Text message marketing software: what it does, what it costs, and how to stay legal

The best text message marketing software sends bulk SMS fast, but TCPA fines hit $500-$1,500 per text. Here's what to look for before you sign up.

LeadCompliant Team
25 min read
In This Article

Last updated 2026-07-10

Hands holding a smartphone at a wooden desk used for text message marketing
Hands holding a smartphone at a wooden desk used for text message marketing

TL;DR

Text message marketing software sends promotional and transactional SMS to opted-in contacts at scale, handling scheduling, opt-out processing, and compliance logging. But the software does not shield you from TCPA liability. You need prior express written consent before sending marketing texts. Without it, each message can cost $500 to $1,500 in statutory damages under 47 U.S.C. § 227.

What is text message marketing software and what does it actually do?

Text message marketing software is a platform that sends SMS and MMS to a list of phone numbers, usually through a short code or 10-digit long code (10DLC), without you tapping out each message by hand. At its core it is a message delivery engine wrapped in contact management, scheduling, and reporting.

Most platforms do the same basic things. Import contacts, segment lists, compose messages, send in bulk or on a trigger, track delivery rates and opt-outs. The better ones add two-way messaging (a customer reply lands in a shared inbox), keyword auto-replies, drip campaigns, and hooks into CRM tools like Salesforce or HubSpot.

What the software does not do is verify consent. That part is on you. The platform has no way to know whether the people on your list actually agreed to hear from your company. Every major carrier and every compliance-aware vendor says as much in their terms of service. The software is neutral plumbing. The legal exposure is yours alone.

For outbound sales teams, SMS software also covers cold-outreach workflows, though the legal picture there gets messier. Sending an unsolicited marketing text to a cell phone with an automatic telephone dialing system (ATDS) is a potential TCPA violation no matter how polished the interface looks. [1][2]

How does TCPA apply to text message marketing?

The Telephone Consumer Protection Act, 47 U.S.C. § 227, is the federal law that governs marketing texts to cell phones. It bars using an ATDS to call or text a cell phone without the called party's prior express consent. For marketing messages, the FCC reads that to mean prior express written consent: a signed agreement that clearly authorizes the specific seller to send promotional texts. [1]

The damages provision is what makes this expensive. Section 227(b)(3) lets a person recover "actual monetary loss from such a violation, or to receive $500 in damages for each such violation, whichever is greater." Courts can treble that to $1,500 per message when the violation is willful or knowing. [1] A blast of 10,000 texts to a bad list is not a $50,000 problem. It is a $5 million to $15 million problem.

The FCC's 2012 order tightened consent rules for autodialed marketing texts. Consent has to be "clearly and conspicuously" disclosed, and the consumer has to sign (electronic signatures count) agreeing to receive texts from that specific company. [3] A lead who opted in to texts from a mortgage comparison site did not necessarily agree to texts from your mortgage brokerage. The FCC reaffirmed this company-specific rule in later orders aimed at lead generation consent practices. [4]

For how these rules bite into your software choices, see our guide to tcpa sms compliance.

One more layer. The National Do Not Call Registry covers text messages too. A 2003 FCC ruling confirmed the DNC rules reach calls to wireless numbers, and the FTC treats text solicitations as covered. [5] Text someone on the registry a marketing message without a prior business relationship or consent, and you have stacked a second violation on top of the TCPA one.

What features should you look for in SMS text message marketing software?

Platforms are not interchangeable. Here is how to size one up honestly.

Consent documentation. The single feature that matters most is audit-ready consent records. Your platform should log the timestamp, IP address, and exact opt-in language for every subscriber. If you get sued, the first thing plaintiff's counsel demands is your consent records. Can't produce them? You lose.

Opt-out processing. Federal law says honor opt-out requests immediately. CTIA guidelines say you have to process opt-out keywords (STOP, QUIT, CANCEL, UNSUBSCRIBE, END, HELP) within a reasonable time and confirm the unsubscribe. [6] A platform that takes 24 hours to suppress a number after a STOP reply is a liability.

10DLC registration support. Since 2021, every major U.S. carrier requires businesses using 10-digit long codes for application-to-person (A2P) messaging to register their brand and campaigns through The Campaign Registry (TCR). [7] Skip registration and carriers filter or block your traffic. Any SMS software worth paying for walks you through 10DLC registration or does it for you.

Short code availability. Dedicated short codes (five or six digit numbers) give the highest throughput (up to 500 messages per second) and the clearest brand identity. Carriers effectively retired shared short codes in 2021 over spam. A vendor still pushing shared short codes is a red flag. [7]

Two-way messaging and inbox management. If a consumer texts back and you auto-ignore the reply, you can miss opt-out requests phrased as normal sentences instead of keywords. A real inbox matters.

Suppression list management. The platform should keep a running suppression list of opted-out numbers and check every send against it automatically. Manual suppression at scale is how numbers slip through.

List upload validation. Good platforms flag landline numbers and known DNC entries before you send. Some plug into third-party DNC scrubbing services. None are foolproof, but the scrub is a reasonable step.

For building the opt-in workflow that feeds your platform, see sms opt in and sms opt-in form.

TCPA statutory damages by scenario Per-message damages range under 47 U.S.C. § 227(b)(3) Single violation (standard) $500 Single violation (willful/knowing) $1,500 10,000 texts, standard damages $5M 10,000 texts, trebled damages $15M Source: U.S. House of Representatives, 47 U.S.C. § 227 (TCPA), current law

How do the major SMS text message marketing platforms compare?

The market sorts into roughly four tiers right now.

TierExample platformsBest forTypical pricing
Enterprise CPaaSTwilio, BandwidthDevelopers building custom workflowsPay-per-message (~$0.0079/SMS) + platform fees [8]
Mid-market suitesKlaviyo, Attentive, PostscriptE-commerce brands with large lists$0.01-$0.02/SMS + monthly base
SMB-focusedEZTexting, SimpleTexting, SlickTextSmall teams, no dev resources$20-$300/month for message bundles
Sales engagementSalesloft, Outreach (SMS add-on)Outbound SDR teamsBundled with seat pricing, typically $100-$150/seat/month

Public pricing data on enterprise contracts is thin because those deals get negotiated. The per-message figures above come from publicly listed API rates and published plan pages as of mid-2025, and they move. Get a written quote every time.

For most small outbound teams, the SMB-focused platforms are the right start. They handle 10DLC registration, run reasonable opt-out management, and don't need an engineering team to operate. The tradeoff is less flexibility and lower throughput.

The CPaaS tier (Twilio being the dominant name) hands you total control and the best deliverability tools, but you are writing code or paying a developer to. Most small teams do not need that.

One honest word on the "best text message marketing software" rankings you see online. Most are affiliate-driven. The platform ranked first often paid the highest commission to the site. Judge platforms on the compliance features above, not on a top-ten list.

What does SMS text message marketing software cost?

Pricing splits into three parts: the platform fee, the per-message cost, and the carrier and registration fees.

Platform fees for SMB tools run roughly $20 to $500 per month, scaling with contacts and included messages. Mid-market e-commerce platforms often start at $500 to $1,000 per month for meaningful list sizes. Enterprise contracts can hit tens of thousands per year.

Per-message costs land between about $0.008 and $0.02 per outbound SMS in the U.S. MMS (images, GIFs, short video) runs roughly two to three times a plain SMS. Inbound replies sometimes cost the same as outbound, sometimes less. Read the fine print.

Carrier and registration fees get overlooked a lot. 10DLC brand registration is a one-time fee of $4 to $6 through The Campaign Registry. [7] Campaign registration (one per use case, like marketing versus transactional) runs $10 to $15 per campaign per month. Short code leasing costs $500 to $1,000 per month for a dedicated short code through the U.S. Short Code Administration. [9] These are not platform fees. They are carrier-imposed costs the platform passes through.

Then there is the compliance cost that rarely shows on a pricing page. A consent audit, a lawyer to review your opt-in language, a DNC scrub service. Budget for those separately. They are not optional. They are the cost of not getting sued.

For a small team sending 10,000 marketing texts a month, a realistic all-in number is $200 to $600 per month covering platform, messages, and 10DLC fees. At 100,000 messages a month, expect $800 to $2,500 depending on the platform and your MMS ratio.

What is 10DLC and why does it matter for your SMS software choice?

10DLC stands for 10-digit long code. It is the standard U.S. phone number format (area code plus seven digits) used for A2P (application-to-person) SMS. Since 2021, AT&T, Verizon, and T-Mobile have required businesses to register their brand and their messaging campaigns with The Campaign Registry before sending A2P messages on 10DLC numbers. [7]

Unregistered messages get throughput caps and aggressive spam filtering. Unregistered traffic on AT&T, for example, was capped at 75 messages per day per long code during the rollout period. Registered campaigns earn higher throughput and better deliverability.

This shapes your software choice because the platform needs to support 10DLC registration, ideally running the process for you. You provide your EIN, business name, and a description of your campaign use case. Approval usually takes a few days to a few weeks, carrier depending.

Regulated industries (financial services, insurance, cannabis, for-profit education, political messaging) draw extra carrier scrutiny. Some use cases get effectively blocked on shared infrastructure and need a dedicated short code.

Short codes skip 10DLC registration but carry their own vetting through the U.S. Short Code Administration, with a carrier review that can run six to eight weeks. [9] The cost and lead time are why most SMBs stick with 10DLC.

This is the question that trips up more teams than any other. The answer is prior express written consent, specifically for marketing messages.

The FCC's 2012 TCPA order defined prior express written consent as "an agreement, in writing, bearing the signature of the person called, that clearly authorizes" the seller to send marketing texts to a specific number. [3] The signature can be electronic. The pieces that matter:

1. The consumer affirmatively agrees (no pre-checked boxes). 2. The agreement names the specific company sending the texts. 3. The agreement states that consent to receive texts is not a condition of purchase. 4. The consumer is told the nature of the messages (promotional, how often).

What doesn't work: buying a list of phone numbers and texting them because they filled out a form somewhere once. What also doesn't work: getting a lead through a comparison site that buried a consent disclosure three paragraphs down where nobody read it. The FCC's 2024 order went after this "lead generator loophole" and required consent obtained on a one-to-one basis with the actual seller. [4]

For a practical walkthrough of a compliant opt-in flow, see sms opt-in requirements and sms double opt-in.

Once someone opts in, they can opt out anytime. Honor opt-out requests promptly, and never send another marketing text after a STOP. That is not a best practice. That is the law.

What are the TCPA penalty risks for sms text message marketing?

The risk is not theoretical. TCPA class action litigation is a multibillion-dollar industry. Plaintiffs' firms watch for violations and recruit named plaintiffs.

The statutory damages structure means small teams carry the same per-message exposure as enterprise companies. A regional car dealership sending 50,000 texts without proper consent stares down $25 million in potential statutory damages. A single named plaintiff in a class action can stand in for thousands of similarly situated consumers.

Recent settlements show the scale. Papa John's settled a TCPA class action for $16.5 million in 2013. [10] Domino's settled a text-message TCPA case for $9.45 million in 2019. [10] These are not freak outcomes. The class action bar likes TCPA cases because they are cheap to bring and settle high, since the per-violation math terrifies defendants.

For small companies, the more common threat is a single-plaintiff demand letter, not a class action. A plaintiff spots a violation, hires a TCPA attorney, and sends a demand for a few thousand dollars. Most small businesses settle because fighting costs more. From the consumer protection side, that is the design working, not breaking.

Cutting the risk comes down to getting proper consent and documenting it, keeping suppression lists airtight, and picking software that produces audit-ready records. The software does not make you compliant. You make you compliant. The software just makes it easier to prove.

For current case developments, see tcpa news today and lead generation compliance news.

How is text message marketing software used in specific industries?

The compliance requirements are identical across industries. The use cases and risk profiles are not.

Real estate. Agents and brokerages use SMS to follow up on listing inquiries, book showings, and push market updates. The risk runs high because real estate lead generation leans hard on purchased lists and shared lead forms, exactly the consent model the FCC targeted in 2024. [4] Agents who buy leads from Zillow or Realtor.com and text them right away without a direct opt-in are on contested legal ground. See real estate text message marketing for the specifics.

Restaurants and retail. Loyalty SMS ("show this text for 10% off") is one of the cleanest use cases because consent is collected directly at sign-up. The legal risk is lower, but opt-out rates spike fast if you over-message. See sample text message marketing for restaurants for examples.

Financial services and insurance. Carriers flag these categories for extra scrutiny during 10DLC registration. The TCPA exposure compounds with state laws in places like Florida and Oklahoma that define autodialers more broadly. [11]

B2B outbound. Business-to-business texts to cell phones are not categorically exempt from the TCPA. The statute covers calls to cellular numbers, full stop. A text to a salesperson's cell phone is covered even in a business context. The "established business relationship" exemption that applies to DNC rules does not apply to TCPA autodialer consent. [2] B2B teams need to be careful. See b2b lead generation platforms gdpr compliance for cross-border considerations.

How do you evaluate an SMS marketing service for compliance, more than features?

Most sales demos dwell on message templates, automation flows, and deliverability rates. Ask these instead.

Ask about consent record storage. How long are opt-in records kept? Can you export them in a litigation-hold format? What gets captured per subscriber (IP, timestamp, opt-in source URL, exact language shown)? A vague answer is the answer.

Ask about their own compliance team. Does the platform have legal or compliance staff reviewing campaign content? Do they flag risky use cases before you send? Some platforms will kill your account and keep your money once they find a compliance violation. Read the terms of service.

Ask about suppression timing. When a contact sends STOP, how long until that number drops out of all future sends? The answer should be immediate or near-real-time, not "within 24 hours."

Ask how they handle 10DLC issues. If your campaign registration gets rejected, what happens? Do they tell you why? Do they help you resubmit? A platform that quietly lets your messages get filtered without a heads-up is not a partner.

Check their own TCPA exposure. Some platforms have faced TCPA suits over how they ran consent on their own marketing. That tells you something about how well they know the law.

LeadCompliant's free compliance checklist covers these vendor questions alongside your own opt-in and suppression requirements, so you walk into a contract with one document to work from.

For the broader regulatory framework your software has to support, see the tcpa overview and marketing text message service.

What are the state law wrinkles that federal TCPA compliance does not cover?

Federal TCPA compliance sets the floor, not the ceiling. Several states stacked more on top.

California's CPRA and the earlier CCPA create data rights for California residents that touch how you collect, store, and delete SMS subscriber data. [12] If a California subscriber requests deletion, you comply. That includes the consent records the TCPA pushes you to keep, which creates a real tension your legal counsel needs to sort out.

Florida passed the Florida Telephone Solicitation Act (FTSA) in 2021, creating a state-level private right of action for unsolicited texts using an "automated system for the selection or dialing of telephone numbers." [11] Florida courts read this more broadly than the federal ATDS definition after Facebook v. Duguid. Florida litigation exploded in 2021 and 2022. Text Florida numbers, and you need Florida-specific legal review.

Oklahoma, Maryland, and Washington have also passed or strengthened state telemarketing laws with SMS implications. The National Conference of State Legislatures tracks them. [13]

The practical takeaway for software selection: your platform needs to support state-specific suppression lists (some states run their own do-not-call registries that supplement the national DNC), and your consent language may need state-specific disclosures. FCC compliance does not equal full compliance everywhere you operate.

What does a compliant SMS marketing workflow actually look like?

Here is a realistic end-to-end workflow for a small outbound team.

Step one is consent collection. You get a consumer to a landing page, checkout flow, or in-store sign-up with clear opt-in language: "By entering your number and clicking Subscribe, you agree to receive promotional text messages from [Company Name] at the number provided. Consent is not a condition of purchase. Message and data rates may apply. Reply STOP to opt out." You record the timestamp, IP, the exact language shown, and the source URL. [3]

Step two is verification. A double opt-in fires an immediate confirmation text: "Reply YES to confirm your subscription to [Company Name] alerts." Not legally required in every context, but it strengthens your consent record and cuts spam complaints hard. [6]

Step three is campaign setup in your SMS platform. Import the verified opt-in list. Set up the suppression list check. Register your 10DLC campaign if you haven't already.

Step four is send. Your platform checks each number against the suppression list at send time, more than at import. Opt-outs that arrived between import and send get caught.

Step five is opt-out processing. Every STOP reply is suppressed immediately, a confirmation goes out ("You have been unsubscribed. You will receive no more messages from us."), and the record updates.

Step six is record retention. Keep consent records and send logs for at least four years. That is not a stated statutory requirement on its own, but the TCPA has a four-year statute of limitations under 28 U.S.C. § 1658, and you want your records to outlast your exposure window.

The LeadCompliant TCPA compliance kit includes template opt-in language, a consent record schema, and a vendor evaluation checklist so you do not build this from scratch.

Frequently asked questions

Yes, but only with prior express written consent from the recipient. The TCPA (47 U.S.C. § 227) prohibits sending marketing texts to cell phones using an autodialer without that consent. Texts to people who have not opted in directly can trigger $500 to $1,500 in statutory damages per message. Transactional texts (order confirmations, appointment reminders) have a somewhat lower consent bar, but marketing messages require the highest standard.

What is the best text message marketing software for small businesses?

For small teams without a developer, SMB platforms like EZTexting, SimpleTexting, and SlickText handle 10DLC registration, opt-out management, and message scheduling without coding. The 'best' platform depends on your list size, industry, and whether you need CRM integration. Compliance features, specifically consent record storage and automatic opt-out suppression, matter more than template variety. Evaluate those first.

Can I text someone who gave me their number but did not explicitly opt in to texts?

Almost certainly not for marketing purposes. Giving you a phone number does not equal consent to receive promotional texts via autodialer. The FCC requires prior express written consent for marketing messages, meaning the consumer specifically agreed in writing to receive texts from your company. A business card, a verbal exchange, or a form that never mentioned texting does not meet that standard.

What is 10DLC registration and do I need it?

10DLC (10-digit long code) registration is a carrier-required process for businesses sending A2P SMS through standard U.S. phone numbers. Since 2021, AT&T, Verizon, and T-Mobile require brand and campaign registration through The Campaign Registry. Without it, your messages face throughput caps and spam filtering. Brand registration costs roughly $4 to $6 one-time; campaign registration runs $10 to $15 per month per use case.

How do SMS opt-out requirements work?

You must honor opt-out requests immediately. CTIA guidelines require platforms to recognize standard opt-out keywords (STOP, QUIT, CANCEL, UNSUBSCRIBE, END) and send a confirmation message. You cannot charge for opt-outs, and you cannot send any further marketing messages after a valid STOP request. If a consumer opts back in later, they must do so affirmatively. Ignoring a STOP and sending another message is a clean TCPA violation.

What is the difference between a short code and a long code for SMS marketing?

Short codes are five or six digit numbers capable of sending up to 500 messages per second, used for high-volume campaigns. Dedicated short codes cost $500 to $1,000 per month and take six to eight weeks to provision. Long codes are standard 10-digit numbers, cheaper and faster to set up through 10DLC registration, but with lower throughput. Shared short codes were retired by major carriers in 2021 due to spam abuse.

Does TCPA apply to B2B text message marketing?

Yes. The TCPA covers calls and texts to cellular telephone numbers without exception for business context. If you text a salesperson's cell phone using an autodialer for marketing and they have not given prior express written consent, it is potentially a TCPA violation regardless of whether it is a business-to-business interaction. The B2B context is a factor in some damages arguments but does not create a categorical exemption.

Keep consent records for at least four years. The TCPA's statute of limitations is four years under 28 U.S.C. § 1658, so if someone sues you four years after receiving a text, you need records showing valid consent at the time of that send. Store the timestamp, the opt-in source URL, the exact disclosure language shown, the consumer's IP address, and the phone number. Your SMS platform should support exporting this data.

What is the Florida Telephone Solicitation Act and why does it matter for SMS?

Florida's FTSA (effective July 2021) created a state private right of action for unsolicited texts sent using an automated system. Florida courts have interpreted 'automated system' more broadly than the post-Facebook v. Duguid federal ATDS definition, catching more technology under the statute. FTSA litigation surged in 2021 and 2022. If you text Florida residents, your consent practices need to meet both federal TCPA and Florida FTSA standards.

What disclosures are required in SMS marketing opt-in forms?

FCC rules require opt-in language that: (1) identifies your company by name, (2) describes the nature and frequency of messages, (3) states that consent is not required for purchase, (4) notes that message and data rates may apply, and (5) explains how to opt out. The disclosure must be clear and conspicuous, meaning not buried in fine print. Electronic agreements (web forms, click-to-agree) count as written consent under the FCC's rules.

Can I send a text message to someone on the National Do Not Call Registry?

No, not for marketing purposes without their prior express written consent or an established business relationship. The FCC confirmed in 2003 that DNC rules apply to wireless numbers, and the FTC treats text solicitations as covered communications. If you have prior express written consent for texting, the DNC registration does not necessarily block you, but you should still scrub against it as a separate compliance layer.

How much does it cost to send a text message marketing campaign?

For a small business, budget $200 to $600 per month all-in for roughly 10,000 messages, including platform fees, per-message costs of $0.008 to $0.02 each, and 10DLC campaign registration fees around $10 to $15 per month. Short code users pay an additional $500 to $1,000 per month for the code lease. MMS messages cost two to three times more than plain SMS. Enterprise pricing is negotiated and varies widely.

What happened in recent TCPA class action cases involving SMS?

Large settlements include Papa John's ($16.5 million, 2013) and Domino's ($9.45 million, 2019) over marketing texts sent without adequate consent. The FCC's 2024 order targeted lead generator consent practices, which has driven new litigation against companies that relied on third-party opt-ins. Single-plaintiff demand letters remain more common than class actions for small businesses, typically settling for a few thousand dollars but adding up across multiple claimants.

What is double opt-in for SMS and do I need it?

Double opt-in sends a confirmation text after the initial sign-up asking the consumer to reply YES before messages begin. It is not legally required by the FCC, but it creates a stronger consent record, reduces spam complaints, and improves list quality. For industries facing higher TCPA scrutiny (financial services, insurance, real estate), the extra verification step is worth the slightly lower opt-in completion rate.

Sources

  1. U.S. Government Publishing Office, 47 U.S.C. § 227 (Telephone Consumer Protection Act): TCPA prohibits ATDS calls/texts to cell phones without prior express consent; damages are $500 per violation, trebled to $1,500 for willful violations
  2. The Campaign Registry (TCR), A2P 10DLC Registration Overview: 10DLC brand registration costs approximately $4-6 one-time; campaign registration costs $10-15 per campaign per month; required by major U.S. carriers since 2021 for A2P messaging
  3. Twilio, SMS Pricing for the United States: Twilio's published outbound SMS API rate is approximately $0.0079 per message for U.S. destinations as of 2025
  4. U.S. Short Code Administration (USCA), Short Code Leasing and Fees: Dedicated short code leasing costs $500-$1,000 per month; provisioning and carrier review takes approximately six to eight weeks
  5. Almeida v. Papa John's International Inc., No. 1:12-cv-23386 (S.D. Fla. 2013); Montegna v. Domino's Pizza LLC (S.D. Cal.): Papa John's settled TCPA class action for $16.5 million (2013); Domino's settled a text-message TCPA case for $9.45 million for sending marketing texts without adequate consent
  6. Florida Legislature, Florida Telephone Solicitation Act, Fla. Stat. § 501.059: Florida FTSA (effective July 2021) created state private right of action for unsolicited texts using automated systems; interpreted more broadly than post-Facebook v. Duguid federal ATDS definition
  7. California Privacy Protection Agency, California Consumer Privacy Act (CPRA) Regulations: California CPRA creates deletion rights for California residents' personal data including SMS subscriber records, creating tension with TCPA consent record retention requirements
  8. National Conference of State Legislatures, State Telemarketing Laws: Multiple states including Oklahoma, Maryland, and Washington have enacted or strengthened state telemarketing and robocall laws with SMS implications beyond federal TCPA

Disclaimer: LeadCompliant is a compliance review tool, not a law firm. We do not provide legal advice. Consult with a TCPA attorney for legal guidance on specific compliance questions. Compliance scores, audits, and risk assessments are informational only.

LeadCompliant Team

LeadCompliant provides expert guidance and tools to help you succeed. Our content is reviewed for accuracy and kept up to date.

Related Articles

Related Glossary Terms

LeadCompliant
Build My Kit