higher rate on both fronts. These records are cheap to keep and very expensive to lack.
Frequently asked questions
Does the TCPA apply to text messages, or only phone calls?
Yes, the TCPA applies to text messages. The FCC has consistently read 47 U.S.C. § 227 to cover SMS, MMS, and RCS, because the statute covers any call made with an automatic telephone dialing system and the agency treats texts as calls. Multiple federal circuit courts have upheld this. Any automated or platform-assisted marketing text needs prior express written consent under the same rules as an automated voice call.
What is the difference between prior express consent and prior express written consent?
Prior express consent is the lower bar. It covers informational texts like appointment reminders or order confirmations with no promotional content. Prior express written consent is the higher bar, required for any message that advertises or promotes something. Written consent must be a documented agreement, can be electronic, and must include specific disclosures, including a statement that consent is not a condition of purchase.
Can I text someone who gave me their number on a business card or a sign-up sheet?
Handing over a phone number is not TCPA consent for marketing texts. The person must have affirmatively agreed to receive marketing messages from your specific company, and that agreement must carry the required disclosures. A number on a business card meets none of that. To text that person legally, get proper opt-in consent before you send any marketing message.
How long do I have to process an opt-out after someone replies STOP?
The FCC's 2024 order caps it at ten business days. In practice, well-configured platforms process opt-outs in minutes or hours. Any marketing text sent to a number after a valid opt-out during that ten-day window is a TCPA violation at $500 to $1,500 per message. Most carriers now enforce near-real-time suppression, so your platform should match that speed.
Is a TCPA class action realistic for a small business that sent a few thousand texts?
Yes. Plaintiffs' attorneys routinely file TCPA class actions against small and mid-sized businesses. A list of 5,000 non-consented texts is $2.5 million in potential base damages, enough to attract litigation. Beyond class actions, individual plaintiffs file single-plaintiff suits in federal court over a handful of texts. The statutory damages make even small cases economical for plaintiff counsel on contingency.
Do I need 10DLC registration to comply with the TCPA?
10DLC registration is a carrier requirement, not a TCPA statutory one. But without it your texts get filtered and don't deliver, which defeats the program. Registration also builds a paper trail of your stated campaign purpose, which matters in litigation. For any U.S. business sending marketing texts from a 10-digit local number, registration through The Campaign Registry is effectively mandatory.
What did the FCC's 2024 one-to-one consent rule change?
The rule, effective January 27, 2025, ended shared consent, where one opt-in could be sold to dozens of marketing companies at once. Consent now has to be specific to one seller, collected on a website logically related to that seller's business, with a clear disclosure naming the specific company. If you buy leads from a third-party generator, the consent must name your business or it isn't valid for your use.
Does TCPA SMS compliance apply to texts sent to business phone numbers?
For mobile numbers, yes. Courts have generally held the TCPA applies to cell phones regardless of business use, because the carrier can't tell business from personal and the statute covers any wireless number. Texting a prospect on their work cell needs TCPA-compliant consent. Business landlines carry more limited exposure, but mobile-to-mobile B2B texting carries real risk.
How does Florida's telemarketing law differ from the TCPA for SMS?
Florida's Telephone Solicitation Act (FTSA), as amended in 2023, adds state restrictions on automated texts that in some respects go past federal rules. Florida has its own private right of action, so a Florida resident can sue you under state law even if the federal TCPA claim is weak. Florida is one of the highest-risk states for SMS marketers, and its rules deserve a separate review from your federal analysis.
What consent language do I need on an SMS opt-in form?
Name your company, describe the message types (marketing, promotions), state the frequency or that it varies, include 'message and data rates may apply,' explain how to opt out (Reply STOP), explain how to get help (Reply HELP), link your privacy policy, and state that consent is not required to make a purchase. The checkbox must be unchecked by default. All disclosures appear at the point of collection, not in a linked policy.
Are there TCPA safe harbors or exceptions for small businesses?
No. The TCPA has no small-business exemption. Statutory damages of $500 to $1,500 per message apply no matter the sender's size. You do have affirmative defenses: prior express written consent, proper opt-out procedures, and an established business relationship for certain message types. None of these work as automatic safe harbors. You have to prove them with documentation in litigation.
What is SMS double opt-in and does it help with TCPA compliance?
SMS double opt-in means the consumer submits their number through a form, then confirms by replying to an automated text, usually with YES. This creates a second documented consent event with a timestamp that's very hard for a plaintiff to challenge. It also filters out fake and mistyped numbers. Double opt-in isn't required by the TCPA, but it's the strongest documentation available and worth the modest drop in initial list size.
Can I use a purchased phone list for SMS marketing?
Almost never safely. Purchased lists usually lack the prior express written consent the TCPA requires for marketing texts. The person consented to give their number to someone else, not to receive texts from your business. Texting a purchased list without re-establishing individual consent is one of the most common paths into a TCPA class action. If a vendor hands you a list, get their written attestation of exactly what consent language was shown and when.
How do real estate teams stay TCPA compliant when texting leads?
Real estate texting runs high-risk: agents often text consumer cells from auto-dialing or semi-automated platforms, and many buy lead lists. Compliant programs collect express written consent at the point of lead capture, with form language naming the specific brokerage or agent. Texting someone whose number appeared in a public listing or got scraped from a site does not satisfy consent. See resources on real estate text message marketing compliance for industry-specific guidance.
Sources
- Cornell Law School Legal Information Institute, 47 U.S.C. § 227 (TCPA full text): Base damages of $500 per violation, trebled to $1,500 for willful violations; private right of action for consumers
- Federal Communications Commission, Report and Order FCC 23-107, one-to-one consent rule (adopted December 2023, effective January 2025): New one-to-one consent requirement: consent must be specific to one seller; opt-outs must be honored within ten business days
- Cornell Law School Legal Information Institute, 47 C.F.R. § 64.1200 (TCPA implementing regulations): Prior express written consent definition, clear and conspicuous disclosure requirement, prohibition on pre-checked consent boxes
- The Campaign Registry (TCR), 10DLC registration overview: 10DLC brand and campaign registration fees; carrier enforcement of registration for U.S. business texting
- Federal Trade Commission, enforcement actions and case history: Papa John's $16.5 million settlement (2013) and Sallie Mae $24.15 million settlement (2017) as examples of TCPA class action outcomes
- Cornell Law School Legal Information Institute, 47 U.S.C. § 503 (FCC forfeiture authority): FCC forfeiture authority under 47 U.S.C. § 503(b), adjusted annually for inflation
- Florida Legislature, Florida Telephone Solicitation Act, Fla. Stat. § 501.059: Florida's FTSA adds state-level automated text restrictions and a private right of action beyond federal TCPA requirements
- California Privacy Protection Agency, CCPA/CPRA overview: California's CPRA creates data deletion and opt-out rights that affect consumer phone number suppression in SMS marketing programs
- Cornell Law School Legal Information Institute, 28 U.S.C. § 1658 (four-year statute of limitations): Four-year statute of limitations applicable to TCPA private right of action claims